Skip to content

Release roundup

IBM week 38, September 2026: MQ and Verify Access flaws lead 74 CVEs

Critical 10.0 Vendor: IBM 74 CVEs in scope Published

IBM week 38 covers 74 CVEs: 6 critical, 33 high, 32 medium, 3 low. None is exploited or in CISA KEV. Prioritise MQ Appliance pre-auth CVE-2026-10747, then unauthenticated RCE in MQ and Verify Identity Access, Sterling File Gateway auth bypass, and authenticated MQ code-execution flaws.

The release at a glance

IBM’s week 38 advisory set, published between 14 and 20 September 2026, covers 74 CVEs. The severity distribution is 6 critical, 33 high, 32 medium and 3 low. No CVE in this release is marked as exploited, and none appears in CISA KEV. The most urgent items cluster in the IBM MQ family, Verify Identity Access and Sterling File Gateway. One pre-authentication heap buffer overflow in IBM MQ Appliance is rated CVSS 10.0. Other critical issues include unauthenticated remote code execution in IBM MQ, a buffer overflow in Verify Identity Access, an authentication bypass in Sterling File Gateway, and a critical heap underflow in MQ for HPE NonStop. IBM has published fixes for the most important CVEs.

What matters most

First look at these CVEs.

IBM MQ Appliance: CVE-2026-10747 is a heap buffer overflow in protocol message processing before authentication. A remote attacker could cause a denial of service or potentially execute arbitrary code. CVSS 3.1 base score is 10.0, critical.

IBM MQ: CVE-2026-12351 is unauthenticated remote code execution via unsafe JNDI lookup processing when the IVT application is deployed (CVSS 9.8). CVE-2026-11725 is an integer overflow in MQINQ request processing; an authenticated attacker could cause denial of service or potentially execute arbitrary code (CVSS 8.8). CVE-2026-12728 is a Java messaging deserialisation flaw that an authenticated attacker could use for arbitrary code execution (CVSS 8.8).

IBM MQ for HPE NonStop: CVE-2026-10858 is a heap buffer underflow when processing multi-segment messages. An authenticated attacker could cause denial of service or potentially execute code (CVSS 9.9).

Verify Identity Access / Security Verify Access: CVE-2026-11928 is a buffer overflow reachable over the network without authentication (CVSS 9.8). CVE-2026-11921 affects containers that may not apply management password change operations correctly (CVSS 9.1).

Sterling File Gateway: CVE-2026-75878 is an authentication bypass through an unvalidated SSO header; a remote attacker could obtain a fully authenticated session (CVSS 9.1).

Patch in this order

Patch in this order:

  1. IBM MQ Appliance — CVE-2026-10747. This pre-authentication heap buffer overflow is rated CVSS 10.0. Treat any MQ Appliance reachable over the network, especially internet-facing ones, as the first action.
  2. IBM MQ — CVE-2026-12351. Unauthenticated remote code execution through unsafe JNDI lookup applies when the IVT application is deployed. Confirm whether IVT is present and patch those systems before other MQ items.
  3. Sterling File Gateway — CVE-2026-75878. Authentication bypass via an unvalidated SSO header can give a remote attacker a fully authenticated session. Patch internet-facing file transfer gateways promptly.
  4. Verify Identity Access / Security Verify Access — CVE-2026-11928 and CVE-2026-11921. The buffer overflow is reachable without authentication, and container deployments may not apply password changes correctly. Address identity infrastructure early.
  5. IBM MQ for HPE NonStop — CVE-2026-10858, and IBM MQ CVE-2026-11725, CVE-2026-10575, CVE-2026-11375, CVE-2026-11378, CVE-2026-11381, CVE-2026-12728. These authenticated high-severity issues can lead to denial of service or code execution. Move through them after pre-authentication issues.
  6. Remaining high, medium and low CVEs across MQ, Verify Identity Access, Db2, WebSphere Application Server, QRadar, Sterling B2B Integrator, Secure Proxy and CICS TX Advanced. Apply through normal change management.

Beyond the patch

Next month, make IBM weeks a review of queue managers and identity infrastructure: identify which MQ Appliance, MQ, Verify Identity Access and Sterling File Gateway instances are reachable and whether IVT is deployed before the patch window. Virtual CISO Services (vCISO) can help map that exposure and prioritise network-reachable, pre-authentication issues, while Managed Detection & Response (MDR) can watch for code execution, privilege escalation or credential abuse that follows a successful exploit.

