IBM Guardium Data Protection is affected by 18 reported vulnerabilities, including 10 rated critical, seven high and one medium. The highest-rated issues have CVSS v3 scores of 9.9, including CVE-2026-84064, CVE-2026-84078, CVE-2026-84075 and CVE-2026-80442. The flaws affect version 12.2 and involve core data-protection components, load balancers and administrative web interfaces. No exploitation in the wild or public proof-of-concept code has been confirmed.
The reported weaknesses include insecure deserialisation in the Change Audit System listener. An unauthenticated attacker able to reach TCP port 16017 could send crafted serialised messages and potentially achieve code execution, according to the advisory quoted by the report.
Other issues include command injection in the certificate export command-line tool, SQL injection affecting web endpoints such as the Load Balancer Servlet and New Query Builder REST Processor, missing authentication checks, and hardcoded credentials that could expose internal database access. The report says these flaws could allow attackers to access or alter protected data and, in some cases, obtain root-level control.
IBM has issued a cumulative fix pack through Fix Central and recommends that customers update promptly. Administrators should consult IBM’s security advisory and apply the official update. Where immediate patching is not possible, restricting network access, particularly to TCP port 16017, is suggested as a temporary measure; the report notes that this does not replace updating the appliance.