CVE-2025-13867
published 2026-02-17CVE-2025-13867: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 could allow an authenticated user to cause a…
PriorityP431medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.23%
14.1th percentile
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | db2 | 11.5.0 – 11.5.9 | — |
| ibm | db2 | 12.1.0 – 12.1.3 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-36365 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-36365 [MEDIUM] CVE-2025-36365 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-36365 :
IBM Db2 vulnerability analysis and mitigation
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 under specific configuration of cataloged remote storage aliases could allow an authenticated user to execute unauthorized commands due to an authorization bypass vulnerability using a user-controlled key.
Source : NVD
## 7.5
Score
Published January 30, 2026
Severity HIGH
CNA Score 6.8
Affected Technologies
IBM Db2
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
linux-fips
linux-gcp-fips
Sources
Ubuntu 16.04, 18.04, 20.04 Severity
Wiz
CVE-2025-13867 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-13867 [MEDIUM] CVE-2025-13867 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-13867 :
IBM Db2 vulnerability analysis and mitigation
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic
Source : NVD
## 6.5
Score
Published February 17, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
IBM Db2
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ibm:db2
Sources
Linux Severity MEDIUM No Fix Added at: Feb 18, 2026
Windows Severity MEDIUM No Fix Added at: Feb 18, 2026
Linux
Wiz
CVE-2025-36070 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-36070 [MEDIUM] CVE-2025-36070 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-36070 :
IBM Db2 vulnerability analysis and mitigation
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 is vulnerable to a denial of service as a trap may occur when selecting from certain types of tables.
Source : NVD
## 7.5
Score
Published January 30, 2026
Severity HIGH
CNA Score 6.5
Affected Technologies
IBM Db2
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
linux-aws-fips
linux-azure-fips
Sources
Ubuntu 16.04, 18.04, 20.04 Severity MEDIUM No Fix Added at: Feb 02, 2026
Linux Severity MEDIUM Has Fix Added at: Jan 31, 2026
Windo
Wiz
CVE-2025-36424 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-36424 [MEDIUM] CVE-2025-36424 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-36424 :
IBM Db2 vulnerability analysis and mitigation
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a denial of service due to improper neutralization of special elements in data query logic.
Source : NVD
## 6.5
Score
Published January 30, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
IBM Db2
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
linux-gcp-fips
cpe:2.3:a:ibm:db2
Sources
Ubuntu 16.04, 18.04, 20.04 Severity MEDIUM No Fix Added at: Feb 02, 2026
Linux Severity MEDIUM Has Fix Added at: Jan 31, 2026
Windows Severity MED
Wiz
CVE-2025-36001 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-36001 [MEDIUM] CVE-2025-36001 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-36001 :
IBM Db2 vulnerability analysis and mitigation
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an authenticated user to cause a denial of service using a specially crafted SQL statement including XML that performs uncontrolled recursion.
Source : NVD
## 6.5
Score
Published January 30, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
IBM Db2
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
linux-gcp-fips
cpe:2.3:a:ibm:db2
Sources
Ubuntu 16.04, 18.04, 20.04 Severity MEDIUM No Fix Added at: Feb 02, 2026
Lin
Wiz
CVE-2025-36123 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-36123 [MEDIUM] CVE-2025-36123 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-36123 :
IBM Db2 vulnerability analysis and mitigation
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow a local user to cause a denial of service when copying large table containing XML data due to improper allocation of system resources.
Source : NVD
## 5.5
Score
Published January 30, 2026
Severity MEDIUM
CNA Score 6.2
Affected Technologies
IBM Db2
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ibm:db2
linux-aws-fips
Sources
Ubuntu 16.04, 18.04, 20.04 Severity MEDIUM No Fix Added at: Feb 02, 2026
Linux Sever
Wiz
CVE-2025-36423 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-36423 [MEDIUM] CVE-2025-36423 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-36423 :
IBM Db2 vulnerability analysis and mitigation
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 12.1.0 - 12.1.3 could allow a local user to cause a denial of service due to improper neutralization of special elements in data query logic.
Source : NVD
## 5.5
Score
Published January 30, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
IBM Db2
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
linux-azure-fips
linux-fips
Sources
Ubuntu 16.04, 18.04, 20.04 Severity MEDIUM No Fix Added at: Feb 02, 2026
Linux Severity MEDIUM No Fix Added at: Jan 31, 2026
Wind
Wiz
CVE-2025-36184 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-36184 [MEDIUM] CVE-2025-36184 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-36184 :
IBM Db2 vulnerability analysis and mitigation
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 could allow an instance owner to execute malicious code that escalate their privileges to root due to execution of unnecessary privileges operated at a higher than minimum level.
