IBM MQ patches CVE-2026-10747 and CVE-2026-10858
IBM published critical MQ fixes: CVE-2026-10747 is CVSS 10.0 pre-auth protocol heap overflow on the listener path, and CVE-2026-10858 is CVSS 9.9 authenticated multi-segment heap underflow on NonStop and Appliance. No KEV listing and no public PoC confirmed.
Published 5 Oct 2026
What happened
In September 2026 IBM published security bulletins for two critical IBM MQ memory-corruption CVEs. CVE-2026-10747 is a heap buffer overflow in protocol message processing before authentication. IBM scores it CVSS 3.1 10.0 with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H and CWE-122. The MQ Server bulletin states that an unauthenticated remote attacker with network access to the listener port could execute arbitrary code; a matching Appliance bulletin covers the same CVE.
CVE-2026-10858 is a heap buffer underflow when processing multi-segment messages. IBM scores it CVSS 3.1 9.9 with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, still CWE-122. Privileges Required is Low: the attacker must be authenticated. NVD published both records on 18 September 2026 as Awaiting Analysis, carrying IBM’s scores from psirt@us.ibm.com.
Who is affected
CVE-2026-10747 affects IBM MQ Server across named 9.1–9.4 LTS/CD ranges and 10.0.0.0, and IBM MQ Appliance on 9.4 LTS/CD and early 10.0 builds listed in the Appliance bulletin. Exposure is to the listener / protocol processing path before authentication.
CVE-2026-10858 is not limited to a single platform. The CVE.org and NVD text name IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40. IBM also published an MQ Appliance bulletin for the same CVE id covering Appliance 9.4 and early 10.0 firmware. Both issues require installing the IBM cumulative updates named below; IBM lists no workarounds.
What is confirmed
IBM is the CVSS source for both scores. For CVE-2026-10747, remediations are under APAR DT472411: Server CSUs 9.1.0.38, 9.2.0.44, 9.3.0.42, and 9.4.0.26, with CD streams moving to 10.0.0.5, and Appliance 9.4.0.26 / 9.4.5.3 / 10.0.0.5 as applicable. For CVE-2026-10858, NonStop customers install CSU 8.1.0.41 (IT49924), and Appliance customers apply the DT472680 fixes (9.4.0.26, 9.4.5.3, or 10.0.0.5). CISA has not listed either CVE in KEV. CISA SSVC sets exploitation to none for both. No public PoC repository was confirmed for either CVE id.
What is not confirmed
Exploitation in the wild is not confirmed for either CVE. Social posts that treat CVE-2026-10858 as NonStop-only omit the IBM MQ Appliance bulletin for that same CVE. Posts that imply CVE-2026-10858 is pre-authentication contradict IBM’s PR:L vector and “authenticated attacker” wording. IBM’s MQ 9.4/10.0 LTS fix lists also tag DT472680 as covering “IBM MQ CVE-2026-10858 and IBM MQ Appliance,” but ThreatWire did not locate a separate standalone MQ Server security-bulletin page for 10858 beyond NonStop and Appliance; treat wider Server exposure as needing confirmation from IBM’s product-specific bulletin if one appears. Neither CVE has a confirmed public exploit.
What to do
Prioritize CVE-2026-10747 on any internet-reachable or broadly network-exposed MQ listener: apply the matching CSU or Appliance firmware immediately. For CVE-2026-10858, upgrade NonStop to 8.1.0.41 and Appliance firmware to the DT472680 builds, and restrict who can authenticate to MQ channels until patched. After patching, verify installed levels against IBM’s Fix Central packages for your release stream.
Sources: IBM MQ and MQ Appliance bulletins for CVE-2026-10747, IBM MQ for HPE NonStop and MQ Appliance bulletins for CVE-2026-10858, NVD and CVE.org for both ids, and GitHub advisories GHSA-xp86-qf4h-97h5 and GHSA-cmx7-5fpv-xc6x.