CVE-2026-10858
IBM MQ for HPE NonStop heap buffer underflow lets authenticated attackers cause denial of service or execute code (CVE-2026-10858)
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 has a critical heap buffer underflow (CVE-2026-10858). An authenticated attacker can cause denial of service or potentially execute arbitrary code. IBM has published a fix; apply it.
What happened
IBM MQ for HPE NonStop versions 8.1.0 through 8.1.0.40 contain a heap buffer underflow when processing multi-segment messages. An attacker with a low-privilege account can exploit the flaw over the network without any user interaction. Successful exploitation can cause denial of service or potentially allow arbitrary code execution.
IBM rates this as critical with a CVSS 3.1 score of 9.9 and changed scope, meaning a compromise could affect resources beyond the vulnerable component. The CVE record does not indicate active exploitation or public disclosure, and it is not listed in CISA KEV.
Who is affected
IBM MQ for HPE NonStop versions 8.1.0 through 8.1.0.40 are affected. The product is messaging middleware for HPE NonStop systems. If you run any version in this range, you are in scope.
What to do now
- Obtain and apply IBM's fix. IBM has indicated a fix is available, but no fixed version numbers are published in this record, so confirm the exact build for your installation with IBM support or from the linked advisory.
- If you cannot patch immediately, restrict network access to the MQ service so only trusted users and hosts can reach it. The attack requires a low-privilege authenticated account, so tightening authentication and access controls reduces exposure.
- IBM has not published a workaround. While waiting for the fix, treat unexpected authenticated activity or repeated message-processing failures as suspicious and investigate.
How to detect it
No vendor indicators of compromise are published. Because the attack requires a low-privilege authenticated network session, review MQ authentication logs for unexpected use of valid accounts from unusual hosts, and monitor for repeated message-processing failures or service interruptions in affected versions.
Beyond the patch
Messaging middleware sits beneath critical applications and is often patched slowly; this CVE is a reminder to track the supplier's fix cycle, not just the patch itself. Managed Detection & Response (MDR) can detect the code-execution or credential-abuse activity that would follow exploitation, while Supply Chain Defense & Third-Party Risk helps keep track of which IBM middleware versions you run and how quickly vendor fixes close the exposure window.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| MQ for HPE NonStop | 8.1.0 – ≤ 8.1.0.40 | No fixed version listed yet |