Junglewise Threat Intelligence

CVE-2026-10858: IBM MQ for HPE NonStop heap buffer underflow in message processing

CVE-2026-10858 · Severity: critical · CVSS 9.9 · Published 2026-09-18

Technologies: IBM MQ for HPE NonStop. Vendors: IBM.

Executive brief

IBM MQ for HPE NonStop is a message queueing system used in enterprise environments to reliably route and process business-critical communications. An authenticated attacker can trigger a heap buffer underflow by sending specially crafted multi-segment messages, causing the service to crash or potentially executing arbitrary code on the system. This could lead to denial of service or compromise of the messaging infrastructure.

Technical details

A heap buffer underflow vulnerability (CWE-122) exists in the message processing logic when handling multi-segment messages. The vulnerability requires authentication and network access but has no user interaction requirement. Successful exploitation allows an authenticated attacker to either crash the MQ service (DoS) or achieve arbitrary code execution with the privileges of the MQ process.

Affected products

  • IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40

Timeline

  • 2026-09-18: disclosed

References

Related threats