PatchSiren

Tanium CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Tanium CVE published 2026-09-16

CVE-2026-87116

A server-side request forgery vulnerability was addressed by Tanium in Threat Response. The CVE record was published on 2026-09-16T20:17:38.207Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. This vulnerability has a CVSS score of 6.5 and is classified as MEDIUM severity. Defenders should assess exposure and prioritize verification and potential remediation for Tanium [truncated]

MEDIUM Tanium CVE published 2026-09-16

CVE-2026-87113

CVE-2026-87113 is a medium-severity vulnerability in Tanium's Threat Response product. The vulnerability is an improper access controls issue. Defenders should prioritize verifying exposure in their deployments and review vendor remediation guidance. The CVE record was published on 2026-09-16T20:17:38.090Z and was last modified on 2026-09-18T19:19:49.643Z. The NVD entry is currently Awaiting Analysis. Lim [truncated]

HIGH Tanium CVE published 2026-09-16

CVE-2026-87105

A CVE debrief based on the supplied source corpus. The CVE-2026-87105 vulnerability is a SQL injection issue in Tanium Threat Response. Defenders should assess exposure and potential impact. The CVE record and NVD entry provide limited information about the vulnerability, so verification and impact assessment are crucial. This debrief aims to provide an executive overview of the vulnerability, its likely [truncated]

MEDIUM Tanium CVE published 2026-09-16

CVE-2026-87076

CVE-2026-87076 is an information disclosure vulnerability in Tanium's Discover product. The vulnerability allows unauthorized access to sensitive information. Defenders should assess their exposure and review vendor remediation guidance. The CVE record was published on 2026-09-16T20:17:37.867Z. The NVD entry is currently Awaiting Analysis. The vendor has addressed the issue, but details about the nature o [truncated]

LOW Tanium CVE published 2026-09-16

CVE-2026-87026

CVE-2026-87026 is an improper access controls vulnerability in Tanium Threat Response, a product used for threat detection and response. The vulnerability has a CVSS score of 3.8 and is considered LOW severity. The CVE record was published on 2026-09-16T20:17:37.757Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. Defenders responsible for Tanium Threat Response deploym [truncated]

HIGH Tanium CVE published 2026-09-16

CVE-2026-87024

A SQL injection vulnerability was addressed by Tanium in their Asset product. The CVE record was published on 2026-09-16T20:17:37.643Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. This vulnerability has a CVSS score of 7.2 and a severity of HIGH. Defenders should assess exposure and potential impact. The vulnerability is a SQL injection issue, which can allow attacke [truncated]

HIGH Tanium CVE published 2026-09-16

CVE-2026-86865

A SQL injection vulnerability was addressed in Tanium's Asset product. The CVE record was published on 2026-09-16T20:17:37.153Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. This vulnerability has a CVSS score of 7.2 and is classified as HIGH severity. Defenders responsible for Tanium Asset deployments should assess exposure and potential impact. The vulnerability all [truncated]

HIGH Tanium CVE published 2026-09-09

CVE-2026-87088

CVE-2026-87088 is a HIGH severity vulnerability in Tanium Enforce, with a CVSS score of 7. The vulnerability addresses an unauthorized code execution issue. Tanium has provided an advisory (TAN-2026-022) addressing this issue. The CVE was published on 2026-09-09 and last modified on 2026-09-16. Defenders responsible for Tanium Enforce installations should assess exposure and prioritize patching, especiall [truncated]

HIGH Tanium CVE published 2026-09-09

CVE-2026-87075

Tanium addressed an improper access controls vulnerability in Comply. The CVE record was published on 2026-09-09T03:17:26.953Z and has not been modified since then. This vulnerability, identified as CWE-863, allows for improper access controls in Tanium Comply. Affected versions include 2.32.0 to 2.32.252, 2.35.0 to 2.35.306, and 2.37.0 to 2.37.308. Tanium has addressed the issue with patches. Defenders r [truncated]

MEDIUM Tanium CVE published 2026-09-09

CVE-2026-87073

CVE-2026-87073 is a medium-severity vulnerability in Tanium Comply, an improper access controls issue addressed by the vendor. The CVE record was published on 2026-09-09T03:17:26.847Z and was last modified on 2026-09-16T15:25:07.537Z. The NVD entry is currently Analyzed. Defenders responsible for Tanium Comply installations should assess exposure and prioritize patching. This vulnerability may impact orga [truncated]

