SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-12150

HIGH · CVSS 7 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

IBM MQ versions 9.1 through 10.0 are vulnerable to a denial of service attack, which can be triggered by a remote attacker using a trusted TLS client certificate. This vulnerability arises from improper validation of deeply nested certificate data during TLS certificate processing, potentially leading to memory corruption. Organizations using affected IBM MQ versions should prioritize patching to mitigate the risk of service disruption and data integrity issues.

CVE
CVE-2026-12150
Severity
HIGH
CVSS
7
EPSS
0.17%

Original NVD Description

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote attacker with a trusted TLS client certificate to cause a denial of service and potentially affect memory contents due to improper validation of deeply nested certificate data during TLS certificate processing.