CVE-2026-10027

IBM MQ could allow a remote attacker to cause a denial of service or execute arbitrary code due to a buffer overflow when processing malformed compressed data on channels configured with compression enabled.

  • Published Sep 18, 2026
  • CVSS 9.8 critical
  • 0.4% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-10027 at the National Vulnerability Database