SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-12351

CRITICAL · CVSS 9.8 EPSS 0.86%

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

IBM MQ versions 9.3.0.0 to 9.3.5.1, 9.4.0.0 to 9.4.5.1, and 10.0.0.0 are vulnerable to remote code execution due to improper handling of JNDI lookups in the IVT application. This critical vulnerability, with a CVSS score of 9.8, could allow attackers to execute arbitrary code on affected systems, potentially compromising sensitive data and system integrity. Organizations using these versions of IBM MQ should prioritize immediate patching to mitigate the risk of exploitation.

CVE
CVE-2026-12351
Severity
CRITICAL
CVSS
9.8
EPSS
0.86%

Original NVD Description

IBM MQ 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 LTS, and 10.0.0.0 could allow a remote attacker to execute arbitrary code due to unsafe JNDI lookup processing when the IVT application is deployed.