Junglewise Threat Intelligence

CVE-2026-11375: IBM MQ stack buffer overflow in XA transaction handling

CVE-2026-11375 · Severity: high · CVSS 8.8 · Published 2026-09-18

Technologies: IBM Mq. Vendors: IBM.

Executive brief

IBM MQ is a message queue manager used by enterprises to reliably transport data between applications. A stack buffer overflow vulnerability in the XA transaction handling could allow an authenticated attacker to execute arbitrary code or crash the queue manager, potentially compromising critical business operations and data.

Technical details

A stack buffer overflow exists in IBM MQ's queue manager when processing crafted XA (distributed transaction) identifiers. The vulnerability requires authentication and network access, allowing an authenticated attacker to overflow a buffer and potentially achieve remote code execution or denial of service. Patches are available for all affected LTS and CD versions.

Affected products

  • IBM MQ 9.1.0.0–9.1.0.37 LTS, 9.2.0.0–9.2.0.43 LTS, 9.3.0.0–9.3.0.41 LTS, 9.3.0.0–9.3.5.1 CD, 9.4.0.0–9.4.0.25 LTS, 9.4.0.0–9.4.5.1 CD, 10.0.0.0

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: Patches available: 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26, and 10.0.0.5

References

Related threats