Skip to content
THREATWIRE

CVE

CriticalNo PoC

CVE-2026-10747

IBM MQ pre-auth heap overflow in protocol message processing

IBM scored CVE-2026-10747 CVSS 3.1 10.0 for a heap buffer overflow in MQ protocol message processing before authentication. An unauthenticated remote attacker with access to the listener can cause denial of service or potentially execute code. Fixed in MQ CSUs such as 9.4.0.26 and 10.0.0.5. Not in CISA KEV.

CVSS
10
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Class
RCE
Status
No PoC
KEV
Not in CISA KEV
0-day
No
Vendor
IBM
Products
IBM MQ, IBM MQ Appliance
Affected
IBM MQ Server: 9.1.0.0–9.1.0.37 LTS; 9.2.0.0–9.2.0.43 LTS; 9.3.0.0–9.3.0.41 LTS; 9.3.0.0–9.3.5.1 CD; 9.4.0.0–9.4.0.25 LTS; 9.4.0.0–9.4.5.1 CD; 10.0.0.0. IBM MQ Appliance: 9.4.0.0–9.4.0.25 LTS; 9.4.1.0–9.4.5.2 CD; 10.0.0.0–10.0.0.1.
Fixed
IBM MQ: CSU 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26 LTS; CD streams upgrade to 10.0.0.5. IBM MQ Appliance: 9.4.0.26 LTS; 9.4.5.3 (M2002 CD); 10.0.0.5 (M2003 CD and 10 LTS). APAR DT472411. No workarounds listed.
Published
18 Sept 2026
Updated
5 Oct 2026

No public PoC is confirmed on this record.

CVE-2026-10747 is a heap-based buffer overflow in IBM MQ protocol message processing before authentication. IBM’s MQ Server bulletin says an unauthenticated remote attacker with network access to the listener port could execute arbitrary code. The same CVE is covered for IBM MQ Appliance. IBM classifies the weakness as CWE-122 and publishes CVSS 3.1 score 10.0 with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. NVD lists that score from psirt@us.ibm.com as Secondary and marks the entry Awaiting Analysis. Impact language is denial of service or potentially arbitrary code execution.

Affected IBM MQ Server ranges in the bulletin include 9.1 through 9.4 LTS/CD builds up to the versions named above and 10.0.0.0; only the Server installable component is called out. Appliance ranges include 9.4 LTS through 9.4.0.25, 9.4 CD through 9.4.5.2, and 10.0.0.0–10.0.0.1. Remediation is under APAR DT472411: CSUs 9.1.0.38, 9.2.0.44, 9.3.0.42, and 9.4.0.26 for LTS; CD customers upgrade to 10.0.0.5; Appliance customers apply 9.4.0.26, 9.4.5.3, or 10.0.0.5 as listed. IBM lists no workarounds.

CISA has not added the CVE to KEV; CISA SSVC sets exploitation to none. ThreatWire found no public PoC repository for this CVE id. Exploitation in the wild is not confirmed.

Sources

Related writing

Share on X@threatwire_https://www.threatwire.tech/cve/cve-2026-10747