<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Ibm-Mq - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/ibm-mq/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 18 Sep 2026 22:08:22 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/ibm-mq/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Integer Overflow Vulnerability in IBM MQ Request Processing (CVE-2026-11725)</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-11725/</link><pubDate>Fri, 18 Sep 2026 22:08:22 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-11725/</guid><description>An integer overflow vulnerability in IBM MQ's processing of MQINQ requests allows an authenticated attacker to trigger a denial of service or potentially execute arbitrary code.</description><content:encoded><![CDATA[<p>IBM MQ contains a critical integer overflow vulnerability, identified as CVE-2026-11725, affecting its processing of MQINQ requests. This vulnerability allows an authenticated attacker with access to the messaging system to manipulate input parameters during the MQINQ call sequence, causing a buffer or memory handling error. The impact of successful exploitation ranges from an immediate denial of service (DoS), causing the queue manager to crash or hang, to the potential for remote arbitrary code execution under the context of the IBM MQ service account. Given the privileged nature of message queuing middleware in enterprise environments, this flaw represents a significant risk for lateral movement or infrastructure disruption. Organizations utilizing IBM MQ should prioritize identifying the patch status of their queue managers and implementing access controls to restrict the ability of unauthorized or untrusted users to perform administrative or inquiries on the messaging infrastructure.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-11725 can lead to a complete service disruption of the IBM MQ messaging backbone, affecting all downstream applications that rely on the queue manager. In scenarios resulting in arbitrary code execution, an attacker may gain persistence on the underlying server, potentially accessing sensitive business messages or pivoting into the internal network.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the identification and patching of all IBM MQ instances. Review IBM security bulletins for the specific version-dependent fixed releases. Audit MQ queue manager access controls to ensure that only authorized service accounts and administrators can invoke MQINQ functions, limiting the potential attack surface.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>remote-code-execution</category><category>ibm-mq</category></item><item><title>Heap Buffer Underflow in IBM MQ for HPE NonStop</title><link>https://feed.craftedsignal.io/briefs/2026-09-ibm-mq-heap-underflow/</link><pubDate>Fri, 18 Sep 2026 18:06:54 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-ibm-mq-heap-underflow/</guid><description>IBM MQ for HPE NonStop versions 8.1.0 through 8.1.0.40 contain a heap buffer underflow vulnerability in multi-segment message processing that allows authenticated attackers to execute arbitrary code or trigger denial of service.</description><content:encoded><![CDATA[<p>IBM has disclosed a critical vulnerability, CVE-2026-10858, affecting IBM MQ for HPE NonStop versions 8.1.0 through 8.1.0.40. The vulnerability stems from an improper handling of multi-segment messages, resulting in a heap buffer underflow condition. An authenticated attacker can exploit this flaw to crash the message queue manager, causing a denial of service, or potentially gain arbitrary code execution capabilities with the privileges of the IBM MQ service. Given the high CVSS base score of 9.9 and the potential for remote code execution, this represents a significant risk to the integrity and availability of messaging infrastructure. Defenders should prioritize patching or applying vendor-recommended mitigations to affected NonStop environments.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability poses a severe risk to messaging infrastructure relying on IBM MQ for HPE NonStop. Successful exploitation can lead to total loss of service through application crashes or unauthorized system access. Given that the impact includes potential arbitrary code execution, attackers could leverage this access for internal lateral movement, exfiltration of sensitive queued message data, or further compromise of the HPE NonStop operating environment.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Identify all instances of IBM MQ for HPE NonStop within the environment that are running version 8.1.0 through 8.1.0.40.</li>
<li>Patch affected instances immediately following vendor guidance for CVE-2026-10858.</li>
<li>Review access control lists (ACLs) for IBM MQ queues to restrict the number of users capable of submitting multi-segment messages, reducing the attack surface until patches are applied.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">threat</category><category>vulnerability</category><category>remote-code-execution</category><category>ibm-mq</category><category>critical</category></item></channel></rss>