Description
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer underflow when processing multi-segment messages.
Published: 2026-09-18
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 contains a heap buffer underflow flaw that occurs when processing multi-segment messages. An attacker who has authenticated credentials can trigger the underflow, leading to program instability that may cause a denial of service or, in some circumstances, execution of arbitrary code. The vulnerability is a classic buffer underflow (CWE-122) that can be leveraged to compromise the reliability and integrity of the messaging system.

Affected Systems

The affected product is IBM MQ for HPE NonStop, version 8.1.0.0 up to 8.1.0.40 inclusive. Systems that have not applied the July 2026 CSU 8.1.0.41 update remain vulnerable. The patch addresses the heap buffer underflow in the MQ message handling component.

Risk and Exploitability

The vulnerability has a CVSS score of 9.9, indicating a high likelihood of severe impact under the appropriate conditions. The EPSS score is &lt; 1%, indicating a low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw requires authenticated access, an attacker must first compromise valid user credentials on the NonStop platform; once authenticated, the attacker can invoke the bug through the standard MQ client libraries or internal components, potentially disrupting critical messaging services or executing code with the MQ process’s privileges.

Generated by OpenCVE AI on September 19, 2026 at 17:12 UTC.

Remediation

Vendor Solution

IBM MQ V8.1 for HPE NonStop 8.1.0.40IT49924 Upgrade to CSU 8.1.0.41 https://www.ibm.com/support/fixcentral/swg/selectFixes IBM strongly recommends addressing this vulnerability now by installing CSU 8.1.0.41.


OpenCVE Recommended Actions

  • Apply IBM MQ V8.1 for HPE NonStop 8.1.0.41 CSC patch by downloading from IBM Fix Central and installing.
  • After installing, restart the MQ server processes to load the updated binaries.
  • Review and enforce account permissions for MQ authentication to limit privileged access, ensuring that only authorized users can connect to the messaging system.

Generated by OpenCVE AI on September 19, 2026 at 17:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Description IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer underflow when processing multi-segment messages.
Title IBM MQ for HPE NonStop is vulnerable to a denial of service attack
First Time appeared Ibm
Ibm mq For Hpe Nonstop
Weaknesses CWE-122
CPEs cpe:2.3:a:ibm:mq_for_hpe_nonstop:8.1.0.40:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq_for_hpe_nonstop:8.1.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm mq For Hpe Nonstop
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Ibm Mq For Hpe Nonstop
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-19T03:56:50.473Z

Reserved: 2026-06-04T13:16:29.221Z

Link: CVE-2026-10858

cve-icon Vulnrichment

Updated: 2026-09-18T17:28:54.298Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T16:17:05.310

Modified: 2026-09-19T04:17:51.203

Link: CVE-2026-10858

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T17:15:04Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow