Description
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote attacker to cause a denial of service or potentially execute arbitrary code in the client due to a heap buffer overflow when receiving messages from a malicious queue manager or through a man-in-the-middle attack.
Published: 2026-09-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

IBM MQ .NET client has a heap buffer overflow that can be triggered when the client receives a message from a malicious queue manager or via a man‑in‑the‑middle. The overwrite allows the attacker to cause a denial of service or, if exploited, to execute arbitrary code on the client host. This flaw is an out‑of‑bounds write, identified as CWE‑787.

Affected Systems

The vulnerability affects IBM MQ LTS releases 9.1, 9.2, 9.3, and 9.4, specifically versions 9.1.0.0‑9.1.0.37, 9.2.0.0‑9.2.0.43, 9.3.0.0‑9.3.0.41 and 9.3.5.1 CD, 9.4.0.0‑9.4.0.25 and 9.4.5.1 CD, as well as the 10.0.0.0 baseline and all earlier 10.x releases up to 10.0.0.5. All of these installations run the IBM MQ .NET client and are susceptible to the overflow.

Risk and Exploitability

The CVSS score of 8.1 signifies high severity, while the EPSS score of less than 1 % suggests a low but non‑zero chance of exploitation. The vulnerability is not listed in the CISA KEV catalog, indicating no widely observed attacks yet. Nevertheless, the flaw is reachable from outside the trusted network, requires no special privileges, and can lead to denial of service or arbitrary code execution on is essential.

Generated by OpenCVE AI on September 20, 2026 at 14:36 UTC.

Remediation

Vendor Solution

This issue was addressed under Known Issue DT473417 IBM MQ version 9.1 LTS Apply cumulative security update 9.1.0.38 IBM MQ version 9.2 LTS Apply cumulative security update 9.2.0.44 IBM MQ version 9.3 LTS Apply cumulative security update 9.3.0.42 IBM MQ version 9.4 LTS Apply cumulative security update 9.4.0.26 IBM MQ version 9.3 CD, 9.4 CD and 10.0.0.0 Upgrade to IBM MQ version 10.0.0.5


OpenCVE Recommended Actions

  • Apply the IBM MQ cumulative security update appropriate for your version—9.1.0.38 for 9.1 LTS, 9.2.0.44 for 9.2 LTS, 9.3.0.42 for 9.3 LTS, 9.4.0.26 for 9.4 LTS, or upgrade to 10.0.0.5 for CD and 10.0.0.0 installations.
  • Enable TLS or other encryption on all MQ traffic and configure the client to accept messages only from trusted queue managers, thereby reducing the risk of a man‑in‑the‑middle delivering malicious payloads.
  • Monitor MQ logs and network traffic for abnormal message patterns that could indicate attempts to trigger the overflow before successful exploitation.

Generated by OpenCVE AI on September 20, 2026 at 14:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote attacker to cause a denial of service or potentially execute arbitrary code in the client due to a heap buffer overflow when receiving messages from a malicious queue manager or through a man-in-the-middle attack.
Title IBM MQ .NET client is vulnerable to remote code execution
First Time appeared Ibm
Ibm mq
Weaknesses CWE-787
CPEs cpe:2.3:a:ibm:mq:10.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.1.0.37:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.2.0.43:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.41:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.5.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.25:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.5.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm mq
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-16T03:56:56.779Z

Reserved: 2026-06-09T02:32:45.930Z

Link: CVE-2026-11728

cve-icon Vulnrichment

Updated: 2026-09-15T18:33:52.118Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T18:17:12.257

Modified: 2026-09-16T19:21:55.793

Link: CVE-2026-11728

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:45:06Z

Weaknesses