CVE-2026-10747 PUBLISHED

IBM MQ Appliance is affected by a heap buffer overflow vulnerability in protocol message processing

Assigner: ibm
Reserved: 03.06.2026 Published: 18.09.2026 Updated: 19.09.2026

IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 10

Product Status

Vendor IBM
Product MQ Appliance
Versions
  • affected from 9.4 LTS to 9.4.0.0 to 9.4.0.25 (incl.)
  • affected from 9.4 CD to 9.4.1.0 to 9.4.5.2 (incl.)
  • affected from 10.0.0.0 to 10.0.0.1 only (incl.)

Solutions

This vulnerability is addressed under APAR DT472411

IBM strongly recommends addressing the vulnerability now.

IBM MQ Appliance version 9.4 LTS Apply IBM MQ Appliance fix pack 9.4.0.26 https://www.ibm.com/support/fixcentral/swg/selectFixes , or later firmware.

IBM MQ Appliance version 9.4 CD - M2003 Upgrade to IBM MQ Appliance 10.0.0.5 https://www.ibm.com/support/fixcentral/swg/selectFixes , or later firmware.

IBM MQ Appliance version 9.4 CD - M2002 Apply  IBM MQ Appliance cumulative security update 9.4.5.3 https://www.ibm.com/support/fixcentral/swg/selectFixes , or later firmware.

IBM MQ Appliance version 10 LTS Apply IBM MQ Appliance fix pack 10.0.0.5 https://www.ibm.com/support/fixcentral/swg/selectFixes , or later firmware.

References

Problem Types

  • CWE-122 Heap-based Buffer Overflow CWE