CVE-2026-10109Patch(ibm / db2)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch ibm db2 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • db2

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-07-01); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
db2

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-01: 1Mentions · 2026-07-02: 1Patch / Workaround · 2026-07-01: 1Patch / Workaround · 2026-07-02: 1Technical Details · 2026-07-01: 1Technical Details · 2026-07-02: 107-0107-02
Signal classification1 categories
Patch
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Daily CyberSecurity@the_yellow_fall
    Patch

    A critical IBM Db2 RCE flaw (CVE-2026-10109) allows pre-auth code execution. IBM patched it plus two other Db2 bugs. Update 11.5 and 12.1 now. #IBMDb2 #Db2 #RCE #CVE202610109 #CyberSecurity #DatabaseSecurity https://securityonline.info/ibm-db2-rce-cve-2026-10109 https://t.co/nTWUb3sKvC

    Post summary

    IBM has patched the critical CVE-2026-10109 Db2 RCE flaw, releasing updates 11.5 and 12.1 for users to apply.

    02092705
    12.9K followersView on X
  • しーにゃ♪@公式@Syynya
    Patch

    【セキュリティ ニュース】「IBM Db2」に深刻な脆弱性 - 暫定的な修正を提供:Security NEXT https://www.security-next.com/186679 『なかでも「CVE-2026-10109」については影響が大きい(中略)認証を必要とすることなくリモートよりコードを実行されるおそれがある』

    Post summary

    The article announces a serious IBM Db2 vulnerability (CVE-2026-10109) that enables unauthenticated remote code execution, and it notes that a temporary patch has been released.

    0000073
    917 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appibmdb2---

Explore more