VYPR
Vypr IntelligenceAI-generatedSep 10, 2026· 25 CVEs

IBM: 25 Vulnerabilities Across Db2, Langflow OSS, and DataStage Disclosed Together

IBM addresses 25 vulnerabilities in Db2, Langflow OSS, and DataStage, including critical flaws enabling code execution and data breaches.

Key findings

  • 25 vulnerabilities disclosed across IBM Db2, Langflow OSS, and DataStage on Cloud Pak for Data on September 10, 2026.
  • Critical vulnerabilities in Langflow OSS (CVE-2026-81204) and DataStage (CVE-2026-82107, CVE-2026-82100) allow for code execution and sensitive data access.
  • Multiple flaws in Langflow OSS enable arbitrary code execution via injection, improper authorization, and unsafe eval() calls.
  • Path traversal and OS command injection vulnerabilities affect IBM DataStage, impacting file system access and system commands.
  • Affected versions range from IBM Db2 11.5.0 to 12.1.5, Langflow OSS 1.0.0 to 1.11.5, and DataStage on Cloud Pak for Data 5.4.0.0.

On September 10, 2026, a significant batch of 25 vulnerabilities was disclosed across multiple IBM products, including IBM Db2, IBM Langflow OSS, and IBM DataStage on Cloud Pak for Data. The vulnerabilities, all disclosed on the same day, range in severity from Medium to Critical, with several allowing for arbitrary code execution, denial of service, and sensitive information disclosure. This coordinated disclosure event highlights potential risks for organizations utilizing these IBM offerings.

IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 are affected by three vulnerabilities. CVE-2026-87958, a High severity flaw, allows a privileged user to disable specific functionality. CVE-2026-86093, also High severity, involves a stack-based buffer overflow that could lead to arbitrary command execution on Db2 clients when an attacker controls a DRDA server endpoint. A Medium severity vulnerability, CVE-2026-86087, permits an authenticated user to write arbitrary files to the system via a specially crafted request.

IBM Langflow OSS versions 1.0.0 through 1.11.5 (and 1.0.0 through 1.10.3 for CVE-2026-84889) are impacted by a substantial number of vulnerabilities, including two Critical flaws. CVE-2026-81204, with a CVSSv3 score of 9.8, allows arbitrary code execution due to code injection during graph construction. CVE-2026-84889, rated High (8.8), involves improper limitation of a pathname to a restricted directory, enabling arbitrary code execution for remote authenticated attackers. Other High severity vulnerabilities in Langflow OSS include CVE-2026-81211 (improper authorization of custom components), CVE-2026-81940 (improper neutralization of special characters in flow display names), and CVE-2026-81213 (improper validation of user-supplied URLs leading to sensitive information disclosure). CVE-2026-81268, another High severity flaw, exploits insufficient session expiration of API keys after user deactivation, allowing attackers to execute flows and obtain sensitive information. CVE-2026-81941 allows authenticated non-administrative users to execute arbitrary OS commands.

IBM DataStage on Cloud Pak for Data 5.4.0.0 is affected by numerous High and Critical severity vulnerabilities. CVE-2026-82107 and CVE-2026-82100, both Critical (9.6), allow remote authenticated attackers to obtain sensitive information and bypass security restrictions due to improper authentication, and cause a denial of service due to path traversal, respectively. Multiple High severity vulnerabilities, including CVE-2026-82099, CVE-2026-82098, and CVE-2026-82095, involve improper neutralization of OS command elements, leading to arbitrary code execution. Path traversal vulnerabilities are prevalent, with CVE-2026-81554 and CVE-2026-81551 allowing sensitive information disclosure and arbitrary file deletion, respectively. CVE-2026-81540 permits overwriting ruleset files belonging to other tenants, and CVE-2026-81210 involves IDOR plus traversal for accessing job logs. CVE-2026-82097 (SSRF) and CVE-2026-82099 (OS command execution) also pose significant risks. CVE-2026-80436, a High severity flaw, allows attackers to delete arbitrary RabbitMQ queues or exchanges, causing a denial of service.

The coordinated disclosure of these 25 vulnerabilities across multiple IBM products underscores the importance of timely patching and security updates. Users are advised to consult IBM's official advisories for specific version information and remediation guidance. The breadth of issues, particularly the critical code execution flaws in Langflow OSS and DataStage, necessitates prompt attention from affected organizations to mitigate potential security risks.

The vulnerabilities affect IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5. IBM Langflow OSS versions 1.0.0 through 1.11.5 are impacted, with CVE-2026-84889 affecting up to 1.10.3. IBM DataStage on Cloud Pak for Data version 5.4.0.0 is affected by numerous vulnerabilities.

The batch of vulnerabilities was disclosed on September 10, 2026. Multiple critical and high-severity vulnerabilities allow for arbitrary code execution. Path traversal and improper neutralization of OS commands are common themes across affected products. CVE-2026-81204 and CVE-2026-82107 are among the critical severity flaws. The vulnerabilities span IBM Db2, IBM Langflow OSS, and IBM DataStage on Cloud Pak for Data.

AI-written article. Grounded in 25 CVE records listed below.