ZeroHour
Product

Kaspersky Security 10 for Linux Mail Server

1 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

Check Point, Kaspersky, Tanium Patch Product Vulnerabilities

Check Point fixes critical unauthenticated RCE CVE-2026-91843 in Security Management; Tanium and Kaspersky also patch product vulnerabilities.

Check Point patched CVE-2026-91843, a critical flaw in Security Management and Log Server that lets unauthenticated attackers remotely execute arbitrary code with root privileges via the login process; the vendor found no evidence of in-the-wild exploitation but shared potential IoCs. Tanium issued five advisories fixing two high-severity SQL injection vulnerabilities in Tanium Asset plus SQL tampering, SSRF, and access control issues in Threat Response. Kaspersky addressed a 2023 Redis vulnerability in Kaspersky Security 10 for Linux Mail Server that could cause malfunction or code execution when processing certain files.

SecurityWeekupdated · 4h agofirst · 6h agoVulnerability 10 sourcesCVE-2026-91843

Related CVEs

  • Unauthenticated stack overflow gives root RCE in Check Point login process
    CVE-2026-91843 is a stack-based buffer overflow (CWE-121) in the unauthenticated login process of a Check Point product, as Check Point Software ([email protected]) is the assigning CNA and its CVE scope covers Check Point products. An attacker can trigger the flaw remotely by sending crafted input to the login interface before authenticating, with no user interaction or credentials required. Successful exploitation allows arbitrary code execution with root privileges, the highest level of control on the affected system. The vulnerability is rated 9.8 Critical (AV:N/AC:L/PR:N/UI:N, all impacts high), reflecting trivial network exploitability. No public proof-of-concept or confirmed in-the-wild exploitation is known at this time, and the source data does not name the specific product line or affected version ranges.
    · Check Point

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.