[NEU] [hoch] IBM MQ Appliance (Axios Node.js): Mehrere Schwachstellen
Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM MQ Appliance ausnutzen, um beliebigen Programmcode auszuführen, Server-Side Request Forgery (SSRF) durchzuführen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder Denial-of-Service-Zustände herbeizuführen.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3307
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2018-164871.6% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 74% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-444860.66% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 49% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-444870.66% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 50% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-444880.67% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 50% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-444890.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-444900.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-444920.87% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 57% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-444941.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 61% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-444950.84% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 56% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-444960.67% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 50% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2018-16487 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-44486 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-44487 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-44488 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-44489 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-44490 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-44492 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-44494 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-44495 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-44496 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [hoch] Red Hat Enterprise Linux (Apicurio Registry): Mehrere Schwachstellencert-bund
- medium[UPDATE] [mittel] Red Hat OpenShift Container Platform (protobufjs, fast-uri): Mehrere Schwachstellencert-bund
- highexploited[UPDATE] [hoch] Atlassian Produkte (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, und Jira): Mehrere Schwa…cert-bund
- high[UPDATE] [hoch] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management: …cert-bund
- highexploited[UPDATE] [high] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira and Jira Service Management: …cert-bund
- unknownNCSC-2026-0325 [1.00] [M/H] Kwetsbaarheden verholpen in Atlassian productenncsc-nl
- unknownMultiple vulnerabilities in IBM products (July 31, 2026)cert-fr-avis
- unknownMultiple vulnerabilities in Atlassian products (July 27, 2026)cert-fr-avis
- highGHSA-pjwm-pj3p-43mv: axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROX…ghsa
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service2026-09-15
- high[UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen2026-09-15
- high[UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff2026-09-15
- high[NEU] [hoch] MISP: Mehrere Schwachstellen2026-09-15
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service oder unspezifischer Angri…2026-09-15