ZeroHour

Search: “tanium”

57 stories

Check Point, Kaspersky, Tanium Patch Product Vulnerabilities

Check Point fixes critical unauthenticated RCE CVE-2026-91843 in Security Management; Tanium and Kaspersky also patch product vulnerabilities.

Check Point patched CVE-2026-91843, a critical flaw in Security Management and Log Server that lets unauthenticated attackers remotely execute arbitrary code with root privileges via the login process; the vendor found no evidence of in-the-wild exploitation but shared potential IoCs. Tanium issued five advisories fixing two high-severity SQL injection vulnerabilities in Tanium Asset plus SQL tampering, SSRF, and access control issues in Threat Response. Kaspersky addressed a 2023 Redis vulnerability in Kaspersky Security 10 for Linux Mail Server that could cause malfunction or code execution when processing certain files.

SecurityWeekupdated · 4h agofirst · 6h agoVulnerability 10 sourcesCVE-2026-91843

Critical Orkes Conductor Vulnerability Exploited in Attacks

Attackers actively exploit CVE-2026-58138 (CVSS 9.8), an unauthenticated RCE in Orkes Conductor via malicious JavaScript or Python expressions in inline workflows.

CVE-2026-58138 lets unauthenticated attackers submit workflow definitions containing hostile INLINE, LAMBDA, DO_WHILE, or SWITCH tasks; the GraalVM evaluator runs with HostAccess.ALL, disabling the sandbox so attacker code reflects into Java and executes OS commands, often as root. The flaw was patched in Conductor 3.30.2 in June, PoC code appeared in early August, and Empirical Security identified in-the-wild attacks on August 21. Fortinet blocked roughly 1,300 exploitation attempts between September 8 and 9 and issued an outbreak alert on the ongoing exploitation.

SecurityWeek · 5h agoExploit / PoC in the wildCVE-2026-58138