securityonline.info 20 Sept 2026, 19:20 UTC

IBM MQ Flaws Enable Pre-Authentication Code Execution and DoS

IBM MQ Flaws Enable Pre-Authentication Code Execution and DoS
CyberSIXT Evidence Panel Source marked as original reporting
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

IBM MQ has two newly reported vulnerabilities in message processing, including CVE-2026-10747, rated 10.0 (Critical) under CVSSv3, and CVE-2026-10858, rated 9.9. IBM’s advisories describe CVE-2026-10747 as a heap buffer overflow in protocol message processing before authentication. A remote attacker could potentially trigger a denial of service or execute arbitrary code. CVE-2026-10858 involves a heap buffer underflow when processing multi-segment messages and could cause a denial of service. The article says neither vulnerability has been confirmed as exploited in the wild, and no public proof of concept has been reported.

CVE-2026-10747 affects IBM MQ Appliance 9.4 LTS versions 9.4.0.0 through 9.4.0.25, as well as 9.4 CD and 10.0.0.0 releases. CVE-2026-10858 affects IBM MQ for HPE NonStop versions 8.1.0 through 8.1.0.40. IBM recommends prompt remediation: MQ Appliance users should upgrade to fix pack 9.4.0.26 or later, while HPE NonStop users should install CSU 8.1.0.41. The article states that no temporary workarounds are available for either buffer-handling flaw.

View full article

Article by CyberSIXT