Censys Warns of Critical IBM MQ Vulnerability Exposing Web Consoles Worldwide
Critical vulnerability has been disclosed in IBM MQ, tracked as CVE-2026-10747. According to Censys' LinkedIn post, this heap buffer overflow could enable remote code execution or denial-of-service conditions on affected systems.
Censys ARC has observed 120 hosts and 149 web properties with exposed IBM MQ web consoles on the public Internet. However, these figures reflect overall presence rather than confirmed vulnerable instances.
IBM has released fixes for impacted MQ Server and MQ Appliance versions, but no public proof-of-concept or active exploitation has been reported yet.