CVE-2026-10027: IBM MQ queue manager is vulnerable to unauthenticated remote code execution
IBM MQ could allow a remote attacker to cause a denial of service or execute arbitrary code due to a buffer overflow when processing malformed compressed data on channels configured with compression enabled.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM MQ 9.1 LTSto a version that resolves this vulnerability.Fixed in 9.1.0.38 - Upgrade
Upgrade
IBM MQ 9.2 LTSto a version that resolves this vulnerability.Fixed in 9.2.0.44 - Upgrade
Upgrade
IBM MQ 9.3 LTSto a version that resolves this vulnerability.Fixed in 9.3.0.42 - Upgrade
Upgrade
IBM MQ 9.4 LTSto a version that resolves this vulnerability.Fixed in 9.4.0.26 - Upgrade
Upgrade
IBM MQ 10.0.0.0to a version that resolves this vulnerability.Fixed in 10.0.0.5 - Compensating control
Ensure channels that process compressed data with compression enabled are not exposed to untrusted remote clients until the applicable IBM MQ cumulative security update / upgrade (DT472389) is applied.
Event History
Frequently Asked Questions
Which IBM MQ deployments are exposed?
Exposure is limited to queue manager channels configured with compression enabled. The issue is triggered while processing malformed compressed data on those channels.
What does an attacker need to exploit this issue?
An attacker needs network access to reach an affected channel and send malformed compressed data. Authentication and user interaction are not required, although the attack complexity is rated high.