{"id":"CVE-2026-10858","published":"2026-09-18T16:17:05.310","lastModified":"2026-09-19T04:17:51.203","description":"IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer underflow when processing multi-segment messages.","cvssScore":9.9,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","cwes":["CWE-122"],"vendors":[],"products":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7287704","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This flaw allows an authenticated attacker to cause a denial of service or execute arbitrary code by exploiting a heap buffer underflow in the processing of multi-segment messages in IBM MQ for HPE NonStop versions 8.1.0 through 8.1.0.40, making it a critical security risk.","exploitability":"Exploitation requires an authenticated attacker and the ability to send multi-segment messages, which may be challenging in environments where such messages are not commonly used.","blast_radius":"If exploited, the impact could be severe, potentially leading to a complete denial of service or execution of arbitrary code, affecting the availability and integrity of the system.","remediation":"Upgrade to IBM MQ for HPE NonStop 8.1.0.41 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","dos","heap-buffer-overflow","authenticated","message-processing"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:58:01.411Z"}}