Skip to content
THREATWIRE

CVE

CriticalNo PoC

CVE-2026-10858

IBM MQ authenticated heap underflow on multi-segment messages

IBM scored CVE-2026-10858 CVSS 3.1 9.9 (PR:L) for a heap buffer underflow when processing multi-segment messages. An authenticated attacker may cause denial of service or potentially execute code. Affects MQ for HPE NonStop and MQ Appliance. Not pre-auth. Not in CISA KEV.

CVSS
9.9
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Class
RCE
Status
No PoC
KEV
Not in CISA KEV
0-day
No
Vendor
IBM
Products
IBM MQ for HPE NonStop, IBM MQ Appliance
Affected
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40. IBM MQ Appliance 9.4.0.0–9.4.0.25 LTS; 9.4.1.0–9.4.5.2 CD; 10.0.0.0–10.0.0.1.
Fixed
NonStop: CSU 8.1.0.41 (IT49924). Appliance: 9.4.0.26 LTS; 9.4.5.3 (M2002 CD); 10.0.0.5 (M2003 CD and 10 LTS). APAR DT472680. No workarounds listed.
Published
18 Sept 2026
Updated
5 Oct 2026

No public PoC is confirmed on this record.

CVE-2026-10858 is described by IBM as a heap buffer underflow when processing multi-segment messages. An authenticated attacker may cause denial of service or potentially execute arbitrary code. IBM labels the CWE as CWE-122 (Heap-based Buffer Overflow) and scores CVSS 3.1 9.9 with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. Privileges Required is Low, so this is not a pre-authentication flaw. NVD carries IBM’s score as Secondary from psirt@us.ibm.com and marks the entry Awaiting Analysis.

The CVE.org and NVD product text name IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40. IBM’s NonStop bulletin (node 7287704) matches that range and remediates with CSU 8.1.0.41 under IT49924. A separate IBM MQ Appliance bulletin also assigns CVE-2026-10858 to Appliance firmware ranges 9.4.0.0–9.4.0.25 LTS, 9.4.1.0–9.4.5.2 CD, and 10.0.0.0–10.0.0.1, fixed under APAR DT472680 with 9.4.0.26, 9.4.5.3, or 10.0.0.5 as applicable. IBM lists no workarounds on either bulletin.

CISA has not listed the CVE in KEV; CISA SSVC sets exploitation to none and automatable to no. ThreatWire found no public PoC repository for this CVE id. Exploitation in the wild is not confirmed.

Sources

Related writing

Share on X@threatwire_https://www.threatwire.tech/cve/cve-2026-10858