Skip to content
Tanium Joins Common Vulnerabilities and Exposures (CVE™) Program as a CVE ...

Tanium Joins Common Vulnerabilities and Exposures (CVE™) Program as a CVE ...

Morningstar November 13, 2025

Tanium Joins Common Vulnerabilities and Exposures (CVE™) Program as a CVE Numbering Authority

CNA authorization demonstrates company’s mature vulnerability management practices and commitment to transparency

Tanium, a leader in Autonomous Endpoint Management (AEM), announced today it has been authorized by the CVE Program as a CVE Numbering Authority (CNA ). As a CNA, Tanium will publicly document and disclose vulnerabilities, along with the applicable fixed version and remediation steps, in Tanium’s Software-as-a-Service (SaaS) and on-premises offerings.

“Tanium is reaffirming our long-standing commitment to security and transparency – in our product, to our customers and to the larger security industry. Tanium has consistently and responsibly disclosed vulnerabilities to its customers since 2017, and becoming a CNA marks the step in our journey toward greater transparency and maturity in our proactive vulnerability management and responsible disclosure program,” said Loic Simon, vice president, security at Tanium. “The CVE Program’s vulnerability identification capability is fundamental to global vulnerability management, and we’re honored to now play a role in furthering threat information sharing around the world.”

The CVE Program is a community-driven effort to identify, define, catalog and information publicly disclosed cybersecurity vulnerabilities. As a CNA, Tanium will issue CVE Identifiers (CVE ID) and corresponding CVE Records, which will enable discussion and information sharing amongst the security community. By actively contributing to the CVE Program, Tanium provides value-added vulnerability information publicly, fostering trust and resilience in its customers and across the security landscape.

Tanium’s authorization as a CNA builds on the company’s high security standards which comply with various certifications and authorizations frameworks, including ISO 27001, ISO 27017, SOC2, FedRAMP and GovRAMP, in addition to other certifications listed on Tanium’s Trust Center.

For more information Tanium’s secure by design principles, visit:

The information described herein is for general informational purposes only. This information is not a commitment, warranty, offer, promise, or legal obligation for us to deliver any future products, features, or functionality, and is not intended to be, and shall not be deemed to be, incorporated into any contract. The actual timing of any product, feature, or functionality that is ultimately made available may be different from what is described.

Media Tanium PR Press@tanium.com

View source version on businesswire.com:

The articles, information, and content displayed on this webpage may include materials prepared and provided by third parties. Such third-party content is offered for informational purposes only and is not endorsed, reviewed, or verified by Morningstar.

Morningstar makes no representations or warranties regarding the accuracy, completeness, timeliness, or reliability of any third-party content displayed on this site. The views and opinions expressed in third-party content are those of the respective authors and do not necessarily reflect the views of Morningstar, its affiliates, or employees.

Morningstar is not responsible for any errors, omissions, or delays in this content, nor for any actions taken in reliance thereon. Users are advised to exercise their own judgment and seek independent financial advice before making any decisions based on such content. The third-party providers of this content are not affiliated with Morningstar, and their inclusion on this site does not imply any form of partnership, agency, or endorsement.

Extracted Entities

Domains (1)