{"schema_version":1,"title":"IBM Db2 vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 19 vulnerabilities in IBM Db2: 0 in the last 7 days and 15 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-17463, was published on 14 September 2026.","url":"https://junglewise.ai/threats/technologies/db2","json_url":"https://junglewise.ai/threats/technologies/db2.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/db2","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":6,"all_time":19,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":6,"last_90_days":15,"last_365_days":19},"latest":[{"cve":"CVE-2026-17463","cvss":6.5,"epss":0.0035,"slug":"cve-2026-17463-ibm-db2-denial-of-service-in-resource-consumption","title":"IBM Db2 denial of service in resource consumption","severity":"medium","exploited":false,"published_at":"2026-09-14T20:16:41.857+00:00","url":"https://junglewise.ai/threats/cve-2026-17463-ibm-db2-denial-of-service-in-resource-consumption"},{"cve":"CVE-2026-16702","cvss":6.5,"epss":0.0035,"slug":"cve-2026-16702-ibm-db2-null-pointer-dereference-in-federated-server","title":"IBM Db2 null pointer dereference in federated server","severity":"medium","exploited":false,"published_at":"2026-09-14T20:16:41.173+00:00","url":"https://junglewise.ai/threats/cve-2026-16702-ibm-db2-null-pointer-dereference-in-federated-server"},{"cve":"CVE-2026-15955","cvss":7.5,"epss":0.004,"slug":"cve-2026-15955-ibm-db2-arbitrary-file-write-via-path-traversal","title":"IBM Db2 arbitrary file write via path traversal","severity":"high","exploited":false,"published_at":"2026-09-14T20:16:39.057+00:00","url":"https://junglewise.ai/threats/cve-2026-15955-ibm-db2-arbitrary-file-write-via-path-traversal"},{"cve":"CVE-2026-87958","cvss":8.1,"epss":0.0038,"slug":"cve-2026-87958-ibm-db2-denial-of-service-via-privilege-management","title":"IBM Db2 denial of service via privilege management","severity":"high","exploited":false,"published_at":"2026-09-10T22:17:04.76+00:00","url":"https://junglewise.ai/threats/cve-2026-87958-ibm-db2-denial-of-service-via-privilege-management"},{"cve":"CVE-2026-86093","cvss":7.5,"epss":0.0045,"slug":"cve-2026-86093-ibm-db2-stack-based-buffer-overflow-in-drda-client","title":"IBM Db2 stack-based buffer overflow in DRDA client","severity":"high","exploited":false,"published_at":"2026-09-10T22:17:04.62+00:00","url":"https://junglewise.ai/threats/cve-2026-86093-ibm-db2-stack-based-buffer-overflow-in-drda-client"},{"cve":"CVE-2026-86087","cvss":4.3,"epss":0.0034,"slug":"cve-2026-86087-ibm-db2-path-traversal-in-file-write","title":"IBM Db2 path traversal in file write","severity":"medium","exploited":false,"published_at":"2026-09-10T22:17:04.477+00:00","url":"https://junglewise.ai/threats/cve-2026-86087-ibm-db2-path-traversal-in-file-write"},{"cve":"CVE-2026-10534","cvss":8.4,"epss":0.0038,"slug":"cve-2026-10534-ibm-db2-buffer-overflow-in-ixf-import-parser","title":"IBM Db2 buffer overflow in IXF IMPORT parser","severity":"high","exploited":false,"published_at":"2026-08-12T22:17:14.203+00:00","url":"https://junglewise.ai/threats/cve-2026-10534-ibm-db2-buffer-overflow-in-ixf-import-parser"},{"cve":"CVE-2026-18097","cvss":5.5,"epss":0.0015,"slug":"cve-2026-18097-ibm-db2-plain-text-password-logging-in-trace-files","title":"IBM Db2 plain text password logging in trace