MinorCritical vulnerability
CVE-2026-13285 (CVSS 7.1)
NVD · officialPublished Sep 14, 2026Risk 23/100EPSS 0.4%
IBM MQ is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Technical details
CVSS
7.1
AV:NetworkAC:LowPR:LowUI:NoneC:HighI:NoneA:Low
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source