CVE-2026-10853: IBM MQ queue manager is vulnerable to remote code execution
IBM MQ could allow an authenticated attacker with cluster access to cause a denial of service or potentially execute arbitrary code due to improper validation of cluster command message lengths.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM MQ 9.1 LTSto a version that resolves this vulnerability.Fixed in 9.1.0.38 - Upgrade
Upgrade
IBM MQ 9.2 LTSto a version that resolves this vulnerability.Fixed in 9.2.0.44 - Upgrade
Upgrade
IBM MQ 9.3 LTSto a version that resolves this vulnerability.Fixed in 9.3.0.42 - Upgrade
Upgrade
IBM MQ 9.4 LTSto a version that resolves this vulnerability.Fixed in 9.4.0.26 - Upgrade
Upgrade
IBM MQ 10.0to a version that resolves this vulnerability.Fixed in 10.0.0.5 - Compensating control
If the affected IBM MQ versions/queue managers cannot be updated immediately, mitigate exposure by restricting cluster access to trusted clients/IPs to reduce the chance that an authenticated cluster-access attacker can send malformed cluster command messages.
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
An attacker must be authenticated and have access to an IBM MQ cluster. The attack is network-reachable, but it is not described as requiring user interaction.