CVE-2026-11727 PUBLISHED

IBM MQ for HPE NonStop is vulnerable to a denial of service issue

Assigner: ibm
Reserved: 09.06.2026 Published: 18.09.2026 Updated: 18.09.2026

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of queue manager responses when requesting AMS policy data.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 8.1

Product Status

Vendor IBM
Product MQ for HPE NonStop
Versions
  • affected from 8.1.0 to 8.1.0.40 (incl.)

Solutions

IBM MQ V8.1 for HPE NonStop 8.1.0.40IT49921 Upgrade to CSU 8.1.0.41 https://www.ibm.com/support/fixcentral/swg/selectFixes

IBM strongly recommends addressing this vulnerability now by installing CSU 8.1.0.41.

References

Problem Types

  • CWE-122 Heap-based Buffer Overflow CWE