Heap Buffer Overflow Vulnerability in IBM MQ Appliance
CVE-2026-10747

10CRITICAL

Key Information:

Vendor

IBM

Vendor
CVE Published:
18 September 2026

What is CVE-2026-10747?

The vulnerability in IBM MQ Appliance is driven by a heap buffer overflow during the processing of protocol messages prior to user authentication. An attacker exploiting this issue remotely may be capable of executing arbitrary code or instigating a denial of service, posing serious risk to the system's integrity and availability. It is crucial for users of affected versions to apply security patches and monitor for unusual activity.

Affected Version(s)

MQ Appliance 9.4 LTS <= 9.4.0.0 to 9.4.0.25

MQ Appliance 9.4 CD <= 9.4.1.0 to 9.4.5.2

MQ Appliance 10.0.0.0 <= 10.0.0.1 only

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.