{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/ibm-mq-java-and-jms-client-libraries/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ibm:mq:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-10751"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["IBM MQ (Java and JMS client libraries)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["IBM"],"content_html":"\u003cp\u003eIBM MQ Java and JMS client libraries are susceptible to a critical deserialization filter bypass vulnerability (CVE-2026-10751). The flaw exists within the exception handling mechanism of the libraries. An authenticated attacker who can influence the data processed by a client application using these libraries can trigger this vulnerability to execute arbitrary code. Because the issue resides in the client-side library, any Java application integrating these libraries is potentially at risk if it processes untrusted or attacker-controlled MQ messages. The vulnerability is assigned a CVSS v3.1 score of 7.5, reflecting the risk posed by the ability to achieve remote code execution in the context of the application process. Organizations using IBM MQ client libraries should assess their dependency tree and apply vendor-supplied patches to mitigate the risk of arbitrary code execution.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated attacker to execute arbitrary code on the host running the vulnerable IBM MQ client application. This can lead to full compromise of the application context, potentially resulting in data exfiltration, lateral movement within the network, or the installation of persistent malicious payloads. The scope of impact is dependent on the privileges of the application process utilizing the library.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all Java applications utilizing vulnerable versions of IBM MQ Java and JMS client libraries.\u003c/li\u003e\n\u003cli\u003eConsult IBM security bulletins to obtain and apply the latest security patches for the IBM MQ client libraries.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation and deserialization filters for all incoming MQ messages to prevent processing of malicious serialized objects.\u003c/li\u003e\n\u003cli\u003eMonitor for unexpected process creation or unusual network activity originating from Java applications acting as IBM MQ clients.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T18:07:45Z","date_published":"2026-09-18T18:07:45Z","id":"https://feed.craftedsignal.io/briefs/2026-09-ibm-mq-rce/","summary":"An authenticated attacker can execute arbitrary code on client applications by exploiting a deserialization filter bypass in IBM MQ Java and JMS client libraries.","title":"IBM MQ Java and JMS Client Deserialization Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-09-ibm-mq-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - IBM MQ (Java and JMS Client Libraries)","version":"https://jsonfeed.org/version/1.1"}