Check Point, Kaspersky, Tanium Patch Product Vulnerabilities
Vulnerability: Check Point, Kaspersky, and Tanium patch critical vulnerabilities, including RCE and SQL injection flaws.
Deep Analysis and Expert Commentary
The vulnerabilities disclosed by these vendors highlight significant risks across enterprise security products. Check Point's CVE-2026-91843 is particularly severe due to its unauthenticated RCE capability, which could grant attackers root access. Tanium's SQL injection flaws in Tanium Asset and Threat Response could lead to data tampering or unauthorized access, while Kaspersky's Redis vulnerability in its Linux Mail Server product risks code execution. Mitigation involves immediate patching, monitoring for IoCs, and restricting access to vulnerable systems. Organizations should prioritize updating these products to prevent exploitation, especially given the increasing focus on Check Point vulnerabilities by threat actors.
Action Items
- Patch Check Point Security Management and Log Server products immediately.
- Update Tanium Asset and Threat Response to address SQL injection and access control flaws.
- Apply Kaspersky's fix for the Redis vulnerability in Security 10 for Linux Mail Server.
Original Article Brief Intro
SecurityWeek · 2026-09-18 · Vulnerability: Check Point, Kaspersky, and Tanium patch critical vulnerabilities, including RCE and SQL injection flaws.
Related Terms and Notes
CVE IDs
- CVE-2026-91843 — Critical flaw in Check Point products allowing unauthenticated RCE with root privileges.
Techniques / TTPs
- RCE
- SQL Injection
Context Notes
- Check Point
- Kaspersky
- Patch Management
- Remote Code Execution — An attack where an attacker executes arbitrary code on a target system.
- Tanium