CVE-2026-82340
CRITICAL
NVD
CVSS Score
9.8
Severity
CRITICAL
Published
Sep 18, 2026
Vendor
unknown
Description
IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled reflective method dispatch in the Change Audit System (CAS) listener. A network attacker able to reach TCP port 16017 may submit crafted serialized messages and potentially cause unintended code execution in the Guardium appliance.