Stack Buffer Overflow in IBM MQ Vulnerability
CVE-2026-11375

8.8HIGH

Key Information:

Vendor

IBM

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-11375?

IBM MQ has a vulnerability that can be exploited by an authenticated attacker to trigger a stack buffer overflow during the processing of XA transaction identifiers. This issue can lead to denial of service, and in some scenarios, could allow the execution of arbitrary code, posing significant security risks. Users are encouraged to review the advisory and apply recommended patches promptly.

Affected Version(s)

MQ 9.1.0.0 <= 9.1.0.37 LTS

MQ 9.2.0.0 <= 9.2.0.43 LTS

MQ 9.3.0.0 <= 9.3.0.41 LTS

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.