CVE-2026-12728: IBM MQ Java messaging is vulnerable to remote code execution
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code due to a deserialization of untrusted data.
Other sources
IBM MQ could allow an authenticated attacker to execute arbitrary code due to a deserialization of untrusted data.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM MQ 9.1 LTSto a version that resolves this vulnerability.Fixed in 9.1.0.38 - Upgrade
Upgrade
IBM MQ 9.2 LTSto a version that resolves this vulnerability.Fixed in 9.2.0.44 - Upgrade
Upgrade
IBM MQ 9.3 LTSto a version that resolves this vulnerability.Fixed in 9.3.0.42 - Upgrade
Upgrade
IBM MQ 9.4 LTSto a version that resolves this vulnerability.Fixed in 9.4.0.26 - Upgrade
Upgrade
IBM MQ 10.0to a version that resolves this vulnerability.Fixed in 10.0.0.5 - Compensating control
If you cannot upgrade immediately, address Known Issue DT474370 as referenced in the IBM advisory for the deserialization-of-untrusted-data remote code execution vulnerability affecting IBM MQ Java messaging.
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
An attacker must be authenticated. The provided data does not identify what specific IBM MQ account privileges or roles are required.
Which IBM MQ release streams are affected?
Affected versions include 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS and 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS and 9.4.0.0 through 9.4.5.1 CD, plus 10.0.0.0.
What is the potential impact if exploitation succeeds?
A successful attacker could execute arbitrary code. The supplied severity vector indicates high confidentiality, integrity, and availability impact.