IBM MQ has two newly reported vulnerabilities in message processing, including CVE-2026-10747, rated 10.0 (Critical) under CVSSv3, and CVE-2026-10858, rated 9.9. IBM’s advisories describe CVE-2026-10747 as a heap buffer overflow in protocol message processing before authentication. A remote attacker could potentially trigger a denial of service or execute arbitrary code. CVE-2026-10858 involves a heap buffer underflow when processing multi-segment messages and could cause a denial of service. The article says neither vulnerability has been confirmed as exploited in the wild, and no public proof of concept has been reported.
CVE-2026-10747 affects IBM MQ Appliance 9.4 LTS versions 9.4.0.0 through 9.4.0.25, as well as 9.4 CD and 10.0.0.0 releases. CVE-2026-10858 affects IBM MQ for HPE NonStop versions 8.1.0 through 8.1.0.40. IBM recommends prompt remediation: MQ Appliance users should upgrade to fix pack 9.4.0.26 or later, while HPE NonStop users should install CSU 8.1.0.41. The article states that no temporary workarounds are available for either buffer-handling flaw.