PatchSiren cyber security CVE debrief
CVE-2026-87035 Tanium CVE debrief
CVE-2026-87035 is an information disclosure vulnerability in Tanium's Comply product, addressed by the vendor. The CVE record was published on 2026-09-09T03:17:26.027Z and was last modified on 2026-09-16T15:24:07.843Z. The NVD entry is currently Analyzed. This vulnerability affects Tanium Comply versions 2.37.0 to 2.37.308, and defenders should assess exposure and prioritize remediation. The vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. The affected product is a critical component for compliance and security management within the Tanium ecosystem. Defenders should verify potential information disclosure and assess exposure for Tanium Comply versions 2.37.0 to 2.37
- Vendor
- Tanium
- Product
- Comply
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-09
- Original CVE updated
- 2026-09-16
- Advisory published
- 2026-09-09
- Advisory updated
- 2026-09-16
Who should care
Defenders responsible for Tanium Comply deployments should assess exposure and prioritize remediation. This includes operators, platform administrators, vulnerability management teams, and security teams who manage or are impacted by Tanium Comply versions 2.37.0 to 2.37.308. These stakeholders should verify potential information disclosure, assess exposure, and prioritize remediation to mitigate the risk of this MED
Why it matters
CVE-2026-87035 is a medium-severity information disclosure vulnerability in Tanium Comply. Defenders should verify exposure, prioritize remediation, and monitor for potential information disclosure. The vulnerability affects Tanium Comply versions 2.37.0 to 2.37.308.
- Verify potential information disclosure
- Assess exposure for Tanium Comply versions 2.37.0 to 2.37.308
- Prioritize remediation for affected deployments
Technical summary
The vulnerability, CVE-2026-87035, is an information disclosure issue in Tanium's Comply product. It has a CVSS score of 4.3 and a severity of MEDIUM. The affected versions are 2.37.0 to 2.37.308. This issue was addressed by the vendor, and defenders should prioritize verifying exposure and remediation for Tanium Comply versions 2.37.0 to 2.37.308. The vulnerability could potentially lead to unauthorized access to sensitive information, emphasizing the need for prompt assessment and remediation.
Defensive priority
Defenders should prioritize verifying exposure and remediation for Tanium Comply versions 2.37.0 to 2.37.308.
Recommended defensive actions
- Verify Tanium Comply version and check for exposure
- Review and apply vendor remediation
- Monitor for potential information disclosure
Evidence notes
The CVE record and NVD detail page provide official information about the vulnerability. The vendor advisory from Tanium's security page offers additional context.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-87035 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-87035
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-87035 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87035
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://security.tanium.com/TAN-2026-032
3938794e-25f5-4123-a1ba-5cbd7f104512 - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.