Organisations urged to patch IBM Guardium 12.0-12.2 after critical unauthenticated RCE flaw exposed
A critical path traversal flaw in IBM Guardium versions 12.0 to 12.2 allows remote attackers to execute arbitrary code without credentials.

Key points
- CVE-2026-75875 carries a CVSS score of 9.8, classified as critical.
- The vulnerability stems from improper handling of path traversal inputs.
- IBM Guardium Data Protection versions 12.0, 12.1, and 12.2 are affected.
Organisations relying on IBM Guardium Data Protection for security monitoring face an immediate and severe risk. A newly disclosed vulnerability allows unauthenticated remote attackers to execute arbitrary code on affected systems. The flaw, identified as CVE-2026-75875, has been assigned a CVSS score of 9.8, placing it in the critical severity category.
How it unfolded
- The National Vulnerability Database (NVD) recorded CVE-2026-75875, citing CWE-22 (Improper Limitation of a Pathname to a Restricted Directory) as the underlying weakness.
- The entry specifies that IBM Guardium Data Protection versions 12.0, 12.1, and 12.2 are susceptible to this path traversal issue.
- The description notes that a remote attacker can exploit this flaw to execute arbitrary code, requiring no prior authentication to the system.
Who is affected
The vulnerability impacts three specific major releases of IBM Guardium Data Protection: version 12.0, version 12.1, and version 12.2. Any organisation operating these versions exposes its infrastructure to potential remote code execution. Because the attack vector is remote and does not require login credentials, the exposure is significant for any instance accessible from untrusted networks. The nature of path traversal vulnerabilities means attackers can manipulate file paths to access or modify data outside the intended directory, leading to full system compromise in this context.
The fix
No patch, fix, or update has been confirmed yet by IBM or the National Vulnerability Database. Organisations should not assume a mitigation is available through standard update channels at this time. Until the vendor provides an update or explicit mitigation guidance, affected systems remain vulnerable to exploitation.
What to do and how to stay safe: IBM Guardium
- Audit your environment to identify any instances of IBM Guardium Data Protection running versions 12.0, 12.1, or 12.2.
- Restrict network access to these systems to trusted internal networks only, reducing the attack surface for remote exploitation.
- Monitor logs for unusual file access patterns or unexpected process executions that may indicate an active path traversal attempt.
- Once the vendor provides an update, apply it immediately to remediate the vulnerability.
Step-by-step guide: Patch Management: Eight Questions Answered for Stability
General security guidance from the Malware Brief newsroom. It is not confirmed advice from the organisations named in this story.
Frequently asked questions
What is the CVSS score for CVE-2026-75875?
The CVSS score is 9.8, which is classified as critical.
Which versions of IBM Guardium are affected?
IBM Guardium Data Protection versions 12.0, 12.1, and 12.2 are affected.
Is a patch available for this vulnerability?
No, no fix has been confirmed yet.



