CVE-2026-82340: IBM Guardium Data Protection

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled reflective method dispatch in the Change Audit System (CAS) listener. A network attacker able to reach TCP port 16017 may submit crafted serialized messages and potentially cause unintended code execution in the Guardium appliance.

Affected products

  • IBM Guardium Data Protection: version 12.2 only

Published 2026-09-18. Last modified 2026-10-06.