Known vulnerabilities in IBM MQ Appliance 10.0.0.0

Version: 10.0.0.0
Software CPE: cpe:2.3:a:ibm_corporation:ibm_mq_appliance:*:*:*:*:*:*:*:*
Total vulnerabilities: 18
Public exploits: 4
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting IBM MQ Appliance version 10.0.0.0 IBM MQ Appliance 10.0.0.0 is affected by 18 vulnerabilities: 4 high, 9 medium, 5 low Critical High Medium Low

Vulnerabilities (18)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU139055 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-8646
CWE-444 High
No
No
9.4.0.26, 9.4.5.3, 10.0.0.5 22.07.2026 SB2026072215
SB2026072219
SB2026072328
and 19 more
#VU139054 - Resource exhaustion
CVE-2026-9320
CWE-400 Medium
No
No
9.4.0.26, 9.4.5.3, 10.0.0.5 22.07.2026 SB2026072214
SB2026072219
SB2026072328
and 19 more
#VU137314 - Resource exhaustion
CVE-2026-9071
CWE-400 Low
No
No
9.4.0.26, 9.4.5.3, 10.0.0.5 10.07.2026 SB2026071036
SB2026071037
SB2026072219
and 18 more
#VU136794 - Resource exhaustion
CVE-2026-9171
CWE-400 Medium
No
No
9.4.0.26, 9.4.5.3, 10.0.0.5 02.07.2026 SB2026070280
SB2026070646
SB2026070880
and 17 more
#VU136790 - Resource exhaustion
CVE-2026-9322
CWE-400 Medium
No
No
9.4.0.26, 9.4.5.3, 10.0.0.5 02.07.2026 SB2026070280
SB2026070646
SB2026070880
and 17 more
#VU136712 - Resource exhaustion
CVE-2026-50645
CWE-400 Low
No
No
9.4.0.26, 9.4.5.3, 10.0.0.5 02.07.2026 SB2026070266
SB2026070280
SB2026070646
and 20 more
#VU135124 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-11541
CWE-444 High
No
No
9.4.0.26, 9.4.5.3, 10.0.0.5 24.06.2026 SB2026062445
SB2026062950
SB2026063026
and 21 more
#VU133099 - Allocation of Resources Without Limits or Throttling
CVE-2026-44488
CWE-770 Medium
No
No
9.4.0.26, 9.4.5.3, 10.0.0.5 31.05.2026 SB2026052927
SB2026061992
SB2026070157
and 14 more
#VU133098 - Insertion of Sensitive Information Into Sent Data
CVE-2026-44487
CWE-201 Low
No
No
9.4.0.26, 9.4.5.3, 10.0.0.5 31.05.2026 SB2026052927
SB2026061992
SB2026070157
and 14 more
#VU133097 - Exposure of sensitive information to an unauthorized actor
CVE-2026-44486
CWE-200 Medium
No
No
9.4.0.26, 9.4.5.3, 10.0.0.5 31.05.2026 SB2026052927
SB2026061992
SB2026070157
and 12 more
#VU133096 - Inefficient Regular Expression Complexity
CVE-2026-44496
CWE-1333 Medium
No
No
9.4.0.26, 9.4.5.3, 10.0.0.5 31.05.2026 SB2026052927
SB2026061992
SB2026070157
and 11 more
#VU132949 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2026-44495
CWE-1321 Medium
No
No
9.4.0.26, 9.4.5.3, 10.0.0.5 29.05.2026 SB20260424169
SB2026061999
SB20260619101
and 13 more
#VU132756 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2026-44490
CWE-1321 Medium
Public exploit available
No
9.4.0.26, 9.4.5.3, 10.0.0.5 29.05.2026 SB2026052927
SB2026071542
SB2026072613
and 7 more
#VU132755 - Server-Side Request Forgery (SSRF)
CVE-2026-44492
CWE-918 Medium
Public exploit available
No
9.4.0.26, 9.4.5.3, 10.0.0.5 29.05.2026 SB2026052927
SB2026061992
SB2026070157
and 12 more
#VU132751 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2026-44489
CWE-1321 Low
Public exploit available
No
9.4.0.26, 9.4.5.3, 10.0.0.5 29.05.2026 SB2026052927
SB2026072719
SB2026091111
#VU132750 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2026-44494
CWE-1321 High
Public exploit available
No
9.4.0.26, 9.4.5.3, 10.0.0.5 29.05.2026 SB2026052927
SB2026070157
SB2026070202
and 16 more
#VU132031 - Security Features
CVE-2026-5516
CWE-254 Low
No
No
9.4.0.26, 9.4.5.3, 10.0.0.5 21.05.2026 SB2026052115
SB20260626104
SB2026071327
and 13 more
#VU19305 - Improper Control of Generation of Code ('Code Injection')
CVE-2018-16487
CWE-94 High
No
No
9.4.0.26, 9.4.5.3, 10.0.0.5 22.07.2019 SB2019020111
SB2022062806
SB2022101801
and 15 more