{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/mq-9.1.0.0-through-9.1.0.37-lts-9.2.0.0-through-9.2.0.43-lts-9.3.0.0-through-9.3.0.41-lts-9.3.0.0-through-9.3.5.1-cd-9.4.0.0-through-9.4.0.25-lts-9.4.0.0-through-9.4.5.1-cd-10.0.0.0-managed-file-transfer/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ibm:mq:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-13275"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MQ (9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, 10.0.0.0 Managed File Transfer)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["IBM"],"content_html":"\u003cp\u003eIBM MQ, a message-oriented middleware solution, contains a vulnerability identified as CVE-2026-13275 that stems from improper handling of XML input during reply message processing. This vulnerability enables an authenticated attacker to perform XML External Entity (XXE) injection attacks. By submitting specifically crafted XML messages, an attacker can coerce the IBM MQ application into reading arbitrary files from the host filesystem or performing unauthorized Server-Side Request Forgery (SSRF) requests to internal or external network resources. This flaw impacts multiple long-term support (LTS) and continuous delivery (CD) versions of IBM MQ, as well as the Managed File Transfer component. Given that IBM MQ often handles sensitive financial or operational data, successful exploitation could lead to the exposure of configuration files, credentials, or internal network mapping.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows authenticated attackers to bypass security boundaries within the messaging environment. Successful exploitation leads to unauthorized access to sensitive local files and the ability to conduct SSRF, potentially escalating access within the internal network. The scope covers a wide range of IBM MQ versions, impacting organizations relying on this middleware for enterprise application integration. If exploited, an attacker could exfiltrate configuration data or pivot to other internal services that are not directly exposed to the internet.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and IT teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ePatch IBM MQ installations to the latest version as recommended by IBM to remediate CVE-2026-13275.\u003c/li\u003e\n\u003cli\u003eAudit IBM MQ message flow configurations to identify and restrict untrusted XML input sources.\u003c/li\u003e\n\u003cli\u003eMonitor MQ audit logs for unusual file access patterns or connection attempts originating from the IBM MQ service account.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-14T21:36:04Z","date_published":"2026-09-14T21:36:04Z","id":"https://feed.craftedsignal.io/briefs/2026-09-ibm-mq-xxe/","summary":"An XML external entity injection vulnerability in IBM MQ allows authenticated attackers to perform arbitrary file reads or server-side request forgery during reply message processing.","title":"IBM MQ XML External Entity Injection Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-09-ibm-mq-xxe/"}],"language":"en","title":"CraftedSignal Threat Feed - MQ (9.1.0.0 Through 9.1.0.37 LTS, 9.2.0.0 Through 9.2.0.43 LTS, 9.3.0.0 Through 9.3.0.41 LTS, 9.3.0.0 Through 9.3.5.1 CD, 9.4.0.0 Through 9.4.0.25 LTS, 9.4.0.0 Through 9.4.5.1 CD, 10.0.0.0 Managed File Transfer)","version":"https://jsonfeed.org/version/1.1"}