Remote Code Execution Vulnerability in IBM Db2 by IBM
CVE-2026-10109
9.8CRITICAL
What is CVE-2026-10109?
IBM Db2 versions 11.5.0 to 11.5.9 and 12.1.0 to 12.1.4 are susceptible to a remote code execution vulnerability. This issue arises from improper handling of the DRDA handshake during the pre-authentication phase, potentially allowing an attacker to execute arbitrary code on the affected system. It is crucial for users of these Db2 versions to apply the recommended patches provided by IBM to mitigate this security risk.
Affected Version(s)
Db2 11.5.0 <= 11.5.9
Db2 12.1.0 <= 12.1.4