SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-12667

HIGH · CVSS 7.1 EPSS 0.36%

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

IBM MQ versions 9.1 through 10.0 are vulnerable to an issue that allows authenticated attackers to read sensitive files from a .NET client or potentially induce a limited denial of service through improper XML external entity handling in RFH2 folder parsing. Organizations using these versions should prioritize patching to mitigate the risk of data exposure and service disruption. This vulnerability is particularly critical for environments where IBM MQ is integral to application messaging and data transfer.

CVE
CVE-2026-12667
Severity
HIGH
CVSS
7.1
EPSS
0.36%

Original NVD Description

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to read files from a vulnerable .NET client or cause limited denial of service due to improper handling of XML external entities in RFH2 folder parsing.