Release roundup
IBM week 38, September 2026: MQ and Verify Access flaws lead 74 CVEs
IBM week 38 covers 74 CVEs: 6 critical, 33 high, 32 medium, 3 low. None is exploited or in CISA KEV. Prioritise MQ Appliance pre-auth CVE-2026-10747, then unauthenticated RCE in MQ and Verify Identity Access, Sterling File Gateway auth bypass, and authenticated MQ code-execution flaws.
The release at a glance
IBM’s week 38 advisory set, published between 14 and 20 September 2026, covers 74 CVEs. The severity distribution is 6 critical, 33 high, 32 medium and 3 low. No CVE in this release is marked as exploited, and none appears in CISA KEV. The most urgent items cluster in the IBM MQ family, Verify Identity Access and Sterling File Gateway. One pre-authentication heap buffer overflow in IBM MQ Appliance is rated CVSS 10.0. Other critical issues include unauthenticated remote code execution in IBM MQ, a buffer overflow in Verify Identity Access, an authentication bypass in Sterling File Gateway, and a critical heap underflow in MQ for HPE NonStop. IBM has published fixes for the most important CVEs.
What matters most
First look at these CVEs.
IBM MQ Appliance: CVE-2026-10747 is a heap buffer overflow in protocol message processing before authentication. A remote attacker could cause a denial of service or potentially execute arbitrary code. CVSS 3.1 base score is 10.0, critical.
IBM MQ: CVE-2026-12351 is unauthenticated remote code execution via unsafe JNDI lookup processing when the IVT application is deployed (CVSS 9.8). CVE-2026-11725 is an integer overflow in MQINQ request processing; an authenticated attacker could cause denial of service or potentially execute arbitrary code (CVSS 8.8). CVE-2026-12728 is a Java messaging deserialisation flaw that an authenticated attacker could use for arbitrary code execution (CVSS 8.8).
IBM MQ for HPE NonStop: CVE-2026-10858 is a heap buffer underflow when processing multi-segment messages. An authenticated attacker could cause denial of service or potentially execute code (CVSS 9.9).
Verify Identity Access / Security Verify Access: CVE-2026-11928 is a buffer overflow reachable over the network without authentication (CVSS 9.8). CVE-2026-11921 affects containers that may not apply management password change operations correctly (CVSS 9.1).
Sterling File Gateway: CVE-2026-75878 is an authentication bypass through an unvalidated SSO header; a remote attacker could obtain a fully authenticated session (CVSS 9.1).
Patch in this order
Patch in this order:
- IBM MQ Appliance — CVE-2026-10747. This pre-authentication heap buffer overflow is rated CVSS 10.0. Treat any MQ Appliance reachable over the network, especially internet-facing ones, as the first action.
- IBM MQ — CVE-2026-12351. Unauthenticated remote code execution through unsafe JNDI lookup applies when the IVT application is deployed. Confirm whether IVT is present and patch those systems before other MQ items.
- Sterling File Gateway — CVE-2026-75878. Authentication bypass via an unvalidated SSO header can give a remote attacker a fully authenticated session. Patch internet-facing file transfer gateways promptly.
- Verify Identity Access / Security Verify Access — CVE-2026-11928 and CVE-2026-11921. The buffer overflow is reachable without authentication, and container deployments may not apply password changes correctly. Address identity infrastructure early.
- IBM MQ for HPE NonStop — CVE-2026-10858, and IBM MQ CVE-2026-11725, CVE-2026-10575, CVE-2026-11375, CVE-2026-11378, CVE-2026-11381, CVE-2026-12728. These authenticated high-severity issues can lead to denial of service or code execution. Move through them after pre-authentication issues.
- Remaining high, medium and low CVEs across MQ, Verify Identity Access, Db2, WebSphere Application Server, QRadar, Sterling B2B Integrator, Secure Proxy and CICS TX Advanced. Apply through normal change management.
