CVE-2026-11716 PUBLISHED

IBM MQ for HPE NonStop is vulnerable to a denial of service attack

Assigner: ibm
Reserved: 09.06.2026 Published: 18.09.2026 Updated: 18.09.2026

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code during queue manager startup due to improper validation of cluster migration data.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 7.5

Product Status

Vendor IBM
Product MQ for HPE NonStop
Versions
  • affected from 8.1.0 to 8.1.0.40 (incl.)

Solutions

IBM MQ V8.1 for HPE NonStop 8.1.0.40IT49922 Upgrade to CSU 8.1.0.41 https://www.ibm.com/support/fixcentral/swg/selectFixes

IBM strongly recommends addressing this vulnerability now by installing CSU 8.1.0.41.

References

Problem Types

  • CWE-122 Heap-based Buffer Overflow CWE