Executive brief
IBM MQ Appliance is a messaging middleware used by enterprises to route and queue business-critical messages across systems. A heap buffer overflow vulnerability in its protocol message handling allows unauthenticated remote attackers to crash the service or execute arbitrary code, potentially compromising message confidentiality, integrity, and availability before any authentication can occur.
Technical details
This is a heap-based buffer overflow (CWE-122) in IBM MQ Appliance's protocol message processing logic. The vulnerability is triggered during unauthenticated protocol parsing, meaning an attacker needs only network access to the messaging port—no credentials or prior authentication required. Exploitation can lead to denial of service or remote code execution with full system compromise. Patches are available via fix packs and firmware updates for all affected version branches (9.4 LTS, 9.4 CD, and 10.0 LTS).
Affected products
- IBM MQ Appliance 9.4 LTS (9.4.0.0–9.4.0.25), 9.4 CD (9.4.1.0–9.4.5.2), 10.0.0.0–10.0.0.1
Timeline
- 2026-09-18: disclosed: IBM security bulletin published
- 2026-09-10: patched: Patches available: MQ Appliance 9.4 LTS fix pack 9.4.0.26+, 9.4 CD cumulative security update 9.4.5.3+, 10.0 LTS fix pack 10.0.0.5+