CVE-2026-10858 PUBLISHED

IBM MQ for HPE NonStop is vulnerable to a denial of service attack

Assigner: ibm
Reserved: 04.06.2026 Published: 18.09.2026 Updated: 19.09.2026

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer underflow when processing multi-segment messages.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 9.9

Product Status

Vendor IBM
Product MQ for HPE NonStop
Versions
  • affected from 8.1.0 to 8.1.0.40 (incl.)

Solutions

IBM MQ V8.1 for HPE NonStop 8.1.0.40IT49924 Upgrade to CSU 8.1.0.41 https://www.ibm.com/support/fixcentral/swg/selectFixes

IBM strongly recommends addressing this vulnerability now by installing CSU 8.1.0.41.

References

Problem Types

  • CWE-122 Heap-based Buffer Overflow CWE