Beyond the patch
Next month, make IBM weeks a review of queue managers and identity infrastructure: identify which MQ Appliance, MQ, Verify Identity Access and Sterling File Gateway instances are reachable and whether IVT is deployed before the patch window. Virtual CISO Services (vCISO) can help map that exposure and prioritise network-reachable, pre-authentication issues, while Managed Detection & Response (MDR) can watch for code execution, privilege escalation or credential abuse that follows a successful exploit.
Every CVE in this release
| CVE | Product | Severity | |
|---|---|---|---|
| CVE-2026-10747 | MQ Appliance | Critical 10.0 | Advisory → |
| CVE-2026-10858 | MQ for HPE NonStop | Critical 9.9 | Advisory → |
| CVE-2026-12351 | MQ | Critical 9.8 | Advisory → |
| CVE-2026-11928 | Verify Identity Access | Critical 9.8 | Advisory → |
| CVE-2026-75878 | Sterling File Gateway | Critical 9.1 | Advisory → |
| CVE-2026-11725 | MQ | High 8.8 | |
| CVE-2026-11921 | Verify Identity Access | Critical 9.1 | Advisory → |
| CVE-2026-10575 | MQ | High 8.8 | |
| CVE-2026-11375 | MQ | High 8.8 | |
| CVE-2026-11378 | MQ | High 8.8 | |
| CVE-2026-11381 | MQ for HPE NonStop | High 8.8 | |
| CVE-2026-12728 | MQ | High 8.8 | |
| CVE-2026-13293 | MQ | High 8.8 | |
| CVE-2026-11729 | MQ | High 8.5 | |
| CVE-2026-11726 | MQ for HPE NonStop | High 8.1 | |
| CVE-2026-11727 | MQ for HPE NonStop | High 8.1 | |
| CVE-2026-10027 | MQ | High 8.1 | |
| CVE-2026-12355 | MQ | High 8.1 | |
| CVE-2026-12101 | Verify Identity Access | High 8.1 | Advisory → |
| CVE-2026-11728 | MQ | High 8.1 | |
| CVE-2026-12666 | MQ | High 8.1 | |
| CVE-2026-11716 | MQ for HPE NonStop | High 7.5 | |
| CVE-2026-10744 | MQ for HPE NonStop | High 7.5 | |
| CVE-2026-10751 | MQ | High 7.5 | |
| CVE-2026-10853 | MQ | High 7.5 | |
| CVE-2026-12358 | Verify Identity Access | High 7.5 | Advisory → |
| CVE-2026-12354 | MQ | High 7.5 | |
| CVE-2026-11926 | Verify Identity Access | High 7.5 | Advisory → |
| CVE-2026-11929 | Verify Identity Access | High 7.5 | Advisory → |
| CVE-2026-19290 | Sterling File Gateway | High 7.5 | |
| CVE-2026-15955 | Db2 | High 7.5 | |
| CVE-2026-13260 | Verify Identity Access | High 7.5 | Advisory → |
| CVE-2026-10030 | MQ | High 7.1 | |
| CVE-2026-11934 | Verify Identity Access | High 7.2 | Advisory → |
| CVE-2026-12667 | MQ | High 7.1 | |
| CVE-2026-13287 | MQ | High 7.1 | |
| CVE-2026-13285 | MQ | High 7.1 | |
| CVE-2026-13275 | MQ | High 7.1 | |
| CVE-2026-12150 | MQ | High 7.0 | |
| CVE-2026-11711 | WebSphere Application Server | Medium 6.5 |
Show all 74
| CVE | Product | Severity | |
|---|---|---|---|
| CVE-2026-11549 | CICS TX Advanced | Medium 6.5 | |
| CVE-2026-11710 | WebSphere Application Server | Medium 6.5 | |
| CVE-2025-33141 | QRadar | Medium 6.5 | |
| CVE-2026-13265 | MQ | Medium 6.8 | |
| CVE-2026-11927 | Verify Identity Access | Medium 6.5 | Advisory → |
| CVE-2026-17463 | Db2 | Medium 6.5 | |
