CVE-2026-10027 PUBLISHED

IBM MQ queue manager is vulnerable to unauthenticated remote code execution

Assigner: ibm
Reserved: 28.05.2026 Published: 18.09.2026 Updated: 19.09.2026

IBM MQ could allow a remote attacker to cause a denial of service or execute arbitrary code due to a buffer overflow when processing malformed compressed data on channels configured with compression enabled.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 8.1

Product Status

Vendor IBM
Product MQ
Versions
  • affected from 9.1.0.0 to 9.1.0.37 LTS (incl.)
  • affected from 9.2.0.0 to 9.2.0.43 LTS (incl.)
  • affected from 9.3.0.0 to 9.3.0.41 LTS (incl.)
  • affected from 9.3.0.0 to 9.3.5.1 CD (incl.)
  • affected from 9.4.0.0 to 9.4.0.25 LTS (incl.)
  • affected from 9.4.0.0 to 9.4.5.1 CD (incl.)
  • Version 10.0.0.0 is affected

Solutions

This issue was addressed under Known Issue DT472389

IBM MQ version 9.1 LTS

Apply cumulative security update 9.1.0.38 https://www.ibm.com/support/pages/downloading-ibm-mq-91-lts

IBM MQ version 9.2 LTS

Apply cumulative security update 9.2.0.44 https://www.ibm.com/support/pages/downloading-ibm-mq-92-lts

IBM MQ version 9.3 LTS

Apply cumulative security update 9.3.0.42 https://www.ibm.com/support/pages/downloading-ibm-mq-93-lts

IBM MQ version 9.4 LTS

Apply cumulative security update https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts  9.4.0.26 https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts

IBM MQ version 9.3 CD, 9.4 CD and 10.0.0.0

Upgrade to IBM MQ version 10.0.0.5 https://www.ibm.com/support/pages/downloading-ibm-mq-100

References

Problem Types

  • CWE-787 Out-of-bounds Write CWE