Tanium Inc. provides endpoint management and threat-response platforms that operate across enterprise client and server infrastructure, spanning products such as its core server, Tanos agent framework, Threat Response, Discover, and Interact modules. Its vulnerability footprint reflects the privileged access and file-system interaction inherent to management agents deployed at scale: recurring weakness classes center on improper authorization, incorrect default permissions, insecure file-access patterns including symlink following, and inadvertent logging of sensitive information. The vendor operates as a CNA and maintains a focused product portfolio that, while modestly represented in absolute terms, sits among the more prominent in the management and endpoint-security landscape. Defenders tracking this vendor should prioritize authorization and credential-handling disclosures given the trust model of agent-based systems and their role in lateral movement and privilege escalation paths. Current vulnerability severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tanium Inc. over time
Of all the CVEs published by Tanium Inc. as a CNA, 98.2% affect products that Tanium Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Tanium Inc., 100.0% are self-published by Tanium Inc. as a CNA.
Signals from CVEs in this vendor scope (54 CVEs).
54 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-9207HIGH Tanium addressed an unauthorized code execution vulnerability in Connect. | May 27, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-15053HIGH Tanium addressed a denial of service vulnerability in Tanium Server. | Jul 8, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-9208HIGH Tanium addressed an unauthorized code execution vulnerability in Connect. | May 27, 2026 | 8.8 | 33 | NO | NO |
CVE-2026-9156HIGH Tanium addressed a denial of service vulnerability in Tanium Server. | May 27, 2026 | 7.5 | 30 | NO | NO |
CVE-2025-15330HIGH Tanium addressed an improper input validation vulnerability in Deploy. | Feb 5, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-2435HIGH Tanium addressed a SQL injection vulnