Check Point, Kaspersky, Tanium Patch Product Vulnerabilities

Critical Flaws Found in Check Point, Kaspersky, and Tanium Products – What You Need to Know

A trio of major cybersecurity companies has issued patches for severe vulnerabilities in their products, raising concerns among users about potential exploitation by threat actors. Check Point, Kaspersky, and Tanium have all acknowledged critical flaws that could allow attackers to remotely execute code or gain unauthorized access to sensitive data.

At the center of the patching effort is Check Point’s Security Management and Log Server products, which contain a critical vulnerability (CVE-2026-91843) that can be exploited by an unauthenticated attacker. The flaw allows for remote execution of arbitrary code with root privileges through the login process. While there is currently no evidence of in-the-wild exploitation, Check Point has shared some potential indicators of compromise to help users detect any malicious activity.

Tanium has published five new advisories this week to inform customers about high- and medium-severity vulnerabilities affecting its Asset and Threat Response products. Two high-severity SQL injection vulnerabilities have been fixed in Tanium Asset, which can be exploited by authenticated attackers to gain read and write access to restricted data or tamper with SQL queries executed by the service. Additionally, Threat Response has received patches for two medium-severity vulnerabilities: a server-side request forgery allowing access to restricted data, and an improper access control issue that can be exploited to create or modify alerts.

Kaspersky has also issued a patch for its Security 10 for Linux Mail Server product, which is affected by a Redis vulnerability discovered in 2023. The vulnerability could potentially cause product malfunction or allow an attacker to execute code when processing files of a certain format.

These vulnerabilities highlight the ongoing cat-and-mouse game between cybersecurity companies and threat actors. While patches have been issued to address these critical flaws, users must remain vigilant and take proactive steps to secure their systems. Check Point has advised customers without automatic updates enabled to immediately patch their installations, emphasizing the importance of timely security updates in preventing potential exploitation.

In light of this latest development, it’s essential for organizations and individuals to prioritize regular software updates and ensure that all security patches are applied promptly. This includes enabling automatic updates whenever possible and conducting thorough vulnerability assessments to identify any potential weaknesses. By staying informed and taking proactive measures, users can minimize their exposure to these critical flaws and maintain a robust cybersecurity posture.


Source: SecurityWeek — 2026-09-18