<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>MQ (9.1.0.0 Through 9.1.0.37 LTS, 9.2.0.0 Through 9.2.0.43 LTS, 9.3.0.0 Through 9.3.0.41 LTS, 9.3.0.0 Through 9.3.5.1 CD, 9.4.0.0 Through 9.4.0.25 LTS, 9.4.0.0 Through 9.4.5.1 CD, 10.0.0.0 Managed File Transfer) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/mq-9.1.0.0-through-9.1.0.37-lts-9.2.0.0-through-9.2.0.43-lts-9.3.0.0-through-9.3.0.41-lts-9.3.0.0-through-9.3.5.1-cd-9.4.0.0-through-9.4.0.25-lts-9.4.0.0-through-9.4.5.1-cd-10.0.0.0-managed-file-transfer/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 14 Sep 2026 21:36:04 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/mq-9.1.0.0-through-9.1.0.37-lts-9.2.0.0-through-9.2.0.43-lts-9.3.0.0-through-9.3.0.41-lts-9.3.0.0-through-9.3.5.1-cd-9.4.0.0-through-9.4.0.25-lts-9.4.0.0-through-9.4.5.1-cd-10.0.0.0-managed-file-transfer/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>IBM MQ XML External Entity Injection Vulnerability</title><link>https://feed.craftedsignal.io/briefs/2026-09-ibm-mq-xxe/</link><pubDate>Mon, 14 Sep 2026 21:36:04 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-ibm-mq-xxe/</guid><description>An XML external entity injection vulnerability in IBM MQ allows authenticated attackers to perform arbitrary file reads or server-side request forgery during reply message processing.</description><content:encoded><![CDATA[<p>IBM MQ, a message-oriented middleware solution, contains a vulnerability identified as CVE-2026-13275 that stems from improper handling of XML input during reply message processing. This vulnerability enables an authenticated attacker to perform XML External Entity (XXE) injection attacks. By submitting specifically crafted XML messages, an attacker can coerce the IBM MQ application into reading arbitrary files from the host filesystem or performing unauthorized Server-Side Request Forgery (SSRF) requests to internal or external network resources. This flaw impacts multiple long-term support (LTS) and continuous delivery (CD) versions of IBM MQ, as well as the Managed File Transfer component. Given that IBM MQ often handles sensitive financial or operational data, successful exploitation could lead to the exposure of configuration files, credentials, or internal network mapping.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability allows authenticated attackers to bypass security boundaries within the messaging environment. Successful exploitation leads to unauthorized access to sensitive local files and the ability to conduct SSRF, potentially escalating access within the internal network. The scope covers a wide range of IBM MQ versions, impacting organizations relying on this middleware for enterprise application integration. If exploited, an attacker could exfiltrate configuration data or pivot to other internal services that are not directly exposed to the internet.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security and IT teams:</p>
<ul>
<li>Patch IBM MQ installations to the latest version as recommended by IBM to remediate CVE-2026-13275.</li>
<li>Audit IBM MQ message flow configurations to identify and restrict untrusted XML input sources.</li>
<li>Monitor MQ audit logs for unusual file access patterns or connection attempts originating from the IBM MQ service account.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>