Trend Micro, ESET, Tenable and Tanium patch critical flaws

Trend Micro, ESET, Tenable and Tanium released patches this month for severe vulnerabilities, including Tenable’s CVE-2026-15265 path traversal and an ESET ALPC local privilege escalation.

Four cybersecurity vendors released product updates this month to address high- and critical-severity vulnerabilities affecting widely used security tools.

Tenable published a fix for a critical path traversal in the Tenable Agent tracked as CVE-2026-15265. The vendor’s advisory states the flaw can allow an attacker to reference files outside intended directories and, under certain conditions, to execute arbitrary code on the host.

ESET issued a patch for a high-severity local privilege escalation in Inspect Connector for Windows. An ESET advisory explains that an attacker who can reach the vulnerable process could send crafted Advanced Local Procedure Call (ALPC) requests that are processed without origin or authentication checks, allowing access to restricted functionality. ESET also posted a separate notice for a medium-severity denial-of-service issue affecting some Linux products.

Tanium released an update for a high-severity denial-of-service vulnerability in Tanium Server. The company’s notice describes the flaw as one that could allow an unauthenticated, network-based attacker to disrupt the server. Trend Micro published a patch for a high-severity local privilege escalation in Cleaner One Pro that could let an attacker delete files that require elevated privileges. Palo Alto Networks also addressed more than a dozen vulnerabilities across its product line this month.

Vendors’ advisories say there is no public evidence so far that these specific vulnerabilities are being actively exploited. Advisories note that attackers often target security products because successful exploitation can affect detection or control functions.

All vendors recommend applying the provided updates immediately. Administrators are advised to follow each advisory’s instructions for patching affected versions and to implement any listed mitigations until updates are installed.

Security vendors continued to publish fixes this month; customers and IT teams should monitor vendor advisories for additional details and follow-up patches.

Articles by this author