CVE-2026-10027
8.1IBM · MQ
IBM MQ is vulnerable to a buffer overflow via malformed compressed data on configured channels, potentially allowing remote code execution or denial of service by unauthenticated attackers.
Executive summary
A critical buffer overflow vulnerability in IBM MQ allows remote, unauthenticated attackers to execute arbitrary code or trigger a denial of service condition.
Vulnerability
This is an out-of-bounds write (CWE-787) occurring when the application processes malformed compressed data on channels with compression enabled. The vulnerability is exploitable by remote, unauthenticated attackers.
Business impact
Successful exploitation poses a severe risk to organizational infrastructure, as it enables unauthorized remote code execution and service disruption. With a CVSS score of 8.1, the high severity reflects the potential for total system compromise, leading to data exfiltration or the loss of messaging availability within critical business workflows.
Remediation
Immediate Action: Upgrade to the latest cumulative security updates for your specific IBM MQ version, such as 9.1.0.38, 9.2.0.44, or 9.3.0.42, as detailed in the IBM support documentation.
Proactive Monitoring: Review IBM MQ access logs for abnormal channel traffic or repeated connection failures that may indicate attempts to trigger compression-related buffer overflows.
Compensating Controls: Disable channel compression if it is not strictly required for business operations until the security updates can be successfully deployed.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for remote code execution, this vulnerability represents a significant threat to IBM MQ deployments. Administrators should prioritize identifying vulnerable versions and applying the vendor-supplied cumulative security updates immediately to eliminate the underlying memory corruption risk.
More IBM CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section