CVE-2026-10858
IBM MQ authenticated heap underflow on multi-segment messages
IBM scored CVE-2026-10858 CVSS 3.1 9.9 (PR:L) for a heap buffer underflow when processing multi-segment messages. An authenticated attacker may cause denial of service or potentially execute code. Affects MQ for HPE NonStop and MQ Appliance. Not pre-auth. Not in CISA KEV.
- CVSS
- 9.9
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Class
- RCE
- Status
- No PoC
- KEV
- Not in CISA KEV
- 0-day
- No
- Vendor
- IBM
- Products
- IBM MQ for HPE NonStop, IBM MQ Appliance
- Affected
- IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40. IBM MQ Appliance 9.4.0.0–9.4.0.25 LTS; 9.4.1.0–9.4.5.2 CD; 10.0.0.0–10.0.0.1.
- Fixed
- NonStop: CSU 8.1.0.41 (IT49924). Appliance: 9.4.0.26 LTS; 9.4.5.3 (M2002 CD); 10.0.0.5 (M2003 CD and 10 LTS). APAR DT472680. No workarounds listed.
- CWE
- CWE-122
- Published
- 18 Sept 2026
- Updated
- 5 Oct 2026
No public PoC is confirmed on this record.
CVE-2026-10858 is described by IBM as a heap buffer underflow when processing multi-segment messages. An authenticated attacker may cause denial of service or potentially execute arbitrary code. IBM labels the CWE as CWE-122 (Heap-based Buffer Overflow) and scores CVSS 3.1 9.9 with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. Privileges Required is Low, so this is not a pre-authentication flaw. NVD carries IBM’s score as Secondary from psirt@us.ibm.com and marks the entry Awaiting Analysis.
The CVE.org and NVD product text name IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40. IBM’s NonStop bulletin (node 7287704) matches that range and remediates with CSU 8.1.0.41 under IT49924. A separate IBM MQ Appliance bulletin also assigns CVE-2026-10858 to Appliance firmware ranges 9.4.0.0–9.4.0.25 LTS, 9.4.1.0–9.4.5.2 CD, and 10.0.0.0–10.0.0.1, fixed under APAR DT472680 with 9.4.0.26, 9.4.5.3, or 10.0.0.5 as applicable. IBM lists no workarounds on either bulletin.
CISA has not listed the CVE in KEV; CISA SSVC sets exploitation to none and automatable to no. ThreatWire found no public PoC repository for this CVE id. Exploitation in the wild is not confirmed.