{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/ibm-mq/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ibm:mq:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-11725"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MQ"],"_cs_severities":["high"],"_cs_tags":["vulnerability","remote-code-execution","ibm-mq"],"_cs_type":"advisory","_cs_vendors":["IBM"],"content_html":"\u003cp\u003eIBM MQ contains a critical integer overflow vulnerability, identified as CVE-2026-11725, affecting its processing of MQINQ requests. This vulnerability allows an authenticated attacker with access to the messaging system to manipulate input parameters during the MQINQ call sequence, causing a buffer or memory handling error. The impact of successful exploitation ranges from an immediate denial of service (DoS), causing the queue manager to crash or hang, to the potential for remote arbitrary code execution under the context of the IBM MQ service account. Given the privileged nature of message queuing middleware in enterprise environments, this flaw represents a significant risk for lateral movement or infrastructure disruption. Organizations utilizing IBM MQ should prioritize identifying the patch status of their queue managers and implementing access controls to restrict the ability of unauthorized or untrusted users to perform administrative or inquiries on the messaging infrastructure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-11725 can lead to a complete service disruption of the IBM MQ messaging backbone, affecting all downstream applications that rely on the queue manager. In scenarios resulting in arbitrary code execution, an attacker may gain persistence on the underlying server, potentially accessing sensitive business messages or pivoting into the internal network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification and patching of all IBM MQ instances. Review IBM security bulletins for the specific version-dependent fixed releases. Audit MQ queue manager access controls to ensure that only authorized service accounts and administrators can invoke MQINQ functions, limiting the potential attack surface.\u003c/p\u003e\n","date_modified":"2026-09-18T22:08:22Z","date_published":"2026-09-18T22:08:22Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-11725/","summary":"An integer overflow vulnerability in IBM MQ's processing of MQINQ requests allows an authenticated attacker to trigger a denial of service or potentially execute arbitrary code.","title":"Integer Overflow Vulnerability in IBM MQ Request Processing (CVE-2026-11725)","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-11725/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ibm:mq:8.1.0:*:*:*:*:hpe_nonstop:*:*"],"_cs_cves":[{"cvss":9.9,"id":"CVE-2026-10858"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["IBM MQ for HPE NonStop (8.1.0 through 8.1.0.40)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","remote-code-execution","ibm-mq","critical"],"_cs_type":"threat","_cs_vendors":["IBM"],"content_html":"\u003cp\u003eIBM has disclosed a critical vulnerability, CVE-2026-10858, affecting IBM MQ for HPE NonStop versions 8.1.0 through 8.1.0.40. The vulnerability stems from an improper handling of multi-segment messages, resulting in a heap buffer underflow condition. An authenticated attacker can exploit this flaw to crash the message queue manager, causing a denial of service, or potentially gain arbitrary code execution capabilities with the privileges of the IBM MQ service. Given the high CVSS base score of 9.9 and the potential for remote code execution, this represents a significant risk to the integrity and availability of messaging infrastructure. Defenders should prioritize patching or applying vendor-recommended mitigations to affected NonStop environments.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a severe risk to messaging infrastructure relying on IBM MQ for HPE NonStop. Successful exploitation can lead to total loss of service through application crashes or unauthorized system access. Given that the impact includes potential arbitrary code execution, attackers could leverage this access for internal lateral movement, exfiltration of sensitive queued message data, or further compromise of the HPE NonStop operating environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all instances of IBM MQ for HPE NonStop within the environment that are running version 8.1.0 through 8.1.0.40.\u003c/li\u003e\n\u003cli\u003ePatch affected instances immediately following vendor guidance for CVE-2026-10858.\u003c/li\u003e\n\u003cli\u003eReview access control lists (ACLs) for IBM MQ queues to restrict the number of users capable of submitting multi-segment messages, reducing the attack surface until patches are applied.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T18:06:54Z","date_published":"2026-09-18T18:06:54Z","id":"https://feed.craftedsignal.io/briefs/2026-09-ibm-mq-heap-underflow/","summary":"IBM MQ for HPE NonStop versions 8.1.0 through 8.1.0.40 contain a heap buffer underflow vulnerability in multi-segment message processing that allows authenticated attackers to execute arbitrary code or trigger denial of service.","title":"Heap Buffer Underflow in IBM MQ for HPE NonStop","url":"https://feed.craftedsignal.io/briefs/2026-09-ibm-mq-heap-underflow/"}],"language":"en","title":"CraftedSignal Threat Feed - Ibm-Mq","version":"https://jsonfeed.org/version/1.1"}