Skip to main content

CVE-2026-10109 - IBM® Db2® is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling

  • June 26, 2026
  • 1 comment
  • 32 views

CMF
Forum|alt.badge.img+8
  • Veeam Legend

New CVE for IBM Db2 with a Score of 9.8.

Here is the corresponding link to the IBM - Support homepage:

Security Bulletin: IBM® Db2® is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling (CVE-2026-10109)

Summary

IBM® Db2® is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling.

Vulnerability Details

CVEID:   CVE-2026-10109
DESCRIPTION:   IBM Db2 is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling.
CWE:   CWE-94: Improper Control of Generation of Code ('Code Injection')
CVSS Source:   IBM
CVSS Base score:   9.8
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

1 comment

coolsport00
Forum|alt.badge.img+23
  • Veeam Legend
  • June 26, 2026

Thanks for sharing this security vulnerability Chalid. Thankfully I have no IBMs in my environment. But, this’ll certainly be helpful to those who do!