ZeroHour

Vulnerabilities

21 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-87084
+1 in the same advisory: …87088
Server-Side Request Forgery (SSRF) in Tanium Enforce

Tanium has addressed a server-side request forgery (SSRF, CWE-918) vulnerability in its Enforce product, in which the server can be induced to issue requests to attacker-chosen destinations. Per the CVSS vector, exploitation requires low-privileged (authenticated) access over the network and no user interaction, and the changed scope (S:C) indicates a forged request can cross a trust boundary to reach other internal systems or services. An attacker gains a high degree of confidentiality impact — typically the ability to probe or retrieve data from internal networks, cloud metadata endpoints, or otherwise inaccessible services — with no integrity or availability impact indicated. Any organization operating a Tanium Enforce deployment is affected, particularly where untrusted or low-trust users can authenticate to the product's interface or API. There is no known public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at a low 0.2%, so exploitation is not currently observed.

Do: Update Tanium Enforce to the patched release identified in Tanium's advisory, since the affected/fixed version numbers are not included in this data. Limit which low-privileged users can authenticate to Enforce and review outbound network access from the Enforce server (e.g., egress rules and access to internal services or cloud metadata endpoints) to reduce SSRF blast radius. No public PoC or in-the-wild exploitation is known, so patching at the next normal maintenance window is a reasonable cadence for most defenders.

7.7
group max
<1%
  • Tanium Enforce
moderatelikely on the order of 1,000–10,000 Enforce server deployments (exact counts not published)
CVE-2026-87023
Authenticated Path Traversal in Tanium Comply Allows Sensitive File Reads

Tanium addressed a path traversal vulnerability (CWE-22) in its Comply compliance-assessment module, rated 8.5 (High) with the vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L. Per that vector, an attacker with low-privileged credentials can reach the flaw over the network with no user interaction, sending crafted input containing directory-traversal sequences that escape the intended file path when processed by Comply. The high confidentiality score and changed scope indicate the attacker can read sensitive files beyond the vulnerable component's normal boundary, with no direct integrity impact and only low availability impact. Any organization running the Tanium platform with the Comply module deployed is affected. There is no evidence of active exploitation: the flaw is not on CISA's KEV list and no public proof-of-concept is known.

Do: Upgrade Tanium Comply to the patched release through the Tanium console, and check Tanium's advisory or release notes for the specific fixed version since none is listed in this data. Restrict which accounts can reach the Comply module and review the Comply server for sensitive files (configuration, keys, credentials) that an authenticated attacker could have read. Monitor Tanium channels and CISA KEV for updated guidance or evidence of exploitation.

8.5
group max
<1%
  • Tanium Comply
largelikely 100k–1M+ managed endpoints across hundreds of enterprise and government deployments running the Comply module
CVE-2026-12139
Tanium addressed an information disclosure vulnerability in Connect.

Tanium addressed an information disclosure vulnerability in Connect.

NVD description · AI analysis pending
5.5<1%
  • tanium connect
CVE-2026-11925
Tanium addressed a User Interface (UI) Misrepresentation of Critical Information vulnerability in Tanium Server.

Tanium addressed a User Interface (UI) Misrepresentation of Critical Information vulnerability in Tanium Server.

NVD description · AI analysis pending
2.7<1%
  • tanium server
CVE-2026-15053
Tanium addressed a denial of service vulnerability in Tanium Server.

Tanium addressed a denial of service vulnerability in Tanium Server.

NVD description · AI analysis pending
7.5<1%
  • tanium server