Vulnerability Description
CVE-2026-10747 is a critical heap buffer overflow (CWE-122) in IBM MQ’s message-listener service, CVSS 3.1 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). NVD’s entry for this CVE is currently “Awaiting Analysis,” so the technical description below is IBM’s own, from its Server bulletin: “IBM MQ could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.” Because the overflow happens during message processing that occurs before any authentication step, exploitation requires no credentials or prior access, only network reachability to the listener.
IBM publishes this CVE as two separate bulletins with different version ranges, for MQ Server and MQ Appliance respectively (see Affected Assets); the CVE’s own CPE mapping names only the Appliance, which undercounts the true scope. IBM MQ instances are visible to the Censys ARC team through the product’s web administration console. The console can administer queue managers on other systems. This query does not establish the associated queue managers’ versions or listener reachability, so a vulnerable-versus-patched subset cannot be isolated from these matches alone.

Details
| Field | Description |
| CVE-ID | CVE-2026-10747, CVSS 3.1: 10.0 (Critical), assigned by IBM. |
| Date of Disclosure | September 18, 2026 (NVD); IBM’s bulletins were published earlier: September 14, 2026 (Server), September 10, 2026 (Appliance). |
| Affected Assets | IBM MQ Server on Windows, AIX, Linux, Solaris, and IBM i, and the IBM MQ Appliance hardware line, covered by separate vendor bulletins with different version ranges. |
| Vulnerable Software Versions | Server: 9.1.0.0-9.1.0.37, 9.2.0.0-9.2.0.43, 9.3.0.0-9.3.0.41 (LTS) and 9.3.0.0-9.3.5.1 (CD), 9.4.0.0-9.4.0.25 (LTS) and 9.4.0.0-9.4.5.1 (CD), 10.0.0.0. Appliance: 9.4.0.0-9.4.0.25 (LTS), 9.4.1.0-9.4.5.2 (CD), 10.0.0.0-10.0.0.1 |
| PoC Available | No, as of September 18, 2026. |
| Exploitation Status | Not confirmed. Not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog as of September 18, 2026. |
| Patch Status | IBM documented fixed builds in separate bulletins, published September 14, 2026 (Server) and September 10, 2026 (Appliance). |
Affected Assets
IBM publishes this CVE as two separate bulletins with different version ranges: one for IBM MQ Server (Windows, AIX, Linux, Solaris, and IBM i) and one for the IBM MQ Appliance hardware line (the M2000/M2001-successor M2002 and M2003 models). The CVE’s own CPE mapping names only the Appliance; that undercounts the true scope, since the Server bulletin covers a much larger, non-appliance deployment base running the same vulnerable code.
IBM MQ Server, per IBM’s Server bulletin:
- 9.1 LTS: 9.1.0.0 through 9.1.0.37, fixed in 9.1.0.38
- 9.2 LTS: 9.2.0.0 through 9.2.0.43, fixed in 9.2.0.44
- 9.3 LTS: 9.3.0.0 through 9.3.0.41, fixed in 9.3.0.42
- 9.3 CD: 9.3.0.0 through 9.3.5.1, must upgrade to 10.0.0.5
- 9.4 LTS: 9.4.0.0 through 9.4.0.25, fixed in 9.4.0.26
- 9.4 CD: 9.4.0.0 through 9.4.5.1, must upgrade to 10.0.0.5
- 10.0.0.0, fixed in 10.0.0.5
IBM MQ Appliance, per IBM’s Appliance bulletin, which is a distinct range from the Server bulletin above and should not be read across:
- 9.4 LTS: 9.4.0.0 through 9.4.0.25, fixed in 9.4.0.26
- 9.4 CD, M2002 model: 9.4.1.0 through 9.4.5.2, fixed in 9.4.5.3
- 9.4 CD, M2003 model: 9.4.1.0 through 9.4.5.2, must upgrade to 10.0.0.5
- 10.0 LTS: 10.0.0.0 and 10.0.0.1 only, fixed in 10.0.0.5
The two bulletins do not share a single “CD must move to 10.0.0.5” rule: it holds for Server CD branches and for the Appliance M2003 model, but the Appliance M2002 model has its own in-branch CD fix (9.4.5.3) and does not need the major-version jump. Confirm the model before applying either bulletin’s upgrade path.
