CVE-2026-10747: IBM MQ Appliance is affected by a heap buffer overflow vulnerability in protocol message processing
IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.
Other sources
IBM MQ could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM MQ Appliance 10.0.0.5to a version that resolves this vulnerability.Patch DT472411 - Upgrade
Upgrade
IBM MQ Applianceto a version that resolves this vulnerability.Fixed in 10.0.0.5 - Upgrade
Upgrade
IBM MQ Applianceto a version that resolves this vulnerability.Fixed in 9.4.0.26 - Upgrade
Upgrade
IBM MQ Applianceto a version that resolves this vulnerability.Fixed in 9.4.5.3
Event History
Frequently Asked Questions
Does exploitation require valid IBM MQ credentials or prior access?
No. The vulnerable protocol message processing occurs before authentication, and the vector indicates remote exploitation with no privileges or user interaction required.
What could an attacker achieve if exploitation succeeds?
An attacker could cause a denial of service or potentially execute arbitrary code. The reported impact includes high confidentiality, integrity, and availability impact.
Which deployments should be prioritized for triage?
IBM MQ Appliance deployments should be prioritized, particularly where their protocol service is reachable by untrusted remote systems. The supplied data also identifies IBM MQ, but does not provide affected versions or configuration details.