Skip to content

CVE-2026-10747

IBM MQ Appliance protocol message heap buffer overflow allows pre-authentication denial of service or code execution (CVE-2026-10747)

Critical 10.0 Vendor: IBM Published

IBM MQ Appliance has a critical pre-authentication heap buffer overflow in protocol message processing. A remote attacker can cause denial of service or potentially execute arbitrary code. IBM has a fix; no active exploitation is recorded.

What happened

IBM MQ Appliance has a heap buffer overflow, classified as CWE-122, in protocol message processing. The flaw is reachable over the network before authentication, with no privileges and no user interaction required. A remote attacker can cause a denial of service or potentially execute arbitrary code.

The CVSS 3.1 base score is 10.0: network attack vector, low attack complexity, no privileges, no user interaction, changed scope, and high impact on confidentiality, integrity and availability. Network reachability to the affected message-processing interface is the exposure.

The CVE record does not indicate active exploitation or public disclosure.

Who is affected

IBM MQ Appliance is affected in the following release lines:

  • 9.4 LTS to 9.4.0.0 to 9.4.0.25
  • 9.4 CD to 9.4.1.0 to 9.4.5.2
  • 10.0.0.0 to 10.0.0.1 only

MQ Appliance is messaging infrastructure and is typically deployed where applications exchange messages, so affected devices should be treated as critical network services.

What to do now

  1. Confirm your MQ Appliance release against the affected ranges above.
  2. Apply the IBM fix. The record indicates a fix is available but does not list fixed release numbers here; consult IBM Support node 7284690 for the fixed build for your release.
  3. If patching must be delayed, restrict network access to MQ Appliance listeners. Allow only trusted messaging peers and administrative networks, and block internet exposure.
  4. Monitor for unexpected restarts, crashes, or message-processing anomalies until remediation is complete.

IBM has not published a workaround in the advisory data, so network restriction is the main interim containment measure.

How to detect it

The vulnerability is reachable before authentication over the network, so the immediate task is exposure review: identify every affected MQ Appliance and determine which networks can reach its protocol listeners. IBM has not listed specific indicators of compromise or log signatures in the advisory data.

Beyond the patch

Because this flaw is reachable before authentication over the network, the exposure question matters as much as the patch. Virtual CISO Services (vCISO) can help identify and close unnecessary MQ Appliance network reach, while Managed Detection & Response (MDR) provides the endpoint and SIEM visibility to catch post-exploitation activity if code execution occurs. Apply the fix first, then reduce the reachability that made this vulnerability serious.

Affected and fixed versions

ProductAffectedFixed in
MQ Appliance9.4 LTS – ≤ 9.4.0.0 to 9.4.0.25
9.4 CD – ≤ 9.4.1.0 to 9.4.5.2
10.0.0.0 – ≤ 10.0.0.1 only
No fixed version listed yet

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.