IBM MQ ships on parallel maintenance tracks that do not share a single version number even within one bulletin. Long Term Support (LTS) branches each carry their own in-branch fix. A Continuous Delivery (CD) branch’s fix depends on the product and, for the Appliance, the model, per the ranges above.
The Censys ARC team identifies IBM MQ deployments through the product’s web administration console rather than the message-listener protocol itself, since the listener does not respond to an unsolicited connection with any identifying data. Censys observes the IBM MQ console on 120 hosts and 149 web properties internet-wide as of September 18, 2026 (reported separately, not summed: the host and web indexes are different units, and a host running the console can also serve it under one or more separate web-property hostnames). These figures are a population size, not an unpatched count: they establish that IBM MQ is running, not which build.
Censys Query
We currently detect IBM MQ running on 120 hosts and 149 web properties. The query text is withheld: at this population size, a runnable query is close to a target list, so the finding is reported without the reproduction steps.
Detection matches IBM MQ’s web console by a distinctive signal in its administration interface. Matches indicate an IBM MQ web console, not a confirmed-vulnerable build; the signal used for detection does not itself carry a version string. The console can administer queue managers on other systems, so verify each associated queue manager’s deployed build against the ranges above and check its listener’s network exposure separately.
PoC Available?
No public proof-of-concept exploit code has been published for CVE-2026-10747 as of September 18, 2026.
Exploitation Status
CVE-2026-10747 is not listed in the CISA KEV catalog as of September 18, 2026. The Censys ARC team is not aware of any reported active exploitation as of the same date.
Patch Status
IBM documented fixed builds in separate security bulletins published on September 14, 2026, for MQ Server and September 10, 2026, for MQ Appliance.
IBM MQ Server, per IBM’s Server bulletin:
- 9.1 LTS: fixed in 9.1.0.38
- 9.2 LTS: fixed in 9.2.0.44
- 9.3 LTS: fixed in 9.3.0.42
- 9.3 CD: must upgrade to 10.0.0.5
- 9.4 LTS: fixed in 9.4.0.26
- 9.4 CD: must upgrade to 10.0.0.5
- 10.0.0.0: fixed in 10.0.0.5
IBM MQ Appliance, per IBM’s Appliance bulletin:
- 9.4 LTS: fixed in 9.4.0.26
- 9.4 CD, M2002: fixed in 9.4.5.3
- 9.4 CD, M2003: must upgrade to 10.0.0.5
- 10.0 LTS: fixed in 10.0.0.5
IBM’s bulletins name patching as the only remediation and publish no configuration-level workaround for the flaw itself. Blocking inbound access to the MQ listener (default TCP port 1414) at the perimeter firewall reduces exposure while an upgrade is scheduled, but does not remediate the underlying flaw, since it only limits reachability rather than fixing the vulnerable code path. Compare a deployment’s build against the fixed version for its own branch and, for the Appliance, its own model: a CD branch and an LTS branch on the same major version do not share a fix, and the Appliance’s two CD models (M2002 and M2003) do not share one either.
References
- IBM Security Bulletin for CVE-2026-10747 (MQ Server) (vendor advisory: affected versions, fixed builds, technical description)
- IBM Security Bulletin for CVE-2026-10747 (MQ Appliance) (vendor advisory: Appliance-specific affected versions and fixed builds)
- NVD: CVE-2026-10747 (CVE record; entry status is Awaiting Analysis as of September 18, 2026)
- CWE-122: Heap-based Buffer Overflow (weakness classification for this CVE)
- IBM MQ Technical Overview (mqweb console remote queue manager administration, pages 295-296)
- CISA Known Exploited Vulnerabilities (KEV) catalog (checked for CVE-2026-10747, not listed as of September 18, 2026)

