A total of five security flaws threaten IBM's Db2 database system. In the worst case, attackers can execute malicious code or view unencrypted passwords. According to IBM, there are no signs of attacks in the wild yet, but you should still apply the available updates promptly.
The most important vulnerabilities
The most dangerous is a flaw rated high (CVE-2026-10534) that affects the import of IXF files. According to the brief description, it causes memory errors that can let malicious code onto a system. Also rated high is CVE-2026-10543, which lets attackers gain elevated user privileges through an unspecified path, typically a useful starting point for further attacks.
The remaining three flaws are less critical but not harmless. CVE-2026-18097 (medium) makes unauthorized access to plain-text passwords conceivable. CVE-2026-16480 (medium) allows authorization checks to be bypassed. And CVE-2026-18096 (low) enables denial-of-service attacks.
These versions contain the fix
IBM says it has repaired the database system in several versions. The fixes are included in Db2 V11.5.9 (Security Update #87984), Db2 V12.1.4 (Security Update #86025), and Db2 V12.1.5 (Security Update #88454). Administrators can find details in IBM's corresponding advisories. Just recently, the vendor closed several security flaws in its App Connect Enterprise middleware platform.