Review reviewHigh
CVE-2026-10535
IBM Db2
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc.
- CVSS
- 8.4
- EPSS
- 0.11% 1.62% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.31
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc.
The CVSS severity warrants an early asset and exposure review.
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc.
Confirm exposure before applying a vendor-supported change.
Confirm that IBM Db2 and an affected version are present.
Combine exploitation signals with asset exposure and business criticality.
Follow the vendor advisory or supported update path and preserve rollback options.
Recheck the version, service health, access paths, and relevant logs.