Back Redpacketsecurity CVE Alert: CVE-2026-13275 – IBM
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 Managed File Transfer could allow an authenticated attacker to read arbitrary files or perform server-side request forgery due to XML external entity injection in message processing.
This is a high-priority issue for exposed Managed File Transfer deployments, but available data does not confirm active exploitation, KEV listing, PoC availability or an EPSS value; urgency should therefore be adjusted once those signals are verified.
A low-privilege account could abuse crafted XML to access sensitive local data or make requests from the MQ server’s network position. Likely objectives include credential discovery, cloud metadata access, internal service enumeration and preparation for follow-on compromise, particularly where MQ handles regulated or business-critical transfers.
### Most likely attack path
An attacker needs network reachability to the relevant MQ transfer function and valid low-level credentials, but no victim interaction; low attack complexity makes exploitation practical once access is obtained. Scope is unchanged, so direct impact remains within the affected service, although SSRF can provide an indirect route to otherwise unreachable internal systems.
### Who is most exposed
Organisations using Managed File Transfer across shared infrastructure, internet-connected gateways, partner integrations or flat administration networks are most at risk. Prioritise systems processing sensitive files or holding broad network connectivity.
Alert on unusual -message XML, especially external entity or DTD constructs.
Monitor MQ transfer accounts for unexpected file-read patterns or anomalous destinations.
Review outbound connections from MQ hosts to metadata endpoints, localhost and internal management services.
Correlate transfer activity with new authentication sources, privilege changes and access to sensitive files.
### Mitigation and prioritisation
Apply the vendor’s fixed maintenance update urgently; treat as an expedited change for internet-reachable or sensitive systems.
Disable external entity resolution and restrict outbound traffic from MQ hosts where operationally safe.
Reduce transfer-account privileges and segment MQ servers from management and cloud-control networks.
Confirm KEV, SSVC, EPSS and PoC status; if KEV is true or EPSS is at least 0.5, treat as priority 1.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
