---
id: CVE-2026-11728
title: >-
  IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0
  through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25
  LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote attacker to
  cause a …
summary: >-
  IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0
  through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25
  LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote attacker to
  cause a …
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-787
vendor: IBM
product: MQ
affected:
  - MQ >= 9.1.0.0 <= 9.1.0.37 LTS
  - MQ >= 9.2.0.0 <= 9.2.0.43 LTS
  - MQ >= 9.3.0.0 <= 9.3.0.41 LTS
  - MQ >= 9.3.0.0 <= 9.3.5.1 CD
  - MQ >= 9.4.0.0 <= 9.4.0.25 LTS
  - MQ >= 9.4.0.0 <= 9.4.5.1 CD
  - MQ 10.0.0.0
published: '2026-09-15'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:21:55.793'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-11728'
references:
  - url: 'https://www.ibm.com/support/pages/node/7284943'
    label: psirt@us.ibm.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-15T18:33:44.415689Z'
ingestedAt: '2026-09-15T18:41:59.136Z'
epss: 0.00354
epssPercentile: 0.26343
---

## Overview

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote attacker to cause a denial of service or potentially execute arbitrary code in the client due to a heap buffer overflow when receiving messages from a malicious queue manager or through a man-in-the-middle attack.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
