{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/messaging-middleware/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:*:*","cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:*:*","cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:-:*:*","cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:macos:*:*","cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:-:*:*","cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:macos:*:*","cpe:2.3:a:microsoft:word:2016:*:*:*:*:*:*:*","cpe:2.3:a:microsoft:partner_center:-:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2024-49033"},{"cvss":8.7,"id":"CVE-2024-49035"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MQ"],"_cs_severities":["high"],"_cs_tags":["vulnerability","messaging-middleware","remote-code-execution"],"_cs_type":"advisory","_cs_vendors":["IBM"],"content_html":"\u003cp\u003eIBM has disclosed multiple security vulnerabilities affecting the IBM MQ messaging software. These flaws, tracked as CVE-2024-49033, CVE-2024-49034, and CVE-2024-49035, present significant risks to systems running the software. Successful exploitation of these vulnerabilities may allow an unauthenticated or authenticated attacker to achieve arbitrary remote code execution (RCE) on the underlying host, trigger a Denial of Service (DoS) condition, gain access to sensitive information, or perform unauthorized data manipulation. Defenders should prioritize patching and configuration reviews for all instances of IBM MQ, as these vulnerabilities impact the integrity and availability of messaging infrastructure, which often serves as a critical backbone for enterprise applications.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation could result in the total compromise of the host system, loss of message confidentiality, and disruption of critical business services that rely on IBM MQ for communication. These vulnerabilities affect all deployments of the software, and organizations should apply vendor-provided security updates to mitigate these risks.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all IBM MQ deployments across the environment using asset inventory systems.\u003c/li\u003e\n\u003cli\u003eReview the IBM security advisory for the specific fixed versions associated with CVE-2024-49033, CVE-2024-49034, and CVE-2024-49035.\u003c/li\u003e\n\u003cli\u003eApply the latest security patches provided by IBM to all MQ instances.\u003c/li\u003e\n\u003cli\u003eImplement network segmentation to limit access to MQ listener ports (typically 1414) to authorized clients only to reduce the attack surface.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-15T13:04:36Z","date_published":"2026-09-15T13:04:36Z","id":"https://feed.craftedsignal.io/briefs/2026-09-ibm-mq-vulnerabilities/","summary":"IBM MQ is affected by multiple vulnerabilities, including CVE-2024-49033, CVE-2024-49034, and CVE-2024-49035, which could allow a remote attacker to execute arbitrary code, cause a denial of service, disclose sensitive information, or manipulate data.","title":"Multiple Vulnerabilities in IBM MQ","url":"https://feed.craftedsignal.io/briefs/2026-09-ibm-mq-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Messaging-Middleware","version":"https://jsonfeed.org/version/1.1"}