HIGH
CVE-2026-13285
CVSS
7.1
Description
IBM MQ is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Weakness (CWE)
CWE-611
XML External Entity (XXE)
EPSS Score
0.39%
Probability of exploitation in next 30 days
32.4th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.