Review reviewHigh
CVE-2026-9762
IBM Db2, db2
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under user control.
- CVSS
- 7.8
- EPSS
- - - percentile
- CISA KEV
- Not listed
- Published
- 2026.07.18
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under user control.
The CVSS severity warrants an early asset and exposure review.
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under user control.
Confirm exposure before applying a vendor-supported change.
Confirm that IBM Db2, db2 and an affected version are present.
Combine exploitation signals with asset exposure and business criticality.
Follow the vendor advisory or supported update path and preserve rollback options.
Recheck the version, service health, access paths, and relevant logs.