{"id":"CVE-2026-10747","published":"2026-09-18T16:17:04.413","lastModified":"2026-09-21T13:17:07.147","description":"IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.","cvssScore":10,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","cwes":["CWE-122"],"vendors":[],"products":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7284690","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This flaw in IBM MQ Appliance allows a remote attacker to cause a denial of service or execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.","exploitability":"Exploitation is relatively straightforward as it does not require authentication, but the attacker must be able to send a malicious protocol message.","blast_radius":"If exploited, the impact could be severe, leading to a complete denial of service or execution of arbitrary code on the affected appliance.","remediation":"Upgrade to the latest version of IBM MQ Appliance as soon as possible.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","dos","protocol","heap-overflow"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:54:57.009Z"}}