CVE-2026-81657
published 2026-09-18CVE-2026-81657: IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted…
PriorityP268critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.85%
56.4th percentile
IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | guardium_data_protection | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM Guardium Data Protection 12.2 deserialization
vuldb·2026-09-18·CVSS 9.8
CVE-2026-81657 [CRITICAL] IBM Guardium Data Protection 12.2 deserialization
A vulnerability labeled as very critical has been found in IBM Guardium Data Protection 12.2. This impacts an unknown function. Executing a manipulation can lead to deserialization.
This vulnerability is handled as CVE-2026-81657. The attack can be executed remotely. There is not any exploit available.
GHSA
IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
ghsa_unreviewed·2026-09-18
CVE-2026-81657 [CRITICAL] CWE-502 IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-18
Published