CVE-2026-10535: IBM DB2

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc.

Affected products

  • IBM DB2: from 11.5.0, up to and including 11.5.9; from 12.1.0, before 12.1.5 (fixed in 12.1.5)

Published 2026-07-30. Last modified 2026-08-05.