Critical Vulnerabilities in Check Point, Kaspersky, and Tanium Patch Products

www.news4hackers.com-critical-vulnerabilities-in-check-point-kaspersky-and-tanium-patch-products-critical-vulnerabilities-in-check-point-kaspersky-and-tanium-patch-products

Check Point, Kaspersky, and Tanium have addressed critical flaws in their software solutions, including vulnerabilities that could enable remote code execution.

Check Point Vulnerabilities

Check Point’s Security Management and Log Server systems were found to have a flaw designated CVE-2026-91843. This vulnerability allows an unauthenticated attacker to execute arbitrary code with elevated privileges during the login process. While no evidence of active exploitation has been confirmed, the vendor has released indicators of compromise to help identify potential breaches. Users without automatic update mechanisms are urged to apply patches immediately.

CVE-2026-91843 Details

This flaw enables an unauthenticated attacker to execute arbitrary code with elevated privileges during the login process. The vendor has provided indicators of compromise to assist in detecting potential breaches.

Kaspersky Vulnerabilities

Kaspersky issued a security advisory on September 17 highlighting a Redis-related vulnerability impacting Kaspersky Security 10 for Linux Mail Server. Discovered in 2023, the flaw could lead to system instability or arbitrary code execution when processing specific file formats. The vendor emphasized the potential for attackers to exploit this weakness to compromise affected systems.

Redis-Related Flaw

The Redis-related vulnerability (unspecified CVE) could allow attackers to cause system instability or execute arbitrary code when processing specific file formats. The flaw was discovered in 2023 but remains a critical risk for affected systems.

Tanium Security Advisories

Tanium disclosed five security advisories this week, detailing high- and medium-severity issues across its product line. In Tanium Asset, two critical SQL injection vulnerabilities were resolved, which could have permitted authenticated attackers to access restricted data or manipulate database queries. A separate SQL query tampering flaw was also addressed in Threat Response. Additional updates included fixes for two medium-severity issues: a server-side request forgery vulnerability that could expose sensitive information and an improper access control flaw enabling unauthorized alert modifications.

SQL Injection and Tampering Issues

Tanium Asset resolved two critical SQL injection vulnerabilities, while Threat Response addressed a separate SQL query tampering flaw. These issues could have allowed authenticated attackers to access restricted data or manipulate database queries.

Medium-Severity Fixes

Tanium also resolved a server-side request forgery vulnerability and an improper access control flaw. The former could expose sensitive information, while the latter allowed unauthorized alert modifications.

The disclosures follow a broader trend of threat actors targeting software supply chains and enterprise infrastructure. Cybersecurity professionals are advised to review patch management protocols and monitor for signs of exploitation linked to the identified vulnerabilities. Organizations are encouraged to implement proactive mitigation strategies to reduce exposure to these risks.



About Author

en_USEnglish