SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-11729

HIGH · CVSS 8.5 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

IBM MQ versions 9.1 through 10.0 are vulnerable to arbitrary code execution due to unsafe deserialization, which can be exploited through JNDI injection by authenticated attackers. This vulnerability poses a high risk, as it could allow attackers to manipulate client applications and potentially compromise sensitive data or system integrity. Organizations using affected versions of IBM MQ should prioritize patching to mitigate this critical security risk.

CVE
CVE-2026-11729
Severity
HIGH
CVSS
8.5
EPSS
0.29%

Original NVD Description

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code in client applications due to unsafe deserialization that enables JNDI injection attacks.