HIGH Tanium CVE published 2026-09-09

CVE-2026-87072

CVE-2026-87072 is an improper access controls vulnerability in Tanium Comply. The CVE record was published on 2026-09-09T03:17:26.723Z and has not been modified since then. The NVD entry is currently Analyzed. The vulnerability could allow an attacker to access sensitive information. Defenders should assess exposure and apply remediation. The CVSS score is 7.1 and the severity is HIGH. The vulnerability a [truncated]

MEDIUM Tanium CVE published 2026-09-09

CVE-2026-87048

Tanium addressed an improper access controls vulnerability in Comply. The CVE record was published on 2026-09-09T03:17:26.610Z and has not been modified since then. This vulnerability affects Tanium Comply deployments, particularly versions 2.32.0 to 2.32.252, 2.35.0 to 2.35.306, and 2.37.0 to 2.37.308. Defenders should assess exposure and prioritize verification and remediation efforts. The vulnerability [truncated]

MEDIUM Tanium CVE published 2026-09-09

CVE-2026-87046

Tanium addressed an improper access controls vulnerability in Comply. The CVE record was published on 2026-09-09T03:17:26.380Z and has not been modified since then. This vulnerability affects Tanium Comply deployments, particularly versions 2.32.0 to 2.32.252, 2.35.0 to 2.35.306, and 2.37.0 to 2.37.308. Defenders should assess exposure and prioritize verification and remediation based on the vendor adviso [truncated]

MEDIUM Tanium CVE published 2026-09-09

CVE-2026-87037

CVE-2026-87037 is a medium-severity vulnerability in Tanium Comply, an improper access controls issue addressed by the vendor. The CVE record was published on 2026-09-09T03:17:26.257Z and was last modified on 2026-09-16T15:24:19.167Z. The NVD entry is currently Analyzed. This vulnerability affects Tanium Comply versions 2.32.0 to 2.32.252, 2.35.0 to 2.35.306, and 2.37.0 to 2.37.308. Defenders should asses [truncated]

HIGH Tanium CVE published 2026-09-09

CVE-2026-87036

CVE-2026-87036 is a HIGH severity vulnerability in Tanium Comply, with a CVSS score of 8.1. The vulnerability is described as an improper access controls issue. Tanium has addressed this issue. The CVE record was published on 2026-09-09T03:17:26.143Z and was last modified on 2026-09-16T15:24:12.643Z. The NVD entry is currently Analyzed. This vulnerability affects Tanium Comply versions 2.32.0 to 2.32.252, [truncated]

MEDIUM Tanium CVE published 2026-09-09

CVE-2026-87035

CVE-2026-87035 is an information disclosure vulnerability in Tanium's Comply product, addressed by the vendor. The CVE record was published on 2026-09-09T03:17:26.027Z and was last modified on 2026-09-16T15:24:07.843Z. The NVD entry is currently Analyzed. This vulnerability affects Tanium Comply versions 2.37.0 to 2.37.308, and defenders should assess exposure and prioritize remediation. The vulnerability [truncated]

HIGH Tanium CVE published 2026-09-09

CVE-2026-87034

A SQL injection vulnerability was addressed in Tanium Comply, a product used for compliance and configuration management. The vulnerability has a CVSS score of 8.3 and is considered HIGH severity. It was reported that the vulnerability could allow attackers to inject malicious SQL code, potentially leading to unauthorized access or data manipulation. The CVE record was published on 2026-09-09T03:17:25.897 [truncated]

MEDIUM Tanium CVE published 2026-09-09

CVE-2026-87033

CVE-2026-87033 is a medium-severity vulnerability in Tanium Comply, an improper access controls issue addressed by the vendor. The CVE record was published on 2026-09-09T03:17:25.787Z and was last modified on 2026-09-16T15:24:55.310Z. The NVD entry is currently Analyzed. This vulnerability affects Tanium Comply deployments, particularly versions 2.32.0 to 2.32.252, 2.35.0 to 2.35.306, and 2.37.0 to 2.37.3 [truncated]

HIGH Tanium CVE published 2026-09-09

CVE-2026-87030

A path traversal vulnerability in Tanium Comply has been addressed. The CVE record was published on 2026-09-09T03:17:25.557Z and was last modified on 2026-09-16T15:24:52.067Z. The NVD entry is currently Analyzed. This vulnerability affects Tanium Comply versions 2.32.0 to 2.32.252, 2.35.0 to 2.35.306, and 2.37.0 to 2.37.308. Defenders should assess exposure and apply remediation to prevent potential explo [truncated]

MEDIUM Tanium CVE published 2026-09-09

CVE-2026-87025

Tanium addressed an improper access controls vulnerability in Comply. The CVE record was published on 2026-09-09T03:17:25.437Z and has not been modified since then. This vulnerability affects Tanium Comply deployments, particularly versions 2.32.0 to 2.32.252, 2.35.0 to 2.35.306, and 2.37.0 to 2.37.308. Defenders should assess their exposure and verify access controls to prevent potential unauthorized acc [truncated]

