TL;DR
Security researchers recently uncovered critical IBM MQ vulnerabilities impacting message processing systems. Specifically, these severe heap buffer overflows allow remote attackers to trigger denial of service conditions or execute arbitrary code. Consequently, administrators must prioritize immediate firmware updates to secure affected messaging appliances.
- Product: IBM (2 products)
- Vulnerabilities: 2 flaws (CVE-2026-10747, CVE-2026-10858)
- Highest severity: 10.0 (Critical · CVSSv3)
- Worst impact: is affected by a heap buffer overflow in protocol message processing
- Status: No confirmed exploitation yet
- Action: See vendor advisories
| CVE | CVSS (CVSSv3) | Type | Status |
|---|---|---|---|
| CVE-2026-10747 | 10 | is affected by a heap buffer overflow in protocol message processing | Not exploited |
| CVE-2026-10858 | 9.9 | is vulnerable to a denial of service attack | Not exploited |
Track every CVE that hits your stack the moment it's exploited.
Get free email alertsWhy It Matters
IBM MQ serves as a foundational data transmission backbone for thousands of global enterprise networks. Therefore, critical IBM MQ vulnerabilities threaten widespread operational stability and data integrity. Furthermore, a CVSS score of 10.0 highlights the extreme danger posed by unauthenticated remote code execution. If exploited, an attacker could halt business-critical messaging services completely. Fortunately, no in-the-wild exploitation or public proof-of-concept activity has been confirmed. Given the vast deployment footprint across financial sectors, patching remains an urgent priority. Ultimately, delaying remediation exposes sensitive enterprise infrastructure to potential disaster.
How The Attack Works
The first IBM security advisory details the primary flaw. For instance, the vendor notes, “IBM MQ could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.” Meanwhile, a separate security bulletin highlights a second issue. This second flaw triggers “due to a heap buffer underflow when processing multi-segment messages.” In practice, attackers send malformed data segments that exceed or bypass memory boundaries. The system fails to sanitize this input properly. As a result, the application crashes or allows unauthorized memory writes.
Affected Versions
These IBM MQ vulnerabilities affect multiple product lines. Specifically, the first flaw, CVE-2026-10747, impacts IBM MQ Appliance 9.4 LTS versions 9.4.0.0 through 9.4.0.25. Additionally, it also affects 9.4 CD and 10.0.0.0 releases. Conversely, the second flaw, CVE-2026-10858, impacts IBM MQ for HPE NonStop versions 8.1.0 through 8.1.0.40.
Patch Or Mitigation Steps
System administrators must apply official fixes immediately. For the MQ Appliance, upgrade to fix pack 9.4.0.26 or later. Simultaneously, HPE NonStop users must install CSU 8.1.0.41. The vendor explicitly states, “IBM strongly recommends addressing the vulnerability now.” Finally, no temporary workarounds exist for these buffer overflow flaws.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!