Source : NVD
## 7.2
Score
Published January 30, 2026
Severity HIGH
CNA Score 7.2
Affected Technologies
IBM Db2
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ibm:db2
linux-aws-fips
Sources
Ubuntu 16.04, 18.04, 20.04 Severity MEDIUM No Fix Added at: Feb 02, 2026
Wiz
CVE-2025-2668 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-2668 [MEDIUM] CVE-2025-2668 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-2668 :
IBM Db2 vulnerability analysis and mitigation
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 is vulnerable to a denial of service as the server may crash when an authenticated user creates a specially crafted query.
Source : NVD
## 6.5
Score
Published January 30, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
IBM Db2
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
linux-azure-fips
linux-fips
Sources
Ubuntu 16.04, 18.04, 20.04 Severity MEDIUM No Fix Added at: Feb 02, 2026
Linux Severity MEDIUM Has Fix Added at: Jan 31, 2026
Windows
Wiz
CVE-2025-14689 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-14689 [MEDIUM] CVE-2025-14689 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14689 :
IBM Db2 vulnerability analysis and mitigation
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 12.1.0 through 12.1.3 could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic with federated objects.
Source : NVD
## 6.5
Score
Published February 17, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
IBM Db2
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 19.1
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
cpe:2.3:a:ibm:db2
Sources
Linux Severity MEDIUM No Fix Added at: Feb 18, 2026
Windows Severity MEDIUM No Fix Added at: Feb 18, 2026
Linux Se
Wiz
CVE-2025-36427 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-36427 [MEDIUM] CVE-2025-36427 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-36427 :
IBM Db2 vulnerability analysis and mitigation
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a denial of service due to insufficient validation of special elements in data query logic.
Source : NVD
## 6.5
Score
Published January 30, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
IBM Db2
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
linux-aws-fips
linux-azure-fips
Sources
Ubuntu 16.04, 18.04, 20.04 Severity MEDIUM No Fix Added at: Feb 02, 2026
Linux Severity MEDIUM Has Fix Added at: Jan 31, 2026
Windows Severity MEDI
Wiz
CVE-2025-36384 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-36384 [MEDIUM] CVE-2025-36384 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-36384 :
IBM Db2 vulnerability analysis and mitigation
IBM Db2 for Windows 12.1.0 - 12.1.3 could allow a local user with filesystem access to escalate their privileges due to the use of an unquoted search path element.
Source : NVD
## 7.8
Score
Published January 30, 2026
Severity HIGH
CNA Score 8.4
Affected Technologies
IBM Db2
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ibm:db2
Sources
Linux Severity HIGH No Fix Added at: Jan 31, 2026
Windows Severity HIGH No Fix Added at: Jan 31, 2026
Linux Severity HIGH No Fix Added at: Feb 08, 2026
Windows Severity HIGH No Fix Added at: Feb 08,
Wiz
CVE-2025-36009 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-36009 [MEDIUM] CVE-2025-36009 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-36009 :
IBM Db2 vulnerability analysis and mitigation
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service due to excessive use of a global variable.
Source : NVD
## 6.5
Score
Published January 30, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
IBM Db2
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ibm:db2
linux-aws-fips
Sources
Ubuntu 16.04, 18.04, 20.04 Severity MEDIUM No Fix Added at: Feb 02, 2026
Linux Severity MEDIUM Has Fix Added at: Jan 31, 2026
Windows Severity MEDIUM Has Fix Ad
Wiz
CVE-2025-36428 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-36428 [MEDIUM] CVE-2025-36428 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-36428 :
IBM Db2 vulnerability analysis and mitigation
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic when the RPSCAN feature is enabled.
Source : NVD
## 5.3
Score
Published January 30, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
IBM Db2
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
linux-aws-fips
linux-azure-fips
Sources
Ubuntu 16.04, 18.04, 20.04 Severity MEDIUM No Fix Added at: Feb
Wiz
CVE-2025-36407 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-36407 [MEDIUM] CVE-2025-36407 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-36407 :
IBM Db2 vulnerability analysis and mitigation
IBM® Db2® is vulnerable to a denial of service with a specially crafted query that uses ALTER TABLE operations.
