Endpoint Security

Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities

The cybersecurity companies patched critical and high-severity vulnerabilities in some of their products.

Firewalls and other cybersecurity products

Cybersecurity companies TrendAI (Trend Micro), ESET, Tenable, and Tanium released product updates this month to patch severe vulnerabilities.

Tenable told customers this week that it has fixed a critical-severity path traversal in the Tenable Agent. The security hole, tracked as CVE-2026-15265, may allow an attacker to achieve remote code execution.

[ Read: SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits ]

ESET informed customers on Tuesday that it has discovered and patched a high-severity local privilege escalation vulnerability in Inspect Connector for Windows.

“On systems with the affected ESET product installed, an attacker could send self-crafted Advanced Local Procedure Call (ALPC) requests to the vulnerable process’ interface,” ESET explained in its advisory. “Without proper authentication or origin validation in place, this message would be accepted and processed, enabling the attacker to access restricted functionality.”

ESET has also published a separate advisory for a medium-severity DoS vulnerability in its security products for Linux.

Advertisement. Scroll to continue reading.

Tanium informed customers last week about a high-severity DoS flaw affecting Tanium Server. 

“This vulnerability could allow an unauthenticated, network-based attacker to perform a denial of service attack against the Tanium Server,” the company noted.

Trend Micro informed Cleaner One Pro users last week of a medium-severity arbitrary file deletion vulnerability that could “allow a malicious app already running on your device to trick the cleanup process into deleting a file it shouldn’t have access to.”

The vendor noted that local access is required for exploitation and the vulnerability cannot be exploited remotely.

Palo Alto Networks also released patches this month, addressing over a dozen vulnerabilities in its products.

While there is no evidence of exploitation for the latest vulnerabilities, it’s not uncommon for threat actors to target security products in their attacks. For instance, Palo Alto Networks and Trend Micro recently confirmed in-the-wild exploitation. 

Related: Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow

Related: Vulnerabilities Patched in CrowdStrike, Tenable Products

Related: Trend Micro Patches Critical Apex One Vulnerabilities

Related Content

Artificial Intelligence

AgentForger allows an attacker to create, insert and remotely control an invisible autonomous AI agent inside a victim organization.

Vulnerabilities

The vulnerability tracked as CVE-2026-16232 has been exploited against customers with certain configurations.

Vulnerabilities

An attacker only needed to convince the targeted user to visit a malicious website to exfiltrate WhatsApp messages and contacts.

Vulnerabilities

CVE-2026-50522 is being exploited by threat actors to steal machine keys and retain long-term access.

Vulnerabilities

Many of the vulnerabilities fixed with the July 2026 Critical Patch Update were likely discovered by AI.

Artificial Intelligence

The open-weight Antares models are designed to pinpoint known vulnerabilities in codebases faster and at a fraction of the cost of larger AI models.

Vulnerabilities

A security researcher discovered a broken access control vulnerability in Meta’s support infrastructure.

Vulnerabilities

The ServiceNow AI platform vulnerability tracked as CVE-2026-6875 can be exploited for remote code execution.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version