CVE-2026-11728
largeHeap buffer overflow in IBM MQ clients allows remote code execution
IBM MQ client libraries across the 9.1 through 10.0 release streams contain a heap-based buffer overflow (CWE-787) in the code path that processes incoming messages. An attacker triggers it by running a malicious queue manager that a victim client connects to, or by tampering with client-to-queue-manager traffic as a man-in-the-middle. Successful exploitation can crash the client (denial of service) or execute arbitrary code within the client process, impacting confidentiality, integrity, and availability. The attack requires no authentication or user interaction but has high complexity (CVSS 3.1: 8.1), and no public PoC or in-the-wild exploitation is known; the CVE is not in CISA's KEV catalog.
What to do: Upgrade IBM MQ clients past the affected fix-pack levels — beyond 9.1.0.37, 9.2.0.43, 9.3.0.41 LTS / 9.3.5.1 CD, 9.4.0.25 LTS / 9.4.5.1 CD, and beyond 10.0.0.0 — as directed in IBM's advisory. Enforce TLS-encrypted, mutually authenticated channels (SSL/TLS with client certificate checking and CHLAUTH rules) so a man-in-the-middle cannot alter messages in transit, and configure clients to connect only to explicitly trusted queue managers. Watch client-side logs for unexplained crashes or abnormal message processing as possible signs of attempted exploitation.
| IBM MQ | 9.1.0.0 - 9.1.0.37 LTS |
| IBM MQ | 9.2.0.0 - 9.2.0.43 LTS |
| IBM MQ | 9.3.0.0 - 9.3.0.41 LTS |
| IBM MQ | 9.3.0.0 - 9.3.5.1 CD |
| IBM MQ | 9.4.0.0 - 9.4.0.25 LTS |
| IBM MQ | 9.4.0.0 - 9.4.5.1 CD |
| IBM MQ | 10.0.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote attacker to cause a denial of service or potentially execute arbitrary code in the client due to a heap buffer overflow when receiving messages from a malicious queue manager or through a man-in-the-middle attack.
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.