CVE-2026-17182: IBM DB2 Mirror For I

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to improper validation of request URI path segments.

Affected products

  • IBM DB2 Mirror For I: from 7.4, up to and including 7.6

Published 2026-08-14. Last modified 2026-08-20.