Threat intelligence dashboard
CVE-2026-11728high

IBM MQ .NET client is vulnerable to remote code execution

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote attacker to cause a denial of service or potentially execute arbitrary code in the client due to a heap buffer overflow when receiving messages from a malicious queue manager or through a man-in-the-middle attack.

Risk score

8.1

CVSS 3.1

Vendor
IBM
Product
MQ
CWE
CWE-787
Published
Sep 15, 2026
Updated
Sep 16, 2026
CISA KEV
Not flagged

Affected products and versions

MQ

IBM

Version / rangeStatusType
9.1.0.0 to 9.1.0.37 LTSaffectedsemver
9.2.0.0 to 9.2.0.43 LTSaffectedsemver
9.3.0.0 to 9.3.0.41 LTSaffectedsemver
9.3.0.0 to 9.3.5.1 CDaffectedsemver
9.4.0.0 to 9.4.0.25 LTSaffectedsemver
9.4.0.0 to 9.4.5.1 CDaffectedsemver
10.0.0.0affected

Technical metrics

8.1

CVSS 3.1

Severity
high
Source
ibm
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H