ELEVATED 3 min read 23 Aug 2026

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path traversal. Leads Today's Security Review

Threat Level: Elevated Tags: cve-2026-17181, cwe-22, cve-2026-14163, cwe-532, cve-2026-44223, cwe-131, cwe-704, cve-2026-20177, cve-2026-20232, cwe-770

Key findings
01
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path traversal.
CRITICAL
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path traversal. CVE coverage: CVE-2026-17181.
02
Vulnerability in Octopus Deploy Server
HIGH
A remote authenticated attacker can exploit a vulnerability in Octopus Deploy Server to disclose information. CVE coverage: CVE-2026-14163.
03
Vulnerability in vllm
MEDIUM
A remote authenticated attacker can exploit a vulnerability in vllm to cause a denial of service. CVE coverage: CVE-2026-44223.
04
Multiple vulnerabilities in Cisco Industrial Ethernet 1000 Series Switches
MEDIUM
An attacker can exploit multiple vulnerabilities in Cisco Industrial Ethernet Switches to cause a denial of service or carry out cross-site scripting attacks. CVE coverage: CVE-2026-20177, CVE-2026-20232.
05
Vulnerability in expat
MEDIUM
A local attacker can exploit a vulnerability in expat to carry out an unspecified attack. CVE coverage: CVE-2026-76957.

Executive assessment

Today's brief leads with IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path traversal.. All 5 selected findings retain their own technical scope, action, observed status, and evidence limits.

Finding 01 — IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path traversal.

What changed: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path traversal. CVE coverage: CVE-2026-17181.

Technical evidence: CVE-2026-17181; CVSS v3.1 9.3; weakness ['CWE-22']; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-17181 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-17181>)

Finding 02 — Vulnerability in Octopus Deploy Server

What changed: A remote authenticated attacker can exploit a vulnerability in Octopus Deploy Server to disclose information. CVE coverage: CVE-2026-14163.

Technical evidence: CVE-2026-14163; CVSS v4.0 7.1; weakness ['CWE-532']; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-14163 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: wid.cert-bund.de](<https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2928>)

Finding 03 — Vulnerability in vllm

What changed: A remote authenticated attacker can exploit a vulnerability in vllm to cause a denial of service. CVE coverage: CVE-2026-44223.

Technical evidence: CVE-2026-44223; CVSS v3.1 6.5; weakness ['CWE-131', 'CWE-704']; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-44223 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: wid.cert-bund.de](<https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1299>)

Finding 04 — Multiple vulnerabilities in Cisco Industrial Ethernet 1000 Series Switches

What changed: An attacker can exploit multiple vulnerabilities in Cisco Industrial Ethernet Switches to cause a denial of service or carry out cross-site scripting attacks. CVE coverage: CVE-2026-20177, CVE-2026-20232.

Technical evidence: CVE-2026-20177; CVSS v3.1 5.3; weakness ['CWE-770']; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-20177 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: wid.cert-bund.de](<https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2931>)

Finding 05 — Vulnerability in expat

What changed: A local attacker can exploit a vulnerability in expat to carry out an unspecified attack. CVE coverage: CVE-2026-76957.

Technical evidence: CVE-2026-76957; CVSS v3.1 4.9; weakness ['CWE-416']; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-76957 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: wid.cert-bund.de](<https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2930>)

cve-2026-14163cve-2026-17181cve-2026-20177cve-2026-20232cve-2026-44223cve-2026-76957cwe-131cwe-22cwe-532cwe-704

Act on this brief

Map detection coverage gaps for the techniques above, or generate Sigma rules from the named CVEs.