<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>IBM MQ for HPE NonStop (8.1.0 Through 8.1.0.40) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/ibm-mq-for-hpe-nonstop-8.1.0-through-8.1.0.40/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 18 Sep 2026 18:06:54 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/ibm-mq-for-hpe-nonstop-8.1.0-through-8.1.0.40/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Heap Buffer Underflow in IBM MQ for HPE NonStop</title><link>https://feed.craftedsignal.io/briefs/2026-09-ibm-mq-heap-underflow/</link><pubDate>Fri, 18 Sep 2026 18:06:54 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-ibm-mq-heap-underflow/</guid><description>IBM MQ for HPE NonStop versions 8.1.0 through 8.1.0.40 contain a heap buffer underflow vulnerability in multi-segment message processing that allows authenticated attackers to execute arbitrary code or trigger denial of service.</description><content:encoded><![CDATA[<p>IBM has disclosed a critical vulnerability, CVE-2026-10858, affecting IBM MQ for HPE NonStop versions 8.1.0 through 8.1.0.40. The vulnerability stems from an improper handling of multi-segment messages, resulting in a heap buffer underflow condition. An authenticated attacker can exploit this flaw to crash the message queue manager, causing a denial of service, or potentially gain arbitrary code execution capabilities with the privileges of the IBM MQ service. Given the high CVSS base score of 9.9 and the potential for remote code execution, this represents a significant risk to the integrity and availability of messaging infrastructure. Defenders should prioritize patching or applying vendor-recommended mitigations to affected NonStop environments.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability poses a severe risk to messaging infrastructure relying on IBM MQ for HPE NonStop. Successful exploitation can lead to total loss of service through application crashes or unauthorized system access. Given that the impact includes potential arbitrary code execution, attackers could leverage this access for internal lateral movement, exfiltration of sensitive queued message data, or further compromise of the HPE NonStop operating environment.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Identify all instances of IBM MQ for HPE NonStop within the environment that are running version 8.1.0 through 8.1.0.40.</li>
<li>Patch affected instances immediately following vendor guidance for CVE-2026-10858.</li>
<li>Review access control lists (ACLs) for IBM MQ queues to restrict the number of users capable of submitting multi-segment messages, reducing the attack surface until patches are applied.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">threat</category><category>vulnerability</category><category>remote-code-execution</category><category>ibm-mq</category><category>critical</category></item></channel></rss>