files","severity":"medium","exploited":false,"published_at":"2026-08-12T21:17:36.93+00:00","url":"https://junglewise.ai/threats/cve-2026-18097-ibm-db2-plain-text-password-logging-in-trace-files"},{"cve":"CVE-2026-18096","cvss":3.3,"epss":0.0013,"slug":"cve-2026-18096-ibm-db2-denial-of-service-due-to-memory-leak","title":"IBM Db2 denial of service due to memory leak","severity":"low","exploited":false,"published_at":"2026-08-12T21:17:36.813+00:00","url":"https://junglewise.ai/threats/cve-2026-18096-ibm-db2-denial-of-service-due-to-memory-leak"},{"cve":"CVE-2026-16480","cvss":4.3,"epss":0.0034,"slug":"cve-2026-16480-ibm-db2-improper-authorization-in-command","title":"IBM Db2 improper authorization in command","severity":"medium","exploited":false,"published_at":"2026-08-12T21:17:36.293+00:00","url":"https://junglewise.ai/threats/cve-2026-16480-ibm-db2-improper-authorization-in-command"},{"cve":"CVE-2026-10695","cvss":6.2,"slug":"cve-2026-10695-ibm-db2-denial-of-service-in-federated-server","title":"IBM Db2 denial of service in federated server","severity":"medium","exploited":false,"published_at":"2026-07-30T19:17:01.83+00:00","url":"https://junglewise.ai/threats/cve-2026-10695-ibm-db2-denial-of-service-in-federated-server"},{"cve":"CVE-2026-10535","cvss":8.4,"slug":"cve-2026-10535-ibm-db2-privilege-escalation-in-db2flacc-setgid-helper","title":"IBM Db2 privilege escalation in db2flacc setgid helper","severity":"high","exploited":false,"published_at":"2026-07-30T19:17:01.167+00:00","url":"https://junglewise.ai/threats/cve-2026-10535-ibm-db2-privilege-escalation-in-db2flacc-setgid-helper"},{"cve":"CVE-2026-7771","cvss":5.5,"slug":"cve-2026-7771-ibm-db2-denial-of-service-in-sql-compiler","title":"IBM Db2 denial of service in SQL compiler","severity":"medium","exploited":false,"published_at":"2026-07-17T20:17:30.247+00:00","url":"https://junglewise.ai/threats/cve-2026-7771-ibm-db2-denial-of-service-in-sql-compiler"},{"cve":"CVE-2026-11906","cvss":6.5,"slug":"cve-2026-11906-ibm-db2-denial-of-service-in-xmltable-query-logic","title":"IBM Db2 denial of service in XMLTable query logic","severity":"medium","exploited":false,"published_at":"2026-06-30T20:17:28.273+00:00","url":"https://junglewise.ai/threats/cve-2026-11906-ibm-db2-denial-of-service-in-xmltable-query-logic"},{"cve":"CVE-2026-10109","cvss":9.8,"slug":"cve-2026-10109-ibm-db2-remote-code-execution-in-drda-handshake","title":"IBM Db2 remote code execution in DRDA handshake","severity":"critical","exploited":false,"published_at":"2026-06-30T20:17:26.603+00:00","url":"https://junglewise.ai/threats/cve-2026-10109-ibm-db2-remote-code-execution-in-drda-handshake"},{"cve":"CVE-2026-6053","cvss":5.5,"slug":"cve-2026-6053-ibm-db2-denial-of-service-in-range-partitioned-tables","title":"IBM Db2 denial of service in range partitioned tables","severity":"medium","exploited":false,"published_at":"2026-05-27T14:17:34.633+00:00","url":"https://junglewise.ai/threats/cve-2026-6053-ibm-db2-denial-of-service-in-range-partitioned-tables"},{"cve":"CVE-2026-6052","cvss":6.5,"slug":"cve-2026-6052-ibm-db2-denial-of-service-via-memory-exhaustion-in-mdc-tables","title":"IBM Db2 denial of service via memory exhaustion in MDC tables","severity":"medium","exploited":false,"published_at":"2026-05-27T14:17:34.513+00:00","url":"https://junglewise.ai/threats/cve-2026-6052-ibm-db2-denial-of-service-via-memory-exhaustion-in-mdc-tables"},{"cve":"CVE-2026-6051","cvss":5.5,"slug":"cve-2026-6051-ibm-db2-denial-of-service-via-crafted-query-with-small-statement","title":"IBM