CVE-2026-81657 in IBM Guardium: deserialization flaw rated 9.8
IBM Guardium Data Protection 12.2 contains CVE-2026-81657, an insecure deserialization vulnerability rated 9.8 that is reachable without authentication on TCP port 16017. IBM has released a patch; ZoomEye found 2,395 Guardium-titled assets, and no exploitation in the wild has been confirmed.
- CVE-2026-81657: insecure deserialization in IBM Guardium Data Protection 12.2, CVSS 9.8
- Flaw reachable without authentication via TCP port 16017
- ZoomEye found 2,395 Guardium-titled assets worldwide
- IBM released a fix; no exploitation in the wild confirmed
Read next
Security