Junglewise Threat Intelligence

CVE-2026-10747: IBM MQ Appliance heap buffer overflow in protocol processing

CVE-2026-10747 · Severity: critical · CVSS 10 · Published 2026-09-18

Vendors: IBM.

Executive brief

IBM MQ Appliance is a messaging middleware used by enterprises to route and queue business-critical messages across systems. A heap buffer overflow vulnerability in its protocol message handling allows unauthenticated remote attackers to crash the service or execute arbitrary code, potentially compromising message confidentiality, integrity, and availability before any authentication can occur.

Technical details

This is a heap-based buffer overflow (CWE-122) in IBM MQ Appliance's protocol message processing logic. The vulnerability is triggered during unauthenticated protocol parsing, meaning an attacker needs only network access to the messaging port—no credentials or prior authentication required. Exploitation can lead to denial of service or remote code execution with full system compromise. Patches are available via fix packs and firmware updates for all affected version branches (9.4 LTS, 9.4 CD, and 10.0 LTS).

Affected products

  • IBM MQ Appliance 9.4 LTS (9.4.0.0–9.4.0.25), 9.4 CD (9.4.1.0–9.4.5.2), 10.0.0.0–10.0.0.1

Timeline

  • 2026-09-18: disclosed: IBM security bulletin published
  • 2026-09-10: patched: Patches available: MQ Appliance 9.4 LTS fix pack 9.4.0.26+, 9.4 CD cumulative security update 9.4.5.3+, 10.0 LTS fix pack 10.0.0.5+

References