CVE-2026-12728
Received
Received - Intake
IBM MQ Deserialization Flaw Enables Code Execution
Vulnerability report for CVE-2026-12728, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-15
Last updated on: 2026-09-15
Assigner: IBM Corporation
Description
Description
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code due to a deserialization of untrusted data.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ibm | mq | From 9.1.0.0 (inc) to 9.1.0.37 (inc) |
| ibm | mq | From 9.2.0.0 (inc) to 9.2.0.43 (inc) |
| ibm | mq | From 9.3.0.0 (inc) to 9.3.0.41 (inc) |
| ibm | mq | From 9.3.0.0 (inc) to 9.3.5.1 (inc) |
| ibm | mq | From 9.4.0.0 (inc) to 9.4.0.25 (inc) |
| ibm | mq | From 9.4.0.0 (inc) to 9.4.5.1 (inc) |
| ibm | mq | 10.0.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |