---
id: CVE-2026-12728
title: >-
  IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0
  through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25
  LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated
  attacker to …
summary: >-
  IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0
  through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25
  LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated
  attacker to …
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-502
vendor: IBM
product: MQ
affected:
  - MQ >= 9.1.0.0 <= 9.1.0.37 LTS
  - MQ >= 9.2.0.0 <= 9.2.0.43 LTS
  - MQ >= 9.3.0.0 <= 9.3.0.41 LTS
  - MQ >= 9.3.0.0 <= 9.3.5.1 CD
  - MQ >= 9.4.0.0 <= 9.4.0.25 LTS
  - MQ >= 9.4.0.0 <= 9.4.5.1 CD
  - MQ 10.0.0.0
published: '2026-09-15'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T15:16:40.963'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-12728'
references:
  - url: 'https://www.ibm.com/support/pages/node/7284942'
    label: psirt@us.ibm.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-16T03:56:49.364826Z'
epss: 0.00355
epssPercentile: 0.26566
ingestedAt: '2026-09-15T17:41:02.975Z'
---

## Overview

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code due to a deserialization of untrusted data.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
