Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3791 articles · 197620 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-10109PATCHED
ibm · db2

IBM® Db2® is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling

Description

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling.

Affected Products

VendorProductVersions
ibmdb211.5.0, 12.1.0

References

  • https://www.ibm.com/support/pages/node/7277424(vendor-advisory, patch)

Related News (4 articles)

Tier B
CERT-FR12d ago
Multiples vulnérabilités dans les produits IBM (14 août 2026)
→ No new info (linked only)
Tier B
CERT-FR19d ago
Multiples vulnérabilités dans les produits IBM (07 août 2026)
→ No new info (linked only)
Tier C
VulDB56d ago
CVE-2026-10109 | IBM DB2 up to 11.5.9/12.1.4 code injection
→ No new info (linked only)
Tier D
Heise Security62d ago
Sicherheitsupdate: Kritische Client-Handshake-Lücke bedroht IBM Db2
→ No new info (linked only)
CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://www.ibm.com/support/pages/node/7277424
CWECWE-94
PublishedJun 30, 2026
Last enriched56d agov2
Trending Score16
Source articles4
Independent3
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-14529
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a server-side request forgery
Trending: 36
CRITICALCVE-2026-14446
IBM WebSphere Application Server is affected by a privilege escalation
Trending: 36
CRITICALCVE-2026-14512
IBM WebSphere Application Server is affected by an unsafe deserialization and exposure of sensitive information
Trending: 36
CRITICALCVE-2026-16917
Vulnerabilities in IBM AIX and PowerVM VIOS
Trending: 31
CRITICALCVE-2026-16834
Vulnerabilities in IBM AIX and PowerVM VIOS
Trending: 31

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 30, 2026
Discovered by ZDM
Jun 30, 2026
Updated: description
Jul 1, 2026
Patch Available
Jul 1, 2026

Version History

v2
Last enriched 56d ago
v2Tier C56d ago

Updated description with new details about the vulnerability and corrected exploit availability to false.

description
via VulDB
v156d ago

Initial creation