CVE-2026-3856: IBM DB2 Recovery Expert

Critical severity, CVSS 9.1. EPSS: 0.2% chance of exploitation in the next 30 days.

IBM Db2 Recovery Expert for Linux, UNIX and Windows 5.5 IF 2 could allow an attacker to modify or corrupt data due to an insecure mechanism used for verifying the integrity of the data during transmission.

Affected products

  • IBM DB2 Recovery Expert: version 5.5.0 only

Published 2026-03-17. Last modified 2026-06-17.