CVE-2026-86093
published 2026-09-10CVE-2026-86093: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute…
PriorityP352high7.5CVSS 3.1
AVNACHPRLUINSUCHIHAH
EPSS
0.45%
36.5th percentile
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that improperly copies user-controlled data into a fixed-size stack buffer without bounds checking.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | db2 | 11.5 – 11.5.9 | — |
| ibm | db2 | 11.5.0 – 11.5.9 | — |
| ibm | db2 | 12.1.0 – 12.1.5 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a
ghsa_unreviewed·2026-09-11
CVE-2026-86093 [HIGH] CWE-121 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that improperly copies user-controlled data into a fixed-size stack buffer without bounds checking.
VulDB
IBM Db2 up to 11.5.9/12.1.5 buffer overflow
vuldb·2026-09-10·CVSS 7.5
CVE-2026-86093 [HIGH] IBM Db2 up to 11.5.9/12.1.5 buffer overflow
A vulnerability was found in IBM Db2 up to 11.5.9/12.1.5 and classified as very critical. Affected by this issue is some unknown functionality. Executing a manipulation can lead to buffer overflow.
This vulnerability appears as CVE-2026-86093. The attack may be performed from remote. There is no available exploit.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-10
Published