CHECK Point, Kaspersky and Tanium have patched serious vulnerabilities in their security products, including flaws that could enable remote code execution. Check Point’s critical vulnerability, CVE-2026-91843, affects its Security Management and Log Server products. An unauthenticated attacker could exploit the login process to execute arbitrary code with root privileges.
Check Point said there is no evidence that this vulnerability has been exploited in the wild, although it has provided potential indicators of compromise. Customers without automatic updates enabled have been advised to install the security update immediately.
Tanium issued five advisories covering high- and medium-severity issues. Tanium Asset received fixes for two high-severity SQL injection vulnerabilities that authenticated attackers could use to read or alter restricted data, or tamper with SQL queries run by the service. Threat Response was also patched against SQL query tampering, server-side request forgery that could expose restricted data, and an improper access-control flaw that could allow attackers to create or modify alerts.
Separately, Kaspersky said on 17 September that Kaspersky Security 10 for Linux Mail Server is affected by a Redis vulnerability discovered in 2023. The company said the issue could potentially cause product malfunction or allow code execution when processing files in a particular format.