CVE-2026-10534
published 2026-08-12CVE-2026-10534: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser.
PriorityP355critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.38%
29.2th percentile
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | db2 | 11.5 – 11.5.9 | — |
| ibm | db2 | 11.5.0 – 11.5.9 | — |
| ibm | db2 | 12.1.0 – 12.1.5 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser.
ghsa_unreviewed·2026-08-13
CVE-2026-10534 [HIGH] CWE-121 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser.
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser.
VulDB
IBM Db2 up to 11.5.9/12.1.5 IXF IMPORT parser buffer overflow
vuldb·2026-08-12·CVSS 8.4
CVE-2026-10534 [HIGH] IBM Db2 up to 11.5.9/12.1.5 IXF IMPORT parser buffer overflow
A vulnerability classified as very critical was found in IBM Db2 up to 11.5.9/12.1.5. This affects an unknown function of the component IXF IMPORT parser. The manipulation results in buffer overflow.
This vulnerability was named CVE-2026-10534. The attack may be performed from remote. There is no available exploit.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-12
Published