ZeroHour

CVE-2026-11728

large

Heap buffer overflow in IBM MQ clients allows remote code execution

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

IBM MQ client libraries across the 9.1 through 10.0 release streams contain a heap-based buffer overflow (CWE-787) in the code path that processes incoming messages. An attacker triggers it by running a malicious queue manager that a victim client connects to, or by tampering with client-to-queue-manager traffic as a man-in-the-middle. Successful exploitation can crash the client (denial of service) or execute arbitrary code within the client process, impacting confidentiality, integrity, and availability. The attack requires no authentication or user interaction but has high complexity (CVSS 3.1: 8.1), and no public PoC or in-the-wild exploitation is known; the CVE is not in CISA's KEV catalog.

What to do: Upgrade IBM MQ clients past the affected fix-pack levels — beyond 9.1.0.37, 9.2.0.43, 9.3.0.41 LTS / 9.3.5.1 CD, 9.4.0.25 LTS / 9.4.5.1 CD, and beyond 10.0.0.0 — as directed in IBM's advisory. Enforce TLS-encrypted, mutually authenticated channels (SSL/TLS with client certificate checking and CHLAUTH rules) so a man-in-the-middle cannot alter messages in transit, and configure clients to connect only to explicitly trusted queue managers. Watch client-side logs for unexplained crashes or abnormal message processing as possible signs of attempted exploitation.

Affected
IBM MQ9.1.0.0 - 9.1.0.37 LTS
IBM MQ9.2.0.0 - 9.2.0.43 LTS
IBM MQ9.3.0.0 - 9.3.0.41 LTS
IBM MQ9.3.0.0 - 9.3.5.1 CD
IBM MQ9.4.0.0 - 9.4.0.25 LTS
IBM MQ9.4.0.0 - 9.4.5.1 CD
IBM MQ10.0.0.0
Estimated exposure
largetens of thousands of deployments; roughly 10k-30k queue managers internet-exposed on port 1414 plus an unknown enterprise client population — Public internet scan services (Shodan/Censys) typically show on the order of tens of thousands of exposed IBM MQ listeners on port 1414, and IBM MQ is a staple at large banks, insurers, and governments; the vulnerable component is the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote attacker to cause a denial of service or potentially execute arbitrary code in the client due to a heap buffer overflow when receiving messages from a malicious queue manager or through a man-in-the-middle attack.

Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.