IBM disclosed CVE-2026-10543, a high-severity privilege-escalation vulnerability in IBM Db2 that can be triggered with a specially crafted query. The flaw is classified as CWE-285 Improper Authorization and carries a CVSS v3.1 score of 8.2 with vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N, indicating low-complexity, network-exploitable abuse with no user interaction required and a high integrity impact.
The issue affects IBM Db2 Server versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 on all platforms. IBM said interim security updates are available through Fix Central for supported release levels, while noting that no workarounds or mitigations are available. The company withheld detailed exploitation guidance to reduce attacker enablement and credited Nicolas Verdier of Amazon with reporting the vulnerability.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
The CVE record states that CVE-2026-10543 was newly received by psirt@us.ibm.com. The entry describes an IBM Db2 privilege-escalation vulnerability associated with CWE-285.
IBM disclosed CVE-2026-10543, a privilege-escalation flaw in Db2 triggered by a specially crafted query, affecting Db2 Server 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 on all platforms. IBM said no workarounds are available and released interim security updates through Fix Central for supported release levels.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourceibm.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.