CVE-2026-10747: IBM MQ Appliance is affected by a heap buffer overflow vulnerability in protocol message processing

Published Sep 10, 2026
·
Updated

IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.

Other sources

IBM MQ could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication

— IBM

Affected Software

4 affected components
IBM IBM MQ Appliance
IBM MQ Appliance<=9.4 LTS - 9.4.0.0 to 9.4.0.25
IBM MQ Appliance<=9.4 CD - 9.4.1.0 to 9.4.5.2
IBM MQ Appliance<=10.0.0.0 - 10.0.0.1 only

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade IBM MQ Appliance 10.0.0.5 to a version that resolves this vulnerability.

    Patch DT472411
  2. Upgrade

    Upgrade IBM MQ Appliance to a version that resolves this vulnerability.

    Fixed in 10.0.0.5
  3. Upgrade

    Upgrade IBM MQ Appliance to a version that resolves this vulnerability.

    Fixed in 9.4.0.26
  4. Upgrade

    Upgrade IBM MQ Appliance to a version that resolves this vulnerability.

    Fixed in 9.4.5.3

Event History

Sep 10, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Sep 18, 2026
CVE Published
via MITRE·03:55 PM
Data Sourced
via MITRE·03:55 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeakness

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

Does exploitation require valid IBM MQ credentials or prior access?

No. The vulnerable protocol message processing occurs before authentication, and the vector indicates remote exploitation with no privileges or user interaction required.

2

What could an attacker achieve if exploitation succeeds?

An attacker could cause a denial of service or potentially execute arbitrary code. The reported impact includes high confidentiality, integrity, and availability impact.

3

Which deployments should be prioritized for triage?

IBM MQ Appliance deployments should be prioritized, particularly where their protocol service is reachable by untrusted remote systems. The supplied data also identifies IBM MQ, but does not provide affected versions or configuration details.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203