Skip to content

Check Point, Kaspersky, Tanium Patch Product Vulnerabilities

Check Point Security Management and Log Servers are affected by a critical vulnerability that can allow remote code execution with root privileges. The post Check Point, Kaspersky, Tanium Patch Product Vulnerabilities appeared first on SecurityWeek.

Cybersecurity firms Check Point, Kaspersky, and Tanium have each patched severe vulnerabilities in their products, including ones that can be exploited for remote code execution. 

Check Point has informed customers about a critical vulnerability affecting Security Management and Log Server products.

The flaw, CVE-2026-91843, can be exploited by an unauthenticated attacker “to remotely execute arbitrary code with root privileges through the login process.”

Source: https://www.securityweek.com/check-point-kaspersky-tanium-patch-product-vulnerabilities/

Related breach coverage

  • Check Point Fixes Critical CVE-2026-91843 Allowing Root Code Execution
    2026-09-18

    Check Point fixed CVE-2026-91843, a critical flaw that could let attackers run code as root on Security Management and Log Servers with no login needed. Check Point addressed CVE-2026-91843 (CVSS score of 9.8), a critical vulnerability in its Security Management and Log Servers. The flaw could let an attacker with no account run code as […]

  • Critical Orkes Conductor Vulnerability Exploited in Attacks
    2026-09-18

    CVE-2026-58138 is an unauthenticated remote code execution vulnerability that attackers can exploit via inline workflow definitions. The post Critical Orkes Conductor Vulnerability Exploited in Attacks appeared first on SecurityWeek.

  • AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code
    2026-09-18

    Hacktron researchers earned a bug bounty after demonstrating access to OpenAI employee accounts.  The post AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code appeared first on SecurityWeek.

  • 23 Million User Records Compromised in Gyazo Data Breach 
    2026-09-18

    Gyazo maker Helpfeel said the attacker exploited a vulnerability in its image upload server to gain unauthorized access. The post 23 Million User Records Compromised in Gyazo Data Breach  appeared first on SecurityWeek.