← Vulnerability feed

Vulnerability record · CVE-2026-10534 · published 12 August 2026

CVE-2026-10534: Ibm db2 stack-based buffer overflow vulnerability

Ibm · Db2

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser.

9.8 CVSS 3.1 Critical EPSS 0.38% · top 71.1% CWE-121 · Stack-based buffer overflow
9.8CVSS 3.1 base score
0.38%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Aug 2026Last modified by NVD

Description

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-10534 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2012-1797Ibm db2 permissions and access controls vulnerabilityIBM DB2 9.5 uses world-writable permissions for nodes.reg, which has unspecified impact and attack vectors.EPSS 1.7%10.0CVE-2010-3731Ibm db2 memory buffer overflow vulnerabilityStack-based buffer overflow in the validateUser implementation in the com.ibm.db2.das.core.DasSysCmd function in db2dasrrm in the DB2 Administration …EPSS 9.6%10.0CVE-2010-3193Ibm db2 vulnerabilityUnspecified vulnerability in the DB2STST program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 has unknown impact and attack vectors.EPSS 2.7%10.0CVE-2009-4335Ibm db2 vulnerabilityMultiple unspecified vulnerabilities in bundled stored procedures in the Spatial Extender component in IBM DB2 9.5 before FP5 have unknown impact and…EPSS 2.3%10.0CVE-2009-3473Ibm db2 vulnerabilityIBM DB2 9.1 before FP8 does not require the SETSESSIONUSER privilege for the SET SESSION AUTHORIZATION statement, which has unspecified impact and re…EPSS 2.0%10.0CVE-2008-6820Ibm db2 vulnerabilityThe db2fmp process in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 on Windows runs with "OS privilege," which has unknown impact and att…EPSS 1.8%10.0CVE-2008-6821Ibm db2 memory buffer overflow vulnerabilityBuffer overflow in the DAS server in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 might allow attackers to execute arbitrary code or cau…EPSS 3.7%10.0CVE-2008-4692Ibm db2 vulnerabilityThe Native Managed Provider for .NET component in IBM DB2 8 before FP17, 9.1 before FP6, and 9.5 before FP2, when a definer cannot maintain objects, …EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2026-10534), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.