Cyber & AI intelligence
Wasteland.
Briefs indexed2769
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-81657 2026-09-18

CVE-2026-81657: Unauthenticated RCE in IBM Guardium Data Protection 12.2

"IBM Guardium Data Protection 12.2 contains a critical deserialization flaw (CVSS 9.8) that lets a remote, unauthenticated attacker execute arbitrary code on the affected system."

IBM Guardium Data Protection 12.2 contains a critical deserialization flaw (CVSS 9.8) that lets a remote, unauthenticated attacker execute arbitrary code on the affected system.

What Is It

CVE-2026-81657 is an unsafe deserialization of untrusted data (CWE-502) in IBM Guardium Data Protection 12.2. Per IBM's PSIRT advisory, the flaw "could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data."

The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, base score 9.8, CRITICAL. Every exploitability metric is at its worst value: network-reachable, low attack complexity, no privileges, and no user interaction required. Impact is HIGH across confidentiality, integrity, and availability, with an impact subscore of 5.9 and exploitability subscore of 3.9.

Why It Matters

A pre-authentication code execution bug needs nothing but network reach to the vulnerable service. There is no credential barrier, no victim to phish, and no timing condition to win.

Guardium Data Protection is a database activity monitoring and data security platform, which means the affected system sits in a position of trust relative to the data stores it watches. Full confidentiality, integrity, and availability impact on that system is the worst-case outcome for a security control.

As of publication, CVE-2026-81657 does not appear in CISA's Known Exploited Vulnerabilities catalog, so there is no government-confirmed report of active exploitation in the wild. Absence from KEV is not evidence the flaw is unexploitable; a 9.8 unauthenticated RCE should be treated as attractive to attackers regardless of catalog status.

What's Vulnerable

No other versions are currently listed as affected in the NVD record.

Patch Status

The CVE was published 2026-09-18 and its NVD status is Received, meaning the record has not yet completed NVD analysis. The only reference currently attached to the record is IBM's support advisory (node 7288040), which is the authoritative source for fix availability and remediation steps. Because the CVE is not in the KEV catalog, no federal required-action deadline applies. Consult the IBM advisory directly for patch and mitigation guidance.

Sources