
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
CVE-2026-16702 is a NULL pointer dereference vulnerability in IBM Db2 that allows a remote authenticated attacker to cause a denial of service. It affects IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 for Linux, UNIX, and Windows, including DB2 Connect Server. The vulnerability was published on September 14, 2026, and carries a CVSS v3.1 base score of 6.5 (Medium) (IBM Advisory).
The root cause is a NULL pointer dereference (CWE-476) within the IBM Db2 database engine. An authenticated remote attacker can trigger the flaw over the network with low attack complexity and no user interaction required, causing the Db2 process to crash. The attack vector is network-based, requiring only low-level authenticated access (e.g., a valid database user account) as a precondition for exploitation (IBM Advisory).
Successful exploitation results in a denial of service, crashing or making the IBM Db2 database instance unavailable. There is no impact to confidentiality or integrity — only availability is affected. Organizations relying on Db2 for critical database workloads could experience service outages, potentially disrupting dependent applications and business processes (IBM Advisory).
As of the time of publication, there are no known public proof-of-concept exploits, exploit kits, or evidence of in-the-wild exploitation for CVE-2026-16702. The EPSS score is approximately 0.345%, indicating a low probability of exploitation in the near term. The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (IBM Advisory).
IBM has published a security advisory (IBM Support Page 7286981) addressing this vulnerability. Affected users should apply the patches or fix packs provided by IBM for Db2 versions 11.5.x and 12.1.x. Organizations unable to patch immediately should restrict database access to trusted, authenticated users only and monitor for unexpected Db2 process crashes or restarts (IBM Advisory).
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"