Junglewise Threat Intelligence

CVE-2026-11727: IBM MQ for HPE NonStop C client heap overflow in AMS policy handling

CVE-2026-11727 · Severity: high · CVSS 8.1 · Published 2026-09-18

Technologies: IBM MQ for HPE NonStop. Vendors: IBM.

Executive brief

IBM MQ is a messaging middleware used by enterprises to route business-critical transactions and data between applications. The C client component fails to validate responses from queue managers when processing AMS security policy data, allowing a remote attacker to trigger a heap buffer overflow. This can cause the client application to crash (denial of service) or execute arbitrary code on the system running the client.

Technical details

A heap-based buffer overflow exists in the IBM MQ C client's handling of queue manager responses during AMS (Application Messaging Services) policy data requests due to improper input validation. The vulnerability is remotely exploitable over the network with no authentication or user interaction required, affecting versions 8.1.0 through 8.1.0.40. A patched version 8.1.0.41 is available.

Affected products

  • IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40

Timeline

  • 2026-09-17: disclosed
  • 2026-09-17: patched: CSU 8.1.0.41 released

References

Related threats