Description
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer underflow when processing multi-segment messages.
Published: 2026-09-18
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

IBM MQ V8.1 for HPE NonStop 8.1.0.40IT49924 Upgrade to CSU 8.1.0.41 https://www.ibm.com/support/fixcentral/swg/selectFixes IBM strongly recommends addressing this vulnerability now by installing CSU 8.1.0.41.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Description IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer underflow when processing multi-segment messages.
Title IBM MQ for HPE NonStop is vulnerable to a denial of service attack
First Time appeared Ibm
Ibm mq For Hpe Nonstop
Weaknesses CWE-122
CPEs cpe:2.3:a:ibm:mq_for_hpe_nonstop:8.1.0.40:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq_for_hpe_nonstop:8.1.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm mq For Hpe Nonstop
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Ibm Mq For Hpe Nonstop
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-18T16:08:37.780Z

Reserved: 2026-06-04T13:16:29.221Z

Link: CVE-2026-10858

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-18T16:17:05.310

Modified: 2026-09-18T16:17:05.310

Link: CVE-2026-10858

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow