CVE-2026-10109
Critical · CVSS 9.8IBM Db2 — Remote Code Execution via improper pre-auth DRDA handshake handling (CWE-94 Code Injection)
- CVSS
- 9.8
- nvd
- EPSS
- 0.86%
- 54th pct
- KEV
- No
- Class
- other
- CWE-94
Description
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling.
Search profile — drives PoC discovery
Symbols DRDAhandshakepre-authDb2DRDA handshake handlerRCEDRDA protocolIBM Db2 DRDA
Keywords CVE-2026-10109IBM Db2 RCEDb2 DRDA handshake vulnerabilityDb2 pre-auth remote code executionIBM Db2 11.5 exploitIBM Db2 12.1 exploitDb2 DRDA PoCCWE-94 IBM Db2IBM Db2 code injection
Versions: 11.5.0 through 11.5.9, 12.1.0 through 12.1.4
References
Status: enriched · ingested 2026-07-02T18:00:43.000Z · profiled 2026-07-02T18:30:43.000Z