Buffer Overflow Vulnerability in IBM MQ Affected by Malformed Compressed Data
CVE-2026-10027

8.1HIGH

Key Information:

Vendor

IBM

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-10027?

IBM MQ is susceptible to a serious vulnerability where a remote attacker may exploit a buffer overflow while processing malformed compressed data on channels with compression enabled. This flaw can potentially result in a denial of service or even remote code execution, posing significant risks to affected systems. Organizations using IBM MQ should take immediate precautions to mitigate these risks, including applying the necessary patches and updates as advised.

Affected Version(s)

MQ 9.1.0.0 <= 9.1.0.37 LTS

MQ 9.2.0.0 <= 9.2.0.43 LTS

MQ 9.3.0.0 <= 9.3.0.41 LTS

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.