| CVE-2026-16702 | Db2 | Medium 6.5 | |
| CVE-2026-16187 | WebSphere Application Server | Medium 6.5 | |
| CVE-2026-15634 | WebSphere Application Server | Medium 6.5 | |
| CVE-2026-15412 | WebSphere Application Server | Medium 6.5 | |
| CVE-2026-15396 | WebSphere Application Server | Medium 6.5 | |
| CVE-2026-16185 | WebSphere Application Server | Medium 6.4 | |
| CVE-2026-13276 | Verify Identity Access | Medium 6.1 | |
| CVE-2026-16435 | WebSphere Application Server | Medium 5.9 | |
| CVE-2026-11539 | WebSphere Application Server | Medium 5.3 | |
| CVE-2026-11540 | WebSphere Application Server | Medium 5.3 | |
| CVE-2025-13882 | Sterling Partner Engagement Manager Essentials Edition | Medium 5.3 | |
| CVE-2026-78415 | Sterling Secure Proxy | Medium 5.4 | |
| CVE-2026-19273 | Sterling B2B Integrator | Medium 5.4 | |
| CVE-2026-17047 | Db2 Mirror for i | Medium 5.4 | |
| CVE-2026-16186 | WebSphere Application Server | Medium 5.4 | |
| CVE-2026-15887 | WebSphere Application Server | Medium 5.4 | |
| CVE-2026-13272 | Verify Identity Access | Medium 5.4 | |
| CVE-2026-16188 | WebSphere Application Server | Medium 5.3 | |
| CVE-2026-11548 | CICS TX Advanced | Medium 4.8 | |
| CVE-2026-11722 | CICS TX Advanced | Medium 4.8 | |
| CVE-2026-16189 | WebSphere Application Server | Medium 4.8 | |
| CVE-2026-13277 | Verify Identity Access | Medium 4.7 | |
| CVE-2026-11537 | WebSphere Application Server | Medium 4.3 | |
| CVE-2026-10841 | CICS TX Advanced | Medium 4.2 | |
| CVE-2026-75792 | Sterling Secure Proxy | Medium 4.3 | |
| CVE-2026-11538 | WebSphere Application Server | Low 3.7 | |
| CVE-2026-11545 | WebSphere Application Server | Low 3.7 | |
| CVE-2026-16190 | WebSphere Application Server | Low 3.1 |
References
Vendor advisory
- IBM MQ Appliance is affected by a heap buffer overflow vulnerability in protocol messag…
- IBM MQ for HPE NonStop is vulnerable to a denial of service attack
- IBM MQ is vulnerable to unauthenticated remote code execution via JNDI injection
- Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Secu…
- IBM Sterling File Gateway is Vulnerable to Authentication Bypass
- IBM MQ queue manager is vulnerable to privilege escalation
- IBM MQ queue manager is vulnerable to remote code execution
- IBM MQ queue manager is vulnerable to remote code execution
CVE
- CVE-2026-10747 — cve.org
- CVE-2026-10747 — NVD
- CVE-2026-10858 — cve.org
- CVE-2026-10858 — NVD
- CVE-2026-12351 — cve.org
- CVE-2026-12351 — NVD
- CVE-2026-11928 — cve.org
- CVE-2026-11928 — NVD
- CVE-2026-75878 — cve.org
- CVE-2026-75878 — NVD
- CVE-2026-11725 — cve.org
- CVE-2026-11725 — NVD
- CVE-2026-11921 — cve.org
- CVE-2026-11921 — NVD
- CVE-2026-10575 — cve.org
- CVE-2026-10575 — NVD
- CVE-2026-11375 — cve.org
- CVE-2026-11375 — NVD
- CVE-2026-11378 — cve.org
- CVE-2026-11378 — NVD
- CVE-2026-11381 — cve.org
- CVE-2026-11381 — NVD
- CVE-2026-12728 — cve.org
- CVE-2026-12728 — NVD