CVE-2026-18104: IBM DB2 Mirror For I

Low severity, CVSS 3.3. EPSS: 0.1% chance of exploitation in the next 30 days.

IBM Db2 Mirror for i 7.6, 7.5, and 7.4 could allow a local attacker to obtain sensitive information due to the use of the AES Electronic Codebook (ECB) mode for encryption.

Affected products

  • IBM DB2 Mirror For I: from 7.4, up to and including 7.6

Published 2026-09-24. Last modified 2026-09-29.