Every CVE in this release

CVEProductSeverity
CVE-2026-10747MQ ApplianceCritical 10.0Advisory →
CVE-2026-10858MQ for HPE NonStopCritical 9.9Advisory →
CVE-2026-12351MQCritical 9.8Advisory →
CVE-2026-11928Verify Identity AccessCritical 9.8Advisory →
CVE-2026-75878Sterling File GatewayCritical 9.1Advisory →
CVE-2026-11725MQHigh 8.8
CVE-2026-11921Verify Identity AccessCritical 9.1Advisory →
CVE-2026-10575MQHigh 8.8
CVE-2026-11375MQHigh 8.8
CVE-2026-11378MQHigh 8.8
CVE-2026-11381MQ for HPE NonStopHigh 8.8
CVE-2026-12728MQHigh 8.8
CVE-2026-13293MQHigh 8.8
CVE-2026-11729MQHigh 8.5
CVE-2026-11726MQ for HPE NonStopHigh 8.1
CVE-2026-11727MQ for HPE NonStopHigh 8.1
CVE-2026-10027MQHigh 8.1
CVE-2026-12355MQHigh 8.1
CVE-2026-12101Verify Identity AccessHigh 8.1Advisory →
CVE-2026-11728MQHigh 8.1
CVE-2026-12666MQHigh 8.1
CVE-2026-11716MQ for HPE NonStopHigh 7.5
CVE-2026-10744MQ for HPE NonStopHigh 7.5
CVE-2026-10751MQHigh 7.5
CVE-2026-10853MQHigh 7.5
CVE-2026-12358Verify Identity AccessHigh 7.5Advisory →
CVE-2026-12354MQHigh 7.5
CVE-2026-11926Verify Identity AccessHigh 7.5Advisory →
CVE-2026-11929Verify Identity AccessHigh 7.5Advisory →
CVE-2026-19290Sterling File GatewayHigh 7.5
CVE-2026-15955Db2High 7.5
CVE-2026-13260Verify Identity AccessHigh 7.5Advisory →
CVE-2026-10030MQHigh 7.1
CVE-2026-11934Verify Identity AccessHigh 7.2Advisory →
CVE-2026-12667MQHigh 7.1
CVE-2026-13287MQHigh 7.1
CVE-2026-13285MQHigh 7.1
CVE-2026-13275MQHigh 7.1
CVE-2026-12150MQHigh 7.0
CVE-2026-11711WebSphere Application ServerMedium 6.5
Show all 74
CVEProductSeverity
CVE-2026-11549CICS TX AdvancedMedium 6.5
CVE-2026-11710WebSphere Application ServerMedium 6.5
CVE-2025-33141QRadarMedium 6.5
CVE-2026-13265MQMedium 6.8
CVE-2026-11927Verify Identity AccessMedium 6.5Advisory →
CVE-2026-17463Db2Medium 6.5
CVE-2026-16702Db2Medium 6.5
CVE-2026-16187WebSphere Application ServerMedium 6.5
CVE-2026-15634WebSphere Application ServerMedium 6.5
CVE-2026-15412WebSphere Application ServerMedium 6.5
CVE-2026-15396WebSphere Application ServerMedium 6.5
CVE-2026-16185WebSphere Application ServerMedium 6.4
CVE-2026-13276Verify Identity AccessMedium 6.1
CVE-2026-16435WebSphere Application ServerMedium 5.9
CVE-2026-11539WebSphere Application ServerMedium 5.3
CVE-2026-11540WebSphere Application ServerMedium 5.3
CVE-2025-13882Sterling Partner Engagement Manager Essentials EditionMedium 5.3
CVE-2026-78415Sterling Secure ProxyMedium 5.4
CVE-2026-19273Sterling B2B IntegratorMedium 5.4
CVE-2026-17047Db2 Mirror for iMedium 5.4
CVE-2026-16186WebSphere Application ServerMedium 5.4
CVE-2026-15887WebSphere Application ServerMedium 5.4
CVE-2026-13272Verify Identity AccessMedium 5.4
CVE-2026-16188WebSphere Application ServerMedium 5.3
CVE-2026-11548CICS TX AdvancedMedium 4.8
CVE-2026-11722CICS TX AdvancedMedium 4.8
CVE-2026-16189WebSphere Application ServerMedium 4.8
CVE-2026-13277Verify Identity AccessMedium 4.7
CVE-2026-11537WebSphere Application ServerMedium 4.3
CVE-2026-10841CICS TX AdvancedMedium 4.2
CVE-2026-75792Sterling Secure ProxyMedium 4.3
CVE-2026-11538WebSphere Application ServerLow 3.7
CVE-2026-11545WebSphere Application ServerLow 3.7
CVE-2026-16190WebSphere Application ServerLow 3.1

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.