Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-10751
IBM WebSphere MQ vulnerability analysis and mitigation

Overview

CVE-2026-10751 is a deserialization filter bypass vulnerability in IBM MQ Java and JMS client libraries that allows an authenticated remote attacker to execute arbitrary code on client applications. The flaw exists in exception handling logic within the affected libraries. Affected versions span IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0. It was published on September 18, 2026, with a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, IBM Support).

Technical details

The vulnerability is classified as CWE-502 (Deserialization of Untrusted Data). The root cause is a bypass of the deserialization filter within exception handling code paths in the IBM MQ Java and JMS client libraries — meaning that deserialization protections that would normally block untrusted object graphs are not applied when exceptions are raised during message processing. An authenticated attacker with network access to an IBM MQ broker can craft malicious serialized payloads that are processed through the unprotected exception handling path, leading to arbitrary code execution on the client application. The attack requires low privileges and no user interaction, but has high complexity, suggesting specific conditions or timing must be met (GitHub Advisory, IBM Support).

Impact

Successful exploitation results in arbitrary code execution on client applications using the IBM MQ Java or JMS libraries, with full impact to confidentiality, integrity, and availability. An attacker who achieves code execution on a client application could exfiltrate sensitive data processed through the MQ messaging infrastructure, tamper with messages, or disrupt client application availability. Given that IBM MQ is commonly used in enterprise middleware and financial services environments, compromise of client applications could facilitate lateral movement into broader internal networks (GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at the time of disclosure (GitHub Advisory). The EPSS score is 0.0, indicating a very low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authentication and high attack complexity, which raises the bar for opportunistic attackers, though targeted exploitation by sophisticated actors remains a concern given the enterprise prevalence of IBM MQ.

Mitigation and workarounds

IBM has released patches addressing this vulnerability; users should update IBM MQ Java and JMS client libraries to versions beyond the affected ranges (i.e., above 9.1.0.37 LTS, 9.2.0.43 LTS, 9.3.0.41 LTS, 9.3.5.1 CD, 9.4.0.25 LTS, 9.4.5.1 CD, and 10.0.0.0 as applicable). Refer to the IBM support page for specific fix pack details. As interim mitigations, restrict network access to IBM MQ brokers to authenticated and authorized users only, and monitor exception handling logs for anomalous deserialization activity (IBM Support, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related IBM WebSphere MQ vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-10575HIGH8.8
  • IBM WebSphere MQ logoIBM WebSphere MQ
  • cpe:2.3:a:ibm:mq
NoNoSep 18, 2026
CVE-2026-12728HIGH8.8
  • IBM WebSphere MQ logoIBM WebSphere MQ
  • cpe:2.3:a:ibm:mq
NoNoSep 15, 2026
CVE-2026-10027HIGH8.1
  • IBM WebSphere MQ logoIBM WebSphere MQ
  • cpe:2.3:a:ibm:mq
NoNoSep 18, 2026
CVE-2026-10751HIGH7.5
  • IBM WebSphere MQ logoIBM WebSphere MQ
  • cpe:2.3:a:ibm:mq
NoNoSep 18, 2026
CVE-2026-10030HIGH7.1
  • IBM WebSphere MQ logoIBM WebSphere MQ
  • cpe:2.3:a:ibm:mq
NoNoSep 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management