CVE-2026-11381: IBM Mq For HPE Nonstop

High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of message distribution list structures.

Affected products

  • IBM Mq For HPE Nonstop: from 8.1.0, up to and including 8.1.0.40

Published 2026-09-18. Last modified 2026-09-19.