Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-10747: IBM MQ Appliance may crash or be taken over
CVE-2026-10747 · published 10 days ago
Summary
The IBM MQ Appliance can be tricked by specially crafted network messages to overflow its memory before a user logs in. This could cause the system to stop working or allow an attacker to run their own code. Apply the latest IBM security patch or update to a newer version as soon as possible.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ibm | mq appliance | <= 9.4.0.0 to 9.4.0.25 |
Original advisory text
IBM MQ Appliance is affected by a heap buffer overflow vulnerability in protocol message processing
IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.
Severity
10.0
Critical
CVSS 3.1: 10.0 (NVD)
Exploitation
EPSS <1%
Type
CWE-122Heap-based Buffer Overflow
Timeline
Published18 Sep 2026
Updated27 Sep 2026
First seen18 Sep 2026
Track software like this
Free during beta