Description
IBM MQ could allow a remote attacker to cause a denial of service or execute arbitrary code due to a buffer overflow when processing malformed compressed data on channels configured with compression enabled.
Published: 2026-09-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a buffer overflow caused by malformed compressed data processed on channels where compression is enabled. With a specially crafted packet, a remote attacker can trigger a denial of service or the execution of arbitrary code. This weakness is identified as CWE-787 and the resulting impact is remote code execution.

Affected Systems

IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.4 LTS, 9.3 CD, 9.4 CD, and 10.0.0.0 are affected. Each version requires update to the latest cumulative security release (v9.1.0.38, v9.2.0.44, v9.3.0.42, v9.4.0.26, or v10.0.0.5 for 10.0.0.0) to remediate the issue.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity, and the EPSS score of less than 1% indicates a very low but non‑zero exploitation probability, yet it is not listed in the CISA KEV catalog. The likely attack vector is a remote attacker delivering malformed compressed data to a channel established over the network, which triggers the buffer overflow. The resulting impact can be a denial of service or arbitrary code execution that may compromise the MQ system and the services that depend on it.

Generated by OpenCVE AI on September 19, 2026 at 17:21 UTC.

Remediation

Vendor Solution

This issue was addressed under Known Issue DT472389 IBM MQ version 9.1 LTS Apply cumulative security update 9.1.0.38 https://www.ibm.com/support/pages/downloading-ibm-mq-91-lts IBM MQ version 9.2 LTS Apply cumulative security update 9.2.0.44 https://www.ibm.com/support/pages/downloading-ibm-mq-92-lts IBM MQ version 9.3 LTS Apply cumulative security update 9.3.0.42 https://www.ibm.com/support/pages/downloading-ibm-mq-93-lts IBM MQ version 9.4 LTS Apply cumulative security update https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts  9.4.0.26 https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts IBM MQ version 9.3 CD, 9.4 CD and 10.0.0.0 Upgrade to IBM MQ version 10.0.0.5 https://www.ibm.com/support/pages/downloading-ibm-mq-100


OpenCVE Recommended Actions

  • Apply the IBM MQ cumulative security update for your installed version as listed.
  • If immediate patch is not possible, temporarily disable channel compression to mitigate exploitation risk.
  • Monitor for anomalous compressed data traffic on MQ channels and investigate any unexpected behavior.

Generated by OpenCVE AI on September 19, 2026 at 17:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:mq:*:*:*:*:continuous_delivery:*:*:*
cpe:2.3:a:ibm:mq:*:*:*:*:lts:*:*:*
cpe:2.3:a:ibm:mq:10.0.0.0:*:*:*:continuous_delivery:*:*:*

Mon, 21 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description IBM MQ could allow a remote attacker to cause a denial of service or execute arbitrary code due to a buffer overflow when processing malformed compressed data on channels configured with compression enabled.
Title IBM MQ queue manager is vulnerable to unauthenticated remote code execution
First Time appeared Ibm
Ibm mq
Weaknesses CWE-787
CPEs cpe:2.3:a:ibm:mq:10.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.1.0.37:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.2.0.43:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.41:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.5.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.25:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.5.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm mq
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-21T12:47:23.863Z

Reserved: 2026-05-28T18:23:10.142Z

Link: CVE-2026-10027

cve-icon Vulnrichment

Updated: 2026-09-21T12:45:11.517Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T16:17:03.873

Modified: 2026-09-23T18:32:57.060

Link: CVE-2026-10027

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T17:30:07Z

Weaknesses