Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
This issue was addressed under Known Issue DT473417 IBM MQ version 9.1 LTS Apply cumulative security update 9.1.0.38 IBM MQ version 9.2 LTS Apply cumulative security update 9.2.0.44 IBM MQ version 9.3 LTS Apply cumulative security update 9.3.0.42 IBM MQ version 9.4 LTS Apply cumulative security update 9.4.0.26 IBM MQ version 9.3 CD, 9.4 CD and 10.0.0.0 Upgrade to IBM MQ version 10.0.0.5
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7284943 |
|
Tue, 15 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote attacker to cause a denial of service or potentially execute arbitrary code in the client due to a heap buffer overflow when receiving messages from a malicious queue manager or through a man-in-the-middle attack. | |
| Title | IBM MQ .NET client is vulnerable to remote code execution | |
| First Time appeared |
Ibm
Ibm mq |
|
| Weaknesses | CWE-787 | |
| CPEs | cpe:2.3:a:ibm:mq:10.0.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:mq:9.1.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:mq:9.1.0.37:*:*:*:*:*:*:* cpe:2.3:a:ibm:mq:9.2.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:mq:9.2.0.43:*:*:*:*:*:*:* cpe:2.3:a:ibm:mq:9.3.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:mq:9.3.0.41:*:*:*:*:*:*:* cpe:2.3:a:ibm:mq:9.3.5.1:*:*:*:*:*:*:* cpe:2.3:a:ibm:mq:9.4.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:mq:9.4.0.25:*:*:*:*:*:*:* cpe:2.3:a:ibm:mq:9.4.5.1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm mq |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-09-15T18:33:56.615Z
Reserved: 2026-06-09T02:32:45.930Z
Link: CVE-2026-11728
Updated: 2026-09-15T18:33:52.118Z
Status : Received
Published: 2026-09-15T18:17:12.257
Modified: 2026-09-15T19:17:15.233
Link: CVE-2026-11728
No data.
OpenCVE Enrichment
Updated: 2026-09-15T20:00:07Z
-
CWE-787
Out-of-bounds Write