SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-13293

HIGH · CVSS 8.8 EPSS 0.56%

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

IBM MQ versions 9.1.0.0 to 10.0.0.0 are vulnerable to remote code execution due to the deserialization of untrusted data, allowing authenticated attackers to execute arbitrary code on affected systems. Organizations using these versions should prioritize patching to mitigate the risk of exploitation, as the severity rating indicates a high potential for impact. Immediate action is recommended for environments that rely on IBM MQ for critical messaging services.

CVE
CVE-2026-13293
Severity
HIGH
CVSS
8.8
EPSS
0.56%

Original NVD Description

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote authenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.