Description
IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.
Published: 2026-09-18
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

IBM MQ Appliance suffers from a heap buffer overflow that occurs during processing of protocol messages before authentication is completed. The flaw can be exploited by sending a crafted message that triggers the overflow, which may result in a denial of service or, in the worst case, the execution of arbitrary code on the appliance. This weakness is identified as CWE-122. The urgent nature of the flaw stems from its ability to compromise confidentiality, integrity, and availability of the messaging system. The likely attack vector is an unauthenticated remote attacker targeting the appliance’s messaging ports with a malformed protocol message. Based on the description, it is inferred that the attacker does not need to gain prior authentication to trigger the vulnerability.

Affected Systems

The vulnerability affects all IBM MQ Appliance releases that were listed in the CNA solution. For the 9.4 LTS stream, every build from 9.4.0.0 onward is impacted, and the fix is supplied in fix pack 9.4.0.26 or later firmware. In the 9.4 CD stream, the M2003 revision requires an upgrade to 10.0.0.5 or newer firmware, while the M2002 revision can be mitigated by applying the cumulative security update 9.4.5.3 or later firmware. All 10 LTS releases are affected and a fix pack 10.0.0.5 or newer is required.

Risk and Exploitability

With a CVSS score of 10, this flaw represents the maximum severity. The EPSS score of < 1% indicates a low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, but that does not diminish its seriousness. Attackers who can reach the appliance’s messaging ports may trigger the heap overflow by sending a malicious message before authentication, potentially causing a denial of service or executing code with privileged rights on the appliance. Immediate patching is strongly advised to mitigate this critical risk.

Generated by OpenCVE AI on September 19, 2026 at 17:56 UTC.

Remediation

Vendor Solution

This vulnerability is addressed under APAR DT472411 IBM strongly recommends addressing the vulnerability now. IBM MQ Appliance version 9.4 LTS Apply IBM MQ Appliance fix pack 9.4.0.26 https://www.ibm.com/support/fixcentral/swg/selectFixes , or later firmware. IBM MQ Appliance version 9.4 CD - M2003 Upgrade to IBM MQ Appliance 10.0.0.5 https://www.ibm.com/support/fixcentral/swg/selectFixes , or later firmware. IBM MQ Appliance version 9.4 CD - M2002 Apply  IBM MQ Appliance cumulative security update 9.4.5.3 https://www.ibm.com/support/fixcentral/swg/selectFixes , or later firmware. IBM MQ Appliance version 10 LTS Apply IBM MQ Appliance fix pack 10.0.0.5 https://www.ibm.com/support/fixcentral/swg/selectFixes , or later firmware.


OpenCVE Recommended Actions

  • Apply IBM MQ Appliance fix pack 9.4.0.26 (or later firmware) for 9.4 LTS systems.
  • Apply IBM MQ Appliance cumulative security update 9.4.5.3 (or later firmware) for 9.4 CD – M2002 installations.
  • Upgrade to IBM MQ Appliance 10.0.0.5 (or later firmware) for 9.4 CD – M2003 installations and all 10 LTS systems.
  • Restrict inbound traffic to the appliance’s messaging ports, allowing only trusted hosts to connect and preventing unauthenticated clients from communicating directly.

Generated by OpenCVE AI on September 19, 2026 at 17:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.
Title IBM MQ Appliance is affected by a heap buffer overflow vulnerability in protocol message processing
First Time appeared Ibm
Ibm mq Appliance
Weaknesses CWE-122
CPEs cpe:2.3:a:ibm:mq_appliance:10.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq_appliance:10.0.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq_appliance:9.4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq_appliance:9.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq_appliance:9.4.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq_appliance:9.4:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm mq Appliance
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Ibm Mq Appliance
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-21T12:47:23.571Z

Reserved: 2026-06-03T13:39:03.419Z

Link: CVE-2026-10747

cve-icon Vulnrichment

Updated: 2026-09-21T12:45:06.633Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T16:17:04.413

Modified: 2026-09-21T13:17:07.147

Link: CVE-2026-10747

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T18:00:13Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow