Cyber & AI intelligence
Wasteland.
Briefs indexed3091
Issues31
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-75875 2026-10-08

IBM Guardium Data Protection Path Traversal Flaw Enables Remote Code Execution (CVE-2026-75875)

"IBM has disclosed CVE-2026-75875, a critical path traversal vulnerability (CVSS 9.8) in IBM Guardium Data Protection 12.0, 12.1, and 12.2 that could let a remote attacker execute arbitrary code."

IBM has disclosed CVE-2026-75875, a critical path traversal vulnerability (CVSS 9.8) in IBM Guardium Data Protection 12.0, 12.1, and 12.2 that could let a remote attacker execute arbitrary code.

What Is It

CVE-2026-75875 is a path traversal weakness, classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory). According to the NVD record, IBM Guardium Data Protection "could allow a remote attacker to execute arbitrary code due to path traversal."

IBM's PSIRT ([email protected]) reported the CVE. NVD published it on 2026-10-08, and its status is currently "Received," which means NVD has not yet completed its own analysis.

Why It Matters

IBM gave the flaw a CVSS v3.1 base score of 9.8 (Critical) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. That vector means:

The exploitability subscore is 3.9 and the impact subscore is 5.9. An unauthenticated attacker who can reach the service over the network may be able to fully compromise an affected system.

Exploitation status: The supplied CISA KEV data has no entry for this CVE. As of this writing, KEV does not confirm active exploitation. Watch the KEV catalog for updates.

What's Vulnerable

The affected product is IBM Guardium Data Protection, in these versions:

Version Status
12.0 (12.0.0) Affected
12.1 (12.1.0) Affected
12.2 (12.2.0) Affected

Associated CPEs: - cpe:2.3:a:ibm:guardium_data_protection:12.0:*:*:*:*:*:*:* - cpe:2.3:a:ibm:guardium_data_protection:12.1:*:*:*:*:*:*:* - cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*

Patch Status

The NVD record links to an IBM support advisory (node 7291674) but does not include fixed versions or patch details. Because there is no KEV entry, CISA has not set a required action or a remediation due date.

Organizations running Guardium Data Protection 12.0, 12.1, or 12.2 should:

Sources