Db2 denial of service via crafted query with small statement heap","severity":"medium","exploited":false,"published_at":"2026-05-27T14:17:34.37+00:00","url":"https://junglewise.ai/threats/cve-2026-6051-ibm-db2-denial-of-service-via-crafted-query-with-small-statement"},{"cve":"CVE-2026-1718","cvss":7.1,"slug":"cve-2026-1718-ibm-db2-denial-of-service-in-autonomous-transactions","title":"IBM Db2 denial of service in autonomous transactions","severity":"high","exploited":false,"published_at":"2026-05-27T14:16:43.883+00:00","url":"https://junglewise.ai/threats/cve-2026-1718-ibm-db2-denial-of-service-in-autonomous-transactions"}],"weekly":[{"week":"2026-06-29","critical":1,"exploited":0,"vulnerabilities":2},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"IBM AIX","slug":"aix","vulnerabilities":106,"url":"https://junglewise.ai/threats/technologies/aix"},{"name":"IBM Langflow","slug":"langflow-oss","vulnerabilities":96,"url":"https://junglewise.ai/threats/technologies/langflow-oss"},{"name":"IBM PowerVM VIOS","slug":"powervm-vios","vulnerabilities":73,"url":"https://junglewise.ai/threats/technologies/powervm-vios"},{"name":"IBM i","slug":"i","vulnerabilities":69,"url":"https://junglewise.ai/threats/technologies/i"},{"name":"IBM WebSphere Application Server","slug":"websphere-application-server","vulnerabilities":62,"url":"https://junglewise.ai/threats/technologies/websphere-application-server"},{"name":"IBM Guardium Data Protection","slug":"guardium-data-protection","vulnerabilities":49,"url":"https://junglewise.ai/threats/technologies/guardium-data-protection"},{"name":"IBM Financial Transaction Manager","slug":"financial-transaction-manager","vulnerabilities":45,"url":"https://junglewise.ai/threats/technologies/financial-transaction-manager"},{"name":"IBM WebSphere Application Server Liberty","slug":"websphere-application-server-liberty","vulnerabilities":37,"url":"https://junglewise.ai/threats/technologies/websphere-application-server-liberty"},{"name":"IBM Datastage On Cloud Pak For Data","slug":"datastage-on-cloud-pak-for-data","vulnerabilities":35,"url":"https://junglewise.ai/threats/technologies/datastage-on-cloud-pak-for-data"},{"name":"IBM Concert","slug":"concert","vulnerabilities":22,"url":"https://junglewise.ai/threats/technologies/concert"},{"name":"IBM Db2 Mirror For I","slug":"db2-mirror-for-i","vulnerabilities":22,"url":"https://junglewise.ai/threats/technologies/db2-mirror-for-i"},{"name":"IBM Mq","slug":"mq","vulnerabilities":22,"url":"https://junglewise.ai/threats/technologies/mq"}],"technology":{"hub":true,"name":"IBM Db2","slug":"db2","vendor":{"name":"IBM","slug":"ibm","url":"https://junglewise.ai/threats/vendors/ibm"},"aliases":["db2-server"],"category":"database-management-system","homepage":"https://www.ibm.com/products/db2","description":"A family of data management products including relational database servers.","url":"https://junglewise.ai/threats/technologies/db2"},"most_severe":[{"cve":"CVE-2026-10109","cvss":9.8,"slug":"cve-2026-10109-ibm-db2-remote-code-execution-in-drda-handshake","title":"IBM Db2 remote code execution in DRDA handshake","severity":"critical","exploited":false,"published_at":"2026-06-30T20:17:26.603+00:00","url":"https://junglewise.ai/threats/cve-2026-10109-ibm-db2-remote-code-execution-in-drda-handshake"},{"cve":"CVE-2026-10534","cvss":8.4,"epss":0.0038,"slug":"cve-2026-10534-ibm-db2-buffer-overflow-in-ixf-import-parser","title":"IBM