PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-87088 Tanium CVE debrief

CVE-2026-87088 is a HIGH severity vulnerability in Tanium Enforce, with a CVSS score of 7. The vulnerability addresses an unauthorized code execution issue. Tanium has provided an advisory (TAN-2026-022) addressing this issue. The CVE was published on 2026-09-09 and last modified on 2026-09-16. Defenders responsible for Tanium Enforce installations should assess exposure and prioritize patching, especially for versions 2.9.0 to 2.9.718, 2.10.0 to 2.10.760, and 3.0.0 to 3.0.346. Verification and patching are crucial to prevent potential code execution. The CVSS vector is AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H, and the weakness is CWE-78. The vulnerability requires verification and has

Vendor
Tanium
Product
Enforce
CVSS
HIGH 7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-09
Original CVE updated
2026-09-16
Advisory published
2026-09-09
Advisory updated
2026-09-16

Who should care

Defenders responsible for Tanium Enforce installations, especially those using versions 2.9.0 to 2.9.718, 2.10.0 to 2.10.760, and 3.0.0 to 3.0.346, should assess exposure and prioritize patching.

Why it matters

CVE-2026-87088 is a HIGH severity vulnerability in Tanium Enforce that requires verification and patching to prevent potential code execution. Defenders should assess exposure, especially for specific versions, and prioritize patching.

  • Verify and apply patches for Tanium Enforce to prevent potential code execution
  • Inventory and monitor Tanium Enforce systems for unusual activity
  • Assess exposure of Tanium Enforce installations, especially for versions 2.9.0 to 2.9.718, 2.10.0 to 2.10.760, and 3.0.0 to 3.0.346

Technical summary

The vulnerability is a HIGH severity issue in Tanium Enforce, with a CVSS score of 7. It addresses an unauthorized code execution issue. The CVSS vector is AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H, and the weakness is CWE-78. The vulnerability affects Tanium Enforce versions 2.9.0 to 2.9.718, 2.10.0 to 2.10.760, and 3.0.0 to 3.0.346. Defenders should prioritize verifying and applying the vendor's patch. The CVE record and NVD entry provide details on the vulnerability. Tanium has provided an advisory (TAN-2026-022) addressing this issue.

Defensive priority

Defenders should prioritize verifying and applying the vendor's patch for Tanium Enforce, especially for versions 2.9.0 to 2.9.718, 2.10.0 to 2.10.760, and 3.0.0 to 3.0.346.

Recommended defensive actions

  • Verify and apply the vendor's patch for Tanium Enforce
  • Inventory Tanium Enforce installations to identify potentially vulnerable versions
  • Monitor Tanium Enforce systems for unusual activity

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its CVSS vector (AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H) and weakness (CWE-78).

Sources and references

Verified primary and authoritative sources

  • CVE-2026-87088 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-87088

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-87088 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87088

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://security.tanium.com/TAN-2026-022

    3938794e-25f5-4123-a1ba-5cbd7f104512 - Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.