HIGH Tanium CVE published 2026-09-09

CVE-2026-87021

CVE-2026-87021 is a high-severity unauthorized code execution vulnerability in Tanium Comply. The vulnerability affects Tanium Comply versions 2.32.0 to 2.32.252, 2.35.0 to 2.35.306, and 2.37.0 to 2.37.308. Tanium has addressed the vulnerability. Defenders should verify and apply patches, review inventory, and monitor systems for suspicious activity related to the vulnerability. The CVE record and NVD ent [truncated]

MEDIUM Tanium CVE published 2026-09-09

CVE-2026-87019

CVE-2026-87019 is a medium-severity vulnerability in Tanium's Comply product, addressed by the vendor. The vulnerability is related to improper access controls, with a CVSS score of 4.3. According to the NVD, the vulnerability affects multiple versions of Comply, specifically 2.32.0 to 2.32.252, 2.35.0 to 2.35.306, and 2.37.0 to 2.37.308. Defenders should verify exposure and apply remediation for affected [truncated]

LOW Tanium CVE published 2026-08-19

CVE-2026-75476

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record for CVE-2026-75476 was published on 2026-08-19T21:17:37.143Z and has not been modified since then. This vulnerability, addressed in Tanium Threat Response, is a compression bomb vulnerability with a low CVSS score of 3.1. The NVD entry is currently Awaiting Analysis. Security teams responsible for Tanium Threat Response ins [truncated]

MEDIUM Tanium CVE published 2026-07-21

CVE-2026-12139

CVE-2026-12139 is an information disclosure vulnerability in Tanium Connect, a product used for managing and securing endpoint devices. The vulnerability has a CVSS score of 4.4 and is classified as MEDIUM severity. The CVE record was published on 2026-07-21T21:16:48.937Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. Security teams and administrators responsible for T [truncated]

LOW Tanium CVE published 2026-07-21

CVE-2026-11925

A UI Misrepresentation of Critical Information vulnerability was addressed in Tanium Server. The CVE record was published on 2026-07-21T21:16:48.793Z and has not been modified since then. This vulnerability, classified as LOW severity with a CVSS score of 2.7, relates to a UI Misrepresentation of Critical Information issue in Tanium Server. Security teams should review and verify the affected scope of Tan [truncated]

HIGH Tanium CVE published 2026-07-08

CVE-2026-15053

The CVE record for CVE-2026-15053 was published on 2026-07-08T14:16:56.930Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. This denial of service vulnerability in Tanium Server has a CVSS score of 7.5, indicating high severity. Security teams and administrators of Tanium Server installations should assess and mitigate this vulnerability. The vulnerability's details are [truncated]

HIGH Tanium CVE published 2026-05-27

CVE-2026-9208

Tanium Connect contains an unauthorized code execution vulnerability (CWE-78) that could allow an attacker with low privileges to execute arbitrary code remotely. The vulnerability has a CVSS 3.1 score of 8.8 (HIGH severity) with network attack vector, low attack complexity, and no required user interaction. The vulnerability impacts confidentiality, integrity, and availability at a high level. Tanium has [truncated]

HIGH Tanium CVE published 2026-05-27

CVE-2026-9207

Tanium Connect contains an unauthorized code execution vulnerability. The issue permits an attacker with low privileges to execute arbitrary code remotely without user interaction, resulting in high impact to confidentiality, integrity, and availability. The vulnerability is classified as CWE-78 (OS Command Injection). Tanium has published security advisory TAN-2026-014 addressing this issue.

MEDIUM Tanium CVE published 2026-05-27

CVE-2026-9156

Tanium addressed a denial of service vulnerability in Tanium Server. The vulnerability was published on 2026-05-27 with a CVSS 3.1 score of 6.5 (MEDIUM severity). The NVD entry indicates a CVSS vector of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N, though this vector appears inconsistent with the described denial of service impact—analysts should verify the official Tanium advisory for authoritative scor [truncated]

LOW Tanium CVE published 2026-04-22

CVE-2026-6392

CVE-2026-6392 is a low-severity information disclosure issue in Tanium Threat Response. NVD lists a CVSS 3.1 score of 2.7 with network attack vector, low attack complexity, and high privileges required. The affected ranges published by NVD are Threat Response versions 4.6.0 through 4.6.577 and 4.9.0 through 4.9.379. Tanium’s advisory is referenced by NVD, and the CVE was published on 2026-04-22 and last m [truncated]