Index
Search
Search the public record. Drafts and scheduled notes are not included.
news
IBM MQ patches CVE-2026-10747 and CVE-2026-10858
IBM published critical MQ fixes: CVE-2026-10747 is CVSS 10.0 pre-auth protocol heap overflow on the listener path, and CVE-2026-10858 is CVSS 9.9 authenticated multi-segment heap underflow on NonStop and Appliance. No KEV listing and no public PoC confirmed.
Published 3h ago
research
The Roundcube SQL injection is not in the CISA catalog
CVE-2026-48842 is a pre-authentication SQL injection in Roundcube virtuser_query, fixed in May 2026. A public PoC exists. CISA has not listed it, so ThreatWire does not mark Active Exploitation.
Published 6h ago
CVE-2026-10747
IBM MQ pre-auth heap overflow in protocol message processing
RCE
Published 18 Sept 2026
CVE-2026-10858
IBM MQ authenticated heap underflow on multi-segment messages
RCE
Published 18 Sept 2026
CVE-2026-48842
Roundcube virtuser_query SQL injection
SQLi
Published 25 May 2026