Heap Buffer Underflow in IBM MQ for HPE NonStop
IBM MQ for HPE NonStop versions 8.1.0 through 8.1.0.40 contain a heap buffer underflow vulnerability in multi-segment message processing that allows authenticated attackers to execute arbitrary code or trigger denial of service.
CVE search metadata
CVE search record: CVE-2026-10858. Severity: critical. CVSS: 9.9. KEV: no. Product: IBM MQ for HPE NonStop (8.1.0 through 8.1.0.40). Brief: Heap Buffer Underflow in IBM MQ for HPE NonStop. Brief link: https://feed.craftedsignal.io/briefs/2026-09-ibm-mq-heap-underflow/
IBM has disclosed a critical vulnerability, CVE-2026-10858, affecting IBM MQ for HPE NonStop versions 8.1.0 through 8.1.0.40. The vulnerability stems from an improper handling of multi-segment messages, resulting in a heap buffer underflow condition. An authenticated attacker can exploit this flaw to crash the message queue manager, causing a denial of service, or potentially gain arbitrary code execution capabilities with the privileges of the IBM MQ service. Given the high CVSS base score of 9.9 and the potential for remote code execution, this represents a significant risk to the integrity and availability of messaging infrastructure. Defenders should prioritize patching or applying vendor-recommended mitigations to affected NonStop environments.
Impact
The vulnerability poses a severe risk to messaging infrastructure relying on IBM MQ for HPE NonStop. Successful exploitation can lead to total loss of service through application crashes or unauthorized system access. Given that the impact includes potential arbitrary code execution, attackers could leverage this access for internal lateral movement, exfiltration of sensitive queued message data, or further compromise of the HPE NonStop operating environment.
Recommendation
- Identify all instances of IBM MQ for HPE NonStop within the environment that are running version 8.1.0 through 8.1.0.40.
- Patch affected instances immediately following vendor guidance for CVE-2026-10858.
- Review access control lists (ACLs) for IBM MQ queues to restrict the number of users capable of submitting multi-segment messages, reducing the attack surface until patches are applied.
Immediate actions
Inventory all IBM MQ for HPE NonStop installations to identify versions 8.1.0-8.1.0.40.
Mitigations
Upgrade IBM MQ for HPE NonStop to the latest version as provided by IBM to remediate CVE-2026-10858.
CVE-2026-10858