CVE-2026-11375: IBM MQ queue manager is vulnerable to remote code execution
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a stack buffer overflow when processing XA transaction identifiers.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM MQ 9.1 LTSto a version that resolves this vulnerability.Fixed in 9.1.0.38 - Upgrade
Upgrade
IBM MQ 9.2 LTSto a version that resolves this vulnerability.Fixed in 9.2.0.44 - Upgrade
Upgrade
IBM MQ 9.3 LTSto a version that resolves this vulnerability.Fixed in 9.3.0.42 - Upgrade
Upgrade
IBM MQ 9.4 LTSto a version that resolves this vulnerability.Fixed in 9.4.0.26 - Upgrade
Upgrade
IBM MQto a version that resolves this vulnerability.Fixed in 10.0.0.5Patch DT473424
Event History
Frequently Asked Questions
Can an unauthenticated remote user exploit this issue?
The reported attack requires authentication. The available information does not indicate that unauthenticated users can exploit it.
What outcomes are possible if the flaw is exploited?
An authenticated attacker may cause a denial of service or potentially execute arbitrary code. The reported impact includes compromise of confidentiality, integrity, and availability.