<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>IBM MQ (Java and JMS Client Libraries) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/ibm-mq-java-and-jms-client-libraries/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 18 Sep 2026 18:07:45 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/ibm-mq-java-and-jms-client-libraries/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>IBM MQ Java and JMS Client Deserialization Vulnerability</title><link>https://feed.craftedsignal.io/briefs/2026-09-ibm-mq-rce/</link><pubDate>Fri, 18 Sep 2026 18:07:45 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-ibm-mq-rce/</guid><description>An authenticated attacker can execute arbitrary code on client applications by exploiting a deserialization filter bypass in IBM MQ Java and JMS client libraries.</description><content:encoded><![CDATA[<p>IBM MQ Java and JMS client libraries are susceptible to a critical deserialization filter bypass vulnerability (CVE-2026-10751). The flaw exists within the exception handling mechanism of the libraries. An authenticated attacker who can influence the data processed by a client application using these libraries can trigger this vulnerability to execute arbitrary code. Because the issue resides in the client-side library, any Java application integrating these libraries is potentially at risk if it processes untrusted or attacker-controlled MQ messages. The vulnerability is assigned a CVSS v3.1 score of 7.5, reflecting the risk posed by the ability to achieve remote code execution in the context of the application process. Organizations using IBM MQ client libraries should assess their dependency tree and apply vendor-supplied patches to mitigate the risk of arbitrary code execution.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an authenticated attacker to execute arbitrary code on the host running the vulnerable IBM MQ client application. This can lead to full compromise of the application context, potentially resulting in data exfiltration, lateral movement within the network, or the installation of persistent malicious payloads. The scope of impact is dependent on the privileges of the application process utilizing the library.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Identify all Java applications utilizing vulnerable versions of IBM MQ Java and JMS client libraries.</li>
<li>Consult IBM security bulletins to obtain and apply the latest security patches for the IBM MQ client libraries.</li>
<li>Implement strict input validation and deserialization filters for all incoming MQ messages to prevent processing of malicious serialized objects.</li>
<li>Monitor for unexpected process creation or unusual network activity originating from Java applications acting as IBM MQ clients.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>