Synced 03 Aug 2026 05:54 UTC Account
← IBM Db2

IBM Db2 vulnerabilities: known CVEs & security history

IBM · Database · 9 tracked CVEs · 0 actively exploited · updated August 2026 · what is a CVE? →

This is the full list of known vulnerabilities (CVEs) across all IBM Db2 release lines — 9 in total. A CVE here doesn't mean your version is affected — check IBM Db2's current status and the safe version to run.

9
known CVEs
0
actively exploited (KEV)
1
critical severity
0
ransomware-linked

Known IBM Db2 CVEs

Actively-exploited and most-severe first. Open any CVE for full details.

CVESeverityCVSSEPSSYear
CVE-2026-10109 critical 9.8 1% 2026
CVE-2026-9762 high 7.8 0% 2026
CVE-2026-11906 medium 6.5 0% 2026
CVE-2024-54178 medium 6.5 0% 2026
CVE-2025-2669 medium 6 0% 2026
CVE-2026-7771 medium 5.5 0% 2026
CVE-2025-36372 medium 5.5 0% 2026
CVE-2025-13755 medium 5.5 0% 2026
CVE-2023-33854 medium 5.3 0% 2026

Is my IBM Db2 version affected?

The list above spans every release. To know whether your version is affected — and the minimum safe version to upgrade to — check it directly.

Check your IBM Db2 version → · Monitor IBM Db2 for new CVEs →

IBM Db2 vulnerabilities — frequently asked

How many known vulnerabilities does IBM Db2 have?

IsItPatched tracks 9 CVEs for IBM Db2. 1 is critical-severity and 1 high-severity. These span every release line — what matters is whether the version you run is affected.

Does IBM Db2 have any actively-exploited vulnerabilities?

None of IBM Db2's tracked CVEs are currently in CISA's KEV catalog — but new ones can be added at any time, so keep your version current.

What is the most severe IBM Db2 vulnerability?

Among tracked issues, CVE-2026-10109 (CRITICAL, CVSS 9.8) ranks highest — a Code injection weakness.

Is IBM Db2 safe to use?

It depends on the version. The latest supported IBM Db2 release clears the known issues; older versions may still be affected. Check the exact version you run for a verdict.

CVE data aggregated from NVD, CISA KEV and EPSS (FIRST.org). Related: IBM Db2 security status · IBM Db2 end-of-life · actively-exploited CVEs. Always verify against IBM's advisories — see our disclaimer.