Deserialization Vulnerability in IBM MQ Affected Versions
CVE-2026-12728
8.8HIGH
What is CVE-2026-12728?
A deserialization vulnerability has been identified in IBM MQ product versions, which allows authenticated attackers to execute arbitrary code. This occurs due to improper handling of untrusted data during the deserialization process. Organizations using affected versions must apply the necessary security updates to mitigate this risk effectively.
Affected Version(s)
MQ 9.1.0.0 <= 9.1.0.37 LTS
MQ 9.2.0.0 <= 9.2.0.43 LTS
MQ 9.3.0.0 <= 9.3.0.41 LTS