Version 12.2 of IBM Guardium Data Protection carries the critical CVE-2026-84436 flaw scoring 9.1 on CVSS. Command injection in the certificate export CLI lets a privileged user execute commands as root.

The flaw allows root-level command execution.
This setup lets an authenticated CLI user who holds privileges run any commands desired under root access.
Tap a lens to see what this story means for you.
Liked this? The Brief brings you the whole day in tech, verified, every morning.
Two minutes, free forever. What's in The Brief →
See what’s happening right now
The Feed runs all day — short, verified briefs the moment they break.
Open the FeedFollow @thecircuitry_
Every story we publish, as it happens. No noise between.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
NVD published two more high-severity CVE records for IBM Guardium Data Protection 12.2 on September 25: CVE-2026-85542 (CVSS 8.8), a command injection bug, and CVE-2026-85029 (CVSS 7.5), a path traversal flaw. IBM lists fix pack SqlGuard_12.0p233.
IBM disclosed CVE-2026-16841, a high-severity stack buffer overflow in AIX 7.2, 7.3 and PowerVM VIOS 4.1 that could allow remote arbitrary code execution with a CVSS score of 8.8. The flaw, published August 19 2026, requires prompt patching on affected enterprise Unix and virtualization platforms. Direct NVD page not yet surfaced in searches; support page referenced in related IBM AIX CVE reports.
CVE-2026-100841 affects every release of the MONAI medical imaging AI framework through 1.6.0. A local user who can write to a shared cache directory can plant a malicious pickle file that runs code in another user's pipeline. It is rated high severity and no stable fix has shipped.
CVE-2026-100740 is an out-of-bounds write in the L2TP code of the D-Link DIR-895L router on firmware A1_102b07. It can be triggered remotely, scores 8.6 (high), and an exploit is public.
Microsoft Office Outlook has an integer overflow flaw, CVE-2026-100208, that could let an unauthorized attacker run code over a network. Microsoft scores it 7.5 (High), and an attack needs user interaction.