Skip to content

CVE-2026-10858

IBM MQ for HPE NonStop heap buffer underflow lets authenticated attackers cause denial of service or execute code (CVE-2026-10858)

Critical 9.9 Vendor: IBM Published

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 has a critical heap buffer underflow (CVE-2026-10858). An authenticated attacker can cause denial of service or potentially execute arbitrary code. IBM has published a fix; apply it.

What happened

IBM MQ for HPE NonStop versions 8.1.0 through 8.1.0.40 contain a heap buffer underflow when processing multi-segment messages. An attacker with a low-privilege account can exploit the flaw over the network without any user interaction. Successful exploitation can cause denial of service or potentially allow arbitrary code execution.

IBM rates this as critical with a CVSS 3.1 score of 9.9 and changed scope, meaning a compromise could affect resources beyond the vulnerable component. The CVE record does not indicate active exploitation or public disclosure, and it is not listed in CISA KEV.

Who is affected

IBM MQ for HPE NonStop versions 8.1.0 through 8.1.0.40 are affected. The product is messaging middleware for HPE NonStop systems. If you run any version in this range, you are in scope.

What to do now

  1. Obtain and apply IBM's fix. IBM has indicated a fix is available, but no fixed version numbers are published in this record, so confirm the exact build for your installation with IBM support or from the linked advisory.
  2. If you cannot patch immediately, restrict network access to the MQ service so only trusted users and hosts can reach it. The attack requires a low-privilege authenticated account, so tightening authentication and access controls reduces exposure.
  3. IBM has not published a workaround. While waiting for the fix, treat unexpected authenticated activity or repeated message-processing failures as suspicious and investigate.

How to detect it

No vendor indicators of compromise are published. Because the attack requires a low-privilege authenticated network session, review MQ authentication logs for unexpected use of valid accounts from unusual hosts, and monitor for repeated message-processing failures or service interruptions in affected versions.

Beyond the patch

Messaging middleware sits beneath critical applications and is often patched slowly; this CVE is a reminder to track the supplier's fix cycle, not just the patch itself. Managed Detection & Response (MDR) can detect the code-execution or credential-abuse activity that would follow exploitation, while Supply Chain Defense & Third-Party Risk helps keep track of which IBM middleware versions you run and how quickly vendor fixes close the exposure window.

Affected and fixed versions

ProductAffectedFixed in
MQ for HPE NonStop8.1.0 – ≤ 8.1.0.40No fixed version listed yet

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.