Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-10747: IBM MQ Appliance may crash or be taken over

CVE-2026-10747 · published 10 days ago
Summary

The IBM MQ Appliance can be tricked by specially crafted network messages to overflow its memory before a user logs in. This could cause the system to stop working or allow an attacker to run their own code. Apply the latest IBM security patch or update to a newer version as soon as possible.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
ibm mq appliance <= 9.4.0.0 to 9.4.0.25
Original advisory text
IBM MQ Appliance is affected by a heap buffer overflow vulnerability in protocol message processing
IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.
Severity
10.0 Critical
CVSS 3.1: 10.0 (NVD)
Exploitation
EPSS <1%
Type
CWE-122Heap-based Buffer Overflow
Timeline
Published18 Sep 2026
Updated27 Sep 2026
First seen18 Sep 2026
Sources
CVE-2026-10747 · MITRE
Track software like this
Free during beta