VORANT. Threat Intelligence Sign in Get the full feed

IBM Patches Critical MQ and Langflow RCE Flaws

routine vulnerability technology

IBM fixed 12 vulnerabilities in MQ, MQ Appliance and Langflow OSS, including a CVSS 10.0 unauthenticated RCE and several CVSS 9.8 code-injection bugs.

NCSC-NL published an advisory summarizing 12 vulnerabilities patched by IBM across IBM MQ, IBM MQ Appliance, and Langflow OSS. Four of these are rated critical and can be exploited remotely without authentication or user interaction. The most severe, CVE-2026-10747, is a heap-based buffer overflow in IBM MQ with a maximum CVSS score of 10.0, allowing arbitrary code execution. Three additional critical flaws in Langflow OSS (CVE-2026-79724, CVE-2026-85025, CVE-2026-81204) carry CVSS 9.8 scores and allow unauthenticated attackers to execute arbitrary code or OS commands via improper neutralization of special elements (OS command injection) and code injection weaknesses.

The remaining eight vulnerabilities, all scored 8.8, require authenticated access but still allow code or command execution, and involve missing or incorrect authorization checks in addition to injection flaws. IBM has released updates addressing all 12 issues; no evidence of active exploitation is noted in the advisory. Defenders running IBM MQ, MQ Appliance, or Langflow OSS should prioritize patching the critical unauthenticated flaws immediately, given the low complexity of exploitation and lack of authentication requirements, and review authorization configurations affected by the missing/incorrect authorization CVEs.

Mentioned in this report

Vulnerabilities CVE-2026-10747CVE-2026-76059CVE-2026-78569CVE-2026-78571CVE-2026-78575CVE-2026-79724CVE-2026-79742CVE-2026-81204CVE-2026-81211CVE-2026-81940CVE-2026-81941CVE-2026-85025

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0392.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free