The cybersecurity companies patched critical and high-severity vulnerabilities in some of their products.
Firewalls and other cybersecurity products
Cybersecurity companies TrendAI (Trend Micro), ESET, Tenable, and Tanium released product updates this month to patch severe vulnerabilities.
Tenable told customers this week that it has fixed a critical-severity path traversal in the Tenable Agent. The security hole, tracked as CVE-2026-15265, may allow an attacker to achieve remote code execution.
ESET informed customers on Tuesday that it has discovered and patched a high-severity local privilege escalation vulnerability in Inspect Connector for Windows.
“On systems with the affected ESET product installed, an attacker could send self-crafted Advanced Local Procedure Call (ALPC) requests to the vulnerable process’ interface,” ESET explained in its advisory. “Without proper authentication or origin validation in place, this message would be accepted and processed, enabling the attacker to access restricted functionality.”
ESET has also published a separate advisory for a medium-severity DoS vulnerability in its security products for Linux.
Firewalls and other cybersecurity products
Cybersecurity companies TrendAI (Trend Micro), ESET, Tenable, and Tanium released product updates this month to patch severe vulnerabilities.
Tenable told customers this week that it has fixed a critical-severity path traversal in the Tenable Agent. The security hole, tracked as CVE-2026-15265, may allow an attacker to achieve remote code execution.
ESET informed customers on Tuesday that it has discovered and patched a high-severity local privilege escalation vulnerability in Inspect Connector for Windows.
“On systems with the affected ESET product installed, an attacker could send self-crafted Advanced Local Procedure Call (ALPC) requests to the vulnerable process’ interface,” ESET explained in its advisory. “Without proper authentication or origin validation in place, this message would be accepted and processed, enabling the attacker to access restricted functionality.”
ESET has also published a separate advisory for a medium-severity DoS vulnerability in its security products for Linux.
Tanium informed customers last week about a high-severity DoS flaw affecting Tanium Server.
“This vulnerability could allow an unauthenticated, network-based attacker to perform a denial of service attack against the Tanium Server,” the company noted.
Trend Micro informed Cleaner One Pro users last week of a medium-severity arbitrary file deletion vulnerability that could “allow a malicious app already running on your device to trick the cleanup process into deleting a file it shouldn’t have access to.”
The vendor noted that local access is required for exploitation and the vulnerability cannot be exploited remotely.
Palo Alto Networks also released patches this month, addressing over a dozen vulnerabilities in its products.
While there is no evidence of exploitation for the latest vulnerabilities, it’s not uncommon for threat actors to target security products in their attacks. For instance, Palo Alto Networks and Trend Micro recently confirmed in-the-wild exploitation.




