CVE-2026-84440
IBM Guardium Data Protection 12.2 is vulnerable to command injection in the SNMP alert notification functionality. An authenticated attacker who can influence policy alert text can cause attacker-controlled data to be executed as operating system commands by the SNMP alerter service, which runs with root privileges.
- Published Sep 29, 2026
- CVSS 8.8 high
- 0.7% chance of exploitation in the next 30 days (EPSS)
- A fix is available