CVE-2026-18554: IBM DB2 Mirror For I
High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.
Affected products
- IBM DB2 Mirror For I: from 7.4, up to and including 7.6
Published 2026-08-14. Last modified 2026-08-21.