CVE-2026-17186: IBM DB2 Mirror For I

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special elements in a command.

Affected products

  • IBM DB2 Mirror For I: from 7.4, up to and including 7.6

Published 2026-08-14. Last modified 2026-08-21.