CVE-2026-18554: IBM DB2 Mirror For I

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.

Affected products

  • IBM DB2 Mirror For I: from 7.4, up to and including 7.6

Published 2026-08-14. Last modified 2026-08-21.