CVE-2026-10858
9.9IBM · MQ for HPE NonStop
A heap-based buffer underflow in IBM MQ for HPE NonStop allows an authenticated attacker to trigger a denial of service or execute arbitrary code by sending specially crafted multi-segment messages.
Executive summary
A critical heap-based buffer underflow vulnerability in IBM MQ for HPE NonStop allows authenticated attackers to achieve remote code execution or system denial of service.
Vulnerability
This is a heap-based buffer underflow (CWE-122) occurring during the processing of multi-segment messages. The vulnerability requires the attacker to possess low-level authenticated access to the system to trigger the malicious message processing.
Business impact
The potential for arbitrary code execution combined with a high CVSS score of 9.9 indicates a severe risk to organizational infrastructure. Successful exploitation could lead to full system compromise, unauthorized data access, and significant operational downtime for mission critical messaging services. Given the severity, this vulnerability should be prioritized for immediate remediation to prevent lateral movement or total service disruption.
Remediation
Immediate Action: Upgrade IBM MQ for HPE NonStop to CSU 8.1.0.41 as recommended by the vendor.
Proactive Monitoring: Monitor system logs for unusual error patterns or unexpected process terminations associated with the MQ message processing service.
Compensating Controls: Ensure that access to the messaging environment is restricted to authorized users only, and implement network segmentation to limit the exposure of the management interface.
Exploitation status
Public Exploit Available: No (exploit_available unknown)
Analyst recommendation
This vulnerability presents a critical threat to the integrity and availability of IBM MQ for HPE NonStop environments. Security teams must treat this as a high priority item and coordinate with system administrators to apply the 8.1.0.41 update immediately. Failure to patch the affected systems leaves the infrastructure vulnerable to remote code execution by any authenticated user.
More IBM CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section