Skip to main content

Check Point, Kaspersky, Tanium Patch Product Vulnerabilities

0
Critical
Vulnerabilityremoterce
Published: 09/18/2026 (09/18/2026, 07:14:04 UTC)
Source: SecurityWeek

Description

A critical vulnerability (CVE-2026-91843) affects Check Point Security Management and Log Server products, allowing unauthenticated remote code execution with root privileges via the login process. No evidence of active exploitation in the wild has been reported. Check Point has issued patches and advises immediate updates for systems without automatic patching. Additionally, Tanium and Kaspersky have patched multiple vulnerabilities in their products, including SQL injection and code execution flaws. These vulnerabilities pose significant risks if left unpatched.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/18/2026, 07:16:43 UTC

Technical Analysis

Check Point Security Management and Log Server products contain a critical vulnerability (CVE-2026-91843) that enables unauthenticated attackers to remotely execute arbitrary code with root privileges during the login process. Although no in-the-wild exploitation has been observed, Check Point has provided indicators of compromise and urges customers to patch immediately if automatic updates are disabled. Tanium addressed five vulnerabilities, including two high-severity SQL injection flaws in Tanium Asset and Threat Response, and two medium-severity issues involving server-side request forgery and improper access control. Kaspersky patched a Redis vulnerability in Kaspersky Security 10 for Linux Mail Server that could cause product malfunction or code execution when processing certain file formats.

Potential Impact

Successful exploitation of the Check Point vulnerability could allow attackers to gain root-level remote code execution on affected systems, potentially compromising the entire environment. Tanium's SQL injection vulnerabilities could allow authenticated attackers to read, modify, or tamper with restricted data and SQL queries. Kaspersky's Redis vulnerability may lead to product malfunction or remote code execution when processing specific file formats. These vulnerabilities collectively represent critical to high risks if exploited.

Mitigation Recommendations

Check Point customers should immediately apply the official patches for CVE-2026-91843, especially if automatic updates are not enabled. Tanium users must update to the patched versions addressing the SQL injection, server-side request forgery, and access control vulnerabilities. Kaspersky users should apply the update for Kaspersky Security 10 for Linux Mail Server to mitigate the Redis-related vulnerability. No evidence of active exploitation has been reported for the Check Point vulnerability, but prompt patching is strongly recommended.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.8,"severitySource":"stated","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/check-point-kaspersky-tanium-patch-product-vulnerabilities/","fetched":true,"fetchedAt":"2026-09-18T07:16:37.596Z","wordCount":1009}

Threat ID: 6aace55555bf5e2cf5a84527

Added to database: 09/18/2026, 07:16:37 UTC

Last enriched: 09/18/2026, 07:16:43 UTC

Last updated: 09/18/2026, 08:00:33 UTC

Views: 9

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses