Securityweek Critical Vulnerabilities Patched in Check Point, Kaspersky, and Tanium Products
Article Content
- •Check Point's CVE-2026-91843 allows remote code execution with root privileges.
- •Tanium fixed multiple high-severity SQL injection vulnerabilities this week.
- •Kaspersky's Redis vulnerability could lead to product malfunction or code execution.
Check Point, Kaspersky, and Tanium have released patches for severe vulnerabilities in their products. Check Point's CVE-2026-91843 allows unauthenticated remote code execution through the login process, affecting Security Management and Log Server products. Although there is no evidence of in-the-wild exploitation, Check Point has shared potential indicators of compromise (IoCs) and advised customers to patch immediately. Tanium addressed two high-severity SQL injection vulnerabilities in its Asset product and other vulnerabilities in Threat Response. Kaspersky's advisory highlights a Redis vulnerability in Kaspersky Security 10 for Linux Mail Server that could lead to product malfunction or code execution. The vulnerabilities were disclosed on September 16 and 17, 2026, with proof-of-concept code for CVE-2026-91843 released on September 18, 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Chosen Brick, Check Point and CVE-2018-25032 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Iranian State Actors Deploy CHOSEN BRICK Spyware Against Dissidents On September 15, 2026, the UK, US, and Netherlands issued a joint advisory regarding a spyware campaign attributed to Iranian state actors targeting dissidents, activists, and journalists. The malware, known as CHOSEN BRICK, is delivered through spear-phishing attacks on messaging platforms like WhatsApp and Telegram.…
Russian Frigate Fires Flares at Danish Helicopter, Escalating Tensions A Russian frigate fired two emergency flares at a Danish helicopter conducting a routine operation in the Baltic Sea on September 12, 2026. The incident prompted Denmark to summon the Russian ambassador for discussions, with Danish officials describing the actions as reckless and unacceptable. Danish Prime Minister…