Db2 buffer overflow in IXF IMPORT parser","severity":"high","exploited":false,"published_at":"2026-08-12T22:17:14.203+00:00","url":"https://junglewise.ai/threats/cve-2026-10534-ibm-db2-buffer-overflow-in-ixf-import-parser"},{"cve":"CVE-2026-10535","cvss":8.4,"slug":"cve-2026-10535-ibm-db2-privilege-escalation-in-db2flacc-setgid-helper","title":"IBM Db2 privilege escalation in db2flacc setgid helper","severity":"high","exploited":false,"published_at":"2026-07-30T19:17:01.167+00:00","url":"https://junglewise.ai/threats/cve-2026-10535-ibm-db2-privilege-escalation-in-db2flacc-setgid-helper"},{"cve":"CVE-2026-87958","cvss":8.1,"epss":0.0038,"slug":"cve-2026-87958-ibm-db2-denial-of-service-via-privilege-management","title":"IBM Db2 denial of service via privilege management","severity":"high","exploited":false,"published_at":"2026-09-10T22:17:04.76+00:00","url":"https://junglewise.ai/threats/cve-2026-87958-ibm-db2-denial-of-service-via-privilege-management"},{"cve":"CVE-2026-86093","cvss":7.5,"epss":0.0045,"slug":"cve-2026-86093-ibm-db2-stack-based-buffer-overflow-in-drda-client","title":"IBM Db2 stack-based buffer overflow in DRDA client","severity":"high","exploited":false,"published_at":"2026-09-10T22:17:04.62+00:00","url":"https://junglewise.ai/threats/cve-2026-86093-ibm-db2-stack-based-buffer-overflow-in-drda-client"},{"cve":"CVE-2026-15955","cvss":7.5,"epss":0.004,"slug":"cve-2026-15955-ibm-db2-arbitrary-file-write-via-path-traversal","title":"IBM Db2 arbitrary file write via path traversal","severity":"high","exploited":false,"published_at":"2026-09-14T20:16:39.057+00:00","url":"https://junglewise.ai/threats/cve-2026-15955-ibm-db2-arbitrary-file-write-via-path-traversal"},{"cve":"CVE-2026-1718","cvss":7.1,"slug":"cve-2026-1718-ibm-db2-denial-of-service-in-autonomous-transactions","title":"IBM Db2 denial of service in autonomous transactions","severity":"high","exploited":false,"published_at":"2026-05-27T14:16:43.883+00:00","url":"https://junglewise.ai/threats/cve-2026-1718-ibm-db2-denial-of-service-in-autonomous-transactions"},{"cve":"CVE-2026-17463","cvss":6.5,"epss":0.0035,"slug":"cve-2026-17463-ibm-db2-denial-of-service-in-resource-consumption","title":"IBM Db2 denial of service in resource consumption","severity":"medium","exploited":false,"published_at":"2026-09-14T20:16:41.857+00:00","url":"https://junglewise.ai/threats/cve-2026-17463-ibm-db2-denial-of-service-in-resource-consumption"},{"cve":"CVE-2026-16702","cvss":6.5,"epss":0.0035,"slug":"cve-2026-16702-ibm-db2-null-pointer-dereference-in-federated-server","title":"IBM Db2 null pointer dereference in federated server","severity":"medium","exploited":false,"published_at":"2026-09-14T20:16:41.173+00:00","url":"https://junglewise.ai/threats/cve-2026-16702-ibm-db2-null-pointer-dereference-in-federated-server"},{"cve":"CVE-2026-11906","cvss":6.5,"slug":"cve-2026-11906-ibm-db2-denial-of-service-in-xmltable-query-logic","title":"IBM Db2 denial of service in XMLTable query logic","severity":"medium","exploited":false,"published_at":"2026-06-30T20:17:28.273+00:00","url":"https://junglewise.ai/threats/cve-2026-11906-ibm-db2-denial-of-service-in-xmltable-query-logic"}],"generated_at":"2026-09-27T03:07:00.185062+00:00"}