IBM patched 18 flaws in Db2 Mirror for i this week. The worst bug lets a remote attacker run system commands without logging in. IBM Db2 Mirror RCE risk reaches a CVSS score of 9.9. Also, several other bugs allow data theft, file tampering, and denial of service. Admins should apply the new PTFs right away.
- Total: 18 CVEs
- Severity: 4 Critical · 8 High · 6 Medium
- Actively exploited: None confirmed
- Highest severity: 9.9 (Critical · CVSSv3) — CVE-2026-17186
- Action: Apply the latest security updates now
Notable CVEs
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-17186 | 9.9 | CWE-78 | — | Not exploited |
| CVE-2026-17184 | 9.8 | CWE-73 | — | Not exploited |
| CVE-2026-17182 | 9.8 | CWE-287 | — | Not exploited |
| CVE-2026-17181 | 9.3 | CWE-22 | — | Not exploited |
| CVE-2026-16879 | 8.8 | CWE-285 | — | Not exploited |
| CVE-2026-17179 | 8.5 | CWE-78 | — | Not exploited |
| CVE-2026-16708 | 8.3 | CWE-15 | — | Not exploited |
| CVE-2026-17081 | 8.2 | CWE-22 | — | Not exploited |
Why It Matters
Db2 Mirror for i keeps two IBM i systems in sync for high availability. Its GUI runs with strong system access to manage that sync. So, a flaw in the GUI can hand an attacker the same reach. Because the worst issues need no password and no user click, they are easy to automate. That combination makes patching urgent for any shop running Db2 Mirror. A successful attack could pause data mirroring altogether, disrupting failover during an outage. Meanwhile, mirrored systems often sit at the core of banking, retail, or logistics operations, which raises the stakes further.
How the Attacks Work
Command Injection and Remote Code Execution
The top flaw, CVE-2026-17186, drives most of the IBM Db2 Mirror RCE risk here. It lets an attacker slip extra CL commands into a request. Then, the GUI fails to filter special characters before running them. Similarly, a second bug, CVE-2026-17184, lets an attacker control a file path used by the system. That path confusion can lead to arbitrary code execution too. Neither flaw needs a password, since both allow unauthenticated network access.
Authentication Bypass and Path Traversal
CVE-2026-17182 lets an attacker skip login entirely by sending a crafted request path. In addition, several other bugs, including CVE-2026-17181, let an attacker read or write files outside their intended folder. Path traversal issues like these can expose sensitive system data. Finally, a handful of lower-severity bugs add SQL injection, cross-site scripting, and denial-of-service risks on top.
Affected Versions
The flaws affect Db2 Mirror for i on releases 7.4, 7.5, and 7.6. Still, IBM has not published how many organizations run the affected GUI. No source confirms active exploitation, and no public proof-of-concept exists for any of these 18 flaws today.
Patch and Mitigation Steps
IBM released PTFs for all three releases. Then, install SJ10947 on 7.4, SJ10961 on 7.5, or SJ10948 on 7.6. Full download links and instructions sit in IBM’s security bulletin. Given the top score of 9.9, this IBM Db2 Mirror RCE risk should not wait for routine maintenance. After installing the fix, confirm the GUI service restarts before returning it to production.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.