PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-87035 Tanium CVE debrief

CVE-2026-87035 is an information disclosure vulnerability in Tanium's Comply product, addressed by the vendor. The CVE record was published on 2026-09-09T03:17:26.027Z and was last modified on 2026-09-16T15:24:07.843Z. The NVD entry is currently Analyzed. This vulnerability affects Tanium Comply versions 2.37.0 to 2.37.308, and defenders should assess exposure and prioritize remediation. The vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. The affected product is a critical component for compliance and security management within the Tanium ecosystem. Defenders should verify potential information disclosure and assess exposure for Tanium Comply versions 2.37.0 to 2.37

Vendor
Tanium
Product
Comply
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-09
Original CVE updated
2026-09-16
Advisory published
2026-09-09
Advisory updated
2026-09-16

Who should care

Defenders responsible for Tanium Comply deployments should assess exposure and prioritize remediation. This includes operators, platform administrators, vulnerability management teams, and security teams who manage or are impacted by Tanium Comply versions 2.37.0 to 2.37.308. These stakeholders should verify potential information disclosure, assess exposure, and prioritize remediation to mitigate the risk of this MED

Why it matters

CVE-2026-87035 is a medium-severity information disclosure vulnerability in Tanium Comply. Defenders should verify exposure, prioritize remediation, and monitor for potential information disclosure. The vulnerability affects Tanium Comply versions 2.37.0 to 2.37.308.

  • Verify potential information disclosure
  • Assess exposure for Tanium Comply versions 2.37.0 to 2.37.308
  • Prioritize remediation for affected deployments

Technical summary

The vulnerability, CVE-2026-87035, is an information disclosure issue in Tanium's Comply product. It has a CVSS score of 4.3 and a severity of MEDIUM. The affected versions are 2.37.0 to 2.37.308. This issue was addressed by the vendor, and defenders should prioritize verifying exposure and remediation for Tanium Comply versions 2.37.0 to 2.37.308. The vulnerability could potentially lead to unauthorized access to sensitive information, emphasizing the need for prompt assessment and remediation.

Defensive priority

Defenders should prioritize verifying exposure and remediation for Tanium Comply versions 2.37.0 to 2.37.308.

Recommended defensive actions

  • Verify Tanium Comply version and check for exposure
  • Review and apply vendor remediation
  • Monitor for potential information disclosure

Evidence notes

The CVE record and NVD detail page provide official information about the vulnerability. The vendor advisory from Tanium's security page offers additional context.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-87035 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-87035

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-87035 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87035

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://security.tanium.com/TAN-2026-032

    3938794e-25f5-4123-a1ba-5cbd7f104512 - Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.