CVE-2026-10535
published 2026-07-30CVE-2026-10535: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc.
PriorityP343high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.11%
1.6th percentile
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | db2 | 11.5.0 – 11.5.9 | — |
| ibm | db2 | >= 12.1.0 < 12.1.5 | 12.1.5 |
| ibm | db2 | 12.1.0 – 12.1.4 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc.
ghsa_unreviewed·2026-07-30
CVE-2026-10535 [HIGH] CWE-121 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc.
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc.
VulDB
IBM Db2 up to 11.5.9/12.1.4 db2flacc buffer overflow
vuldb·2026-07-30·CVSS 8.4
CVE-2026-10535 [HIGH] IBM Db2 up to 11.5.9/12.1.4 db2flacc buffer overflow
A vulnerability was found in IBM Db2 up to 11.5.9/12.1.4. It has been rated as very critical. This affects the function db2flacc. The manipulation leads to buffer overflow.
This vulnerability is documented as CVE-2026-10535. The attack can be initiated remotely. There is not any exploit available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-30
Published