CVE-2026-81657: IBM Guardium Data Protection is affected by multiple vulnerabilities.
Published Sep 17, 2026
·Updated
IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
Affected Software
3 affected components
IBM Guardium Data Protection=12.2
IBM Guardium Data Protection<=12.2
IBM Guardium Data Protection<=12.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Guardium Data Protectionto a version that resolves this vulnerability.Patch SqlGuard_12.0p233_FixPack
Event History
Sep 17, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Sep 18, 2026
CVE Published
via MITRE·07:27 PM
Data Sourced
via MITRE·07:27 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Who can exploit this issue?
A remote, unauthenticated attacker could exploit the issue. The available information does not state any additional access requirements or network exposure conditions.
2
What is the potential impact of successful exploitation?
Successful exploitation could allow an attacker to execute arbitrary code on the affected system.
3
What vulnerability mechanism is involved?
The issue is caused by deserialization of untrusted data.