Source : NVD
## 5.5
Score
Published January 30, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
IBM Db2
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
linux-fips
linux-gcp-fips
Sources
Ubuntu 16.04, 18.04, 20.04 Severity MEDIUM No Fix Added at: Feb 02, 2026
Linux Severity MEDIUM Has Fix Added at: Jan 31, 2026
Windows Severity MEDIUM Has Fix Added at: Jan 31, 2026
Linux Severity MEDIUM No Fix Added at: Feb 08
Wiz
CVE-2025-36353 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-36353 [MEDIUM] CVE-2025-36353 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-36353 :
IBM Db2 vulnerability analysis and mitigation
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow a local user to cause a denial of service due to improper neutralization of special elements in data query logic.
Source : NVD
## 5.5
Score
Published January 30, 2026
Severity MEDIUM
CNA Score 6.2
Affected Technologies
IBM Db2
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
linux-gcp-fips
cpe:2.3:a:ibm:db2
Sources
Ubuntu 16.04, 18.04, 20.04 Severity MEDIUM No Fix Added at: Feb 02, 2026
Linux Severity MEDIUM Has Fix Ad
Wiz
CVE-2025-36366 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-36366 [MEDIUM] CVE-2025-36366 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-36366 :
IBM Db2 vulnerability analysis and mitigation
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a denial of service by executing a query that invokes the JSON_Object scalar function, which may trigger an unhandled exception leading to abnormal server termination.
Source : NVD
## 6.5
Score
Published January 30, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
IBM Db2
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
linux-azure-fips
linux-fips
Sources
Ubuntu 16.04, 18.04, 20.04 Severity MEDIUM No Fix Added at: Feb 02, 2026
Lin
Wiz
CVE-2025-36387 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-36387 [MEDIUM] CVE-2025-36387 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-36387 :
IBM Db2 vulnerability analysis and mitigation
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 - 11.5.9 could allow an authenticated user to cause a denial of service when given specially crafted query.
Source : NVD
## 6.5
Score
Published January 30, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
IBM Db2
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ibm:db2
linux-aws-fips
Sources
Ubuntu 16.04, 18.04, 20.04 Severity MEDIUM No Fix Added at: Feb 02, 2026
Linux Severity MEDIUM Has Fix Added at: Jan 31, 2026
Windows Severity MEDIUM H
Wiz
CVE-2025-36247 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-36247 [MEDIUM] CVE-2025-36247 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-36247 :
IBM Db2 vulnerability analysis and mitigation
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Source : NVD
## 8.2
Score
Published February 17, 2026
Severity HIGH
CNA Score 7.1
Affected Technologies
IBM Db2
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 42.3
Exploitation Probability (EPSS) 0.2
Affected packages and libraries
cpe:2.3:a:ibm:db2
Sources
Linux Severity HIGH No Fix Added at: Feb 18, 2026
Wiz
CVE-2025-36442 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-36442 [MEDIUM] CVE-2025-36442 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-36442 :
IBM Db2 vulnerability analysis and mitigation
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query with XML columns.
Source : NVD
## 7.5
Score
Published January 30, 2026
Severity HIGH
CNA Score 6.5
Affected Technologies
IBM Db2
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
linux-gcp-fips
cpe:2.3:a:ibm:db2
Sources
Ubuntu 16.04, 18.04, 20.04 Severity MEDIUM No Fix Added at: Feb 02, 2026
Linux Severity MEDIUM Has
Wiz
CVE-2025-36425 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-36425 [MEDIUM] CVE-2025-36425 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-36425 :
IBM Db2 vulnerability analysis and mitigation
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 could allow an authenticated user to obtain sensitive information under specific HADR configuration.
Source : NVD
## 6.5
Score
Published February 17, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
IBM Db2
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ibm:db2
Sources
Linux Severity MEDIUM No Fix Added at: Feb 18, 2026
Windows Severity MEDIUM No Fix Added at: Feb 18, 2026
Linux Severity MEDIUM No Fix Added at:
Wiz
CVE-2025-36098 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-36098 [MEDIUM] CVE-2025-36098 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-36098 :
IBM Db2 vulnerability analysis and mitigation
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an authenticated user to cause a denial of service due to improper allocation of resources.
Source : NVD
## 6.5
Score
Published January 30, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
IBM Db2
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
linux-azure-fips
linux-fips
Sources
Ubuntu 16.04, 18.04, 20.04 Severity MEDIUM No Fix Added at: Feb 02, 2026
Linux Severity MEDIUM Has Fix Added at: Jan 31, 2026
Windo
2026-02-17
Published