CVE-2026-10747: IBM Mq Appliance

Critical severity, CVSS 10.0. EPSS: 0.6% chance of exploitation in the next 30 days.

IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.

Affected products

  • IBM Mq Appliance: from 10.0.0.0, up to and including 10.0.0.1 only

Published 2026-09-18. Last modified 2026-09-21.