Skip to content
Critical Vulnerabilities Patched in Check Point, Kaspersky, and Tanium Products

Critical Vulnerabilities Patched in Check Point, Kaspersky, and Tanium Products

First seen 18 Sep 2026, 16:55 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 18, 2026 at 18:54 UTC

Check Point, Kaspersky, and Tanium have released patches for severe vulnerabilities in their products. Check Point's CVE-2026-91843 allows unauthenticated remote code execution through the login process, affecting Security Management and Log Server products. Although there is no evidence of in-the-wild exploitation, Check Point has shared potential indicators of compromise (IoCs) and advised customers to patch immediately. Tanium addressed two high-severity SQL injection vulnerabilities in its Asset product and other vulnerabilities in Threat Response. Kaspersky's advisory highlights a Redis vulnerability in Kaspersky Security 10 for Linux Mail Server that could lead to product malfunction or code execution. The vulnerabilities were disclosed on September 16 and 17, 2026, with proof-of-concept code for CVE-2026-91843 released on September 18, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-16
CVE-2026-91843 published
Check Point disclosed a critical vulnerability allowing remote code execution in its Security Management and Log Server products.
Securityweek
2026-09-17
Kaspersky advisory released
Kaspersky informed users of a Redis vulnerability affecting Kaspersky Security 10 for Linux Mail Server.
Securityweek
2026-09-18
Proof-of-concept code released
A public proof-of-concept for CVE-2026-91843 was made available, increasing urgency for patching.
Securityweek

More articles in this cluster (3)

Following this threat?

Track Chosen Brick, Check Point and CVE-2018-25032 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed