Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities
Several cybersecurity firms, including Trend Micro, Tenable, ESET, and Palo Alto Networks, have released patches to address critical vulnerabilities in their products. These vulnerabilities range from local privilege escalation and denial-of-service attacks to path traversal exploits, highlighting a continued focus on securing security products themselves from attack.
Several cybersecurity companies have released updates to address a series of significant vulnerabilities within their products. Trend Micro, Tenable, ESET, and Palo Alto Networks are among those issuing patches this month. These vulnerabilities represent a proactive effort to secure their own products from exploitation.
Trend Micro addressed a critical path traversal vulnerability in the Tenable Agent, tracked as CVE-2026-15265. This allowed an attacker to potentially execute remote code, emphasizing the importance of regularly updating security tools. ESET discovered and patched a high-severity local privilege escalation vulnerability in Inspect Connector for Windows, enabling an attacker to craft specific messages to gain unauthorized access and functionality. ESET also released a medium-severity DoS vulnerability in its Linux security products.
Tanium informed customers of a high-severity DoS flaw affecting Tanium Server, allowing unauthenticated network-based attacks to cause a denial of service. Trend Micro addressed a critical local privilege escalation vulnerability in Cleaner One Pro, potentially allowing an attacker to delete sensitive files.
While there is currently no evidence of active exploitation for these vulnerabilities, cybersecurity companies have previously noted that threat actors frequently target security products in their attacks. Palo Alto Networks and Trend Micro have both confirmed in-the-wild exploitation of vulnerabilities in the past.