{"id":"CVE-2026-10747","title":"IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.","summary":"IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.","severity":"critical","cvss":10,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-122"],"vendor":"IBM","product":"MQ Appliance","affected":["mq_appliance >= 9.4 LTS <= 9.4.0.0 to 9.4.0.25","mq_appliance >= 9.4 CD <= 9.4.1.0 to 9.4.5.2","mq_appliance >= 10.0.0.0 <= 10.0.0.1 only"],"published":"2026-09-18","updated":"2026-09-21","sourceUpdated":"2026-09-21T13:17:07.147","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-10747","references":[{"url":"https://www.ibm.com/support/pages/node/7284690","label":"psirt@us.ibm.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"total","timestamp":"2026-09-19T03:56:46.797549Z"},"epss":0.00519,"epssPercentile":0.42954,"ingestedAt":"2026-09-18T16:45:41.380Z","slug":"CVE-2026-10747","body":"## Overview\n\nIBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":55,"depthScoreParts":{"impact":55,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}