PatchSiren

Tanium CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Tanium CVE published 2026-07-21

CVE-2026-12139

CVE-2026-12139 is an information disclosure vulnerability in Tanium Connect, a product used for managing and securing endpoint devices. The vulnerability has a CVSS score of 4.4 and is classified as MEDIUM severity. The CVE record was published on 2026-07-21T21:16:48.937Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. Security teams and administrators responsible for T [truncated]

LOW Tanium CVE published 2026-07-21

CVE-2026-11925

A UI Misrepresentation of Critical Information vulnerability was addressed in Tanium Server. The CVE record was published on 2026-07-21T21:16:48.793Z and has not been modified since then. This vulnerability, classified as LOW severity with a CVSS score of 2.7, relates to a UI Misrepresentation of Critical Information issue in Tanium Server. Security teams should review and verify the affected scope of Tan [truncated]

HIGH Tanium CVE published 2026-07-08

CVE-2026-15053

The CVE record for CVE-2026-15053 was published on 2026-07-08T14:16:56.930Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. This denial of service vulnerability in Tanium Server has a CVSS score of 7.5, indicating high severity. Security teams and administrators of Tanium Server installations should assess and mitigate this vulnerability. The vulnerability's details are [truncated]

HIGH Tanium CVE published 2026-05-27

CVE-2026-9208

Tanium Connect contains an unauthorized code execution vulnerability (CWE-78) that could allow an attacker with low privileges to execute arbitrary code remotely. The vulnerability has a CVSS 3.1 score of 8.8 (HIGH severity) with network attack vector, low attack complexity, and no required user interaction. The vulnerability impacts confidentiality, integrity, and availability at a high level. Tanium has [truncated]

HIGH Tanium CVE published 2026-05-27

CVE-2026-9207

Tanium Connect contains an unauthorized code execution vulnerability. The issue permits an attacker with low privileges to execute arbitrary code remotely without user interaction, resulting in high impact to confidentiality, integrity, and availability. The vulnerability is classified as CWE-78 (OS Command Injection). Tanium has published security advisory TAN-2026-014 addressing this issue.

MEDIUM Tanium CVE published 2026-05-27

CVE-2026-9156

Tanium addressed a denial of service vulnerability in Tanium Server. The vulnerability was published on 2026-05-27 with a CVSS 3.1 score of 6.5 (MEDIUM severity). The NVD entry indicates a CVSS vector of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N, though this vector appears inconsistent with the described denial of service impact—analysts should verify the official Tanium advisory for authoritative scor [truncated]

LOW Tanium CVE published 2026-04-22

CVE-2026-6392

CVE-2026-6392 is a low-severity information disclosure issue in Tanium Threat Response. NVD lists a CVSS 3.1 score of 2.7 with network attack vector, low attack complexity, and high privileges required. The affected ranges published by NVD are Threat Response versions 4.6.0 through 4.6.577 and 4.9.0 through 4.9.379. Tanium’s advisory is referenced by NVD, and the CVE was published on 2026-04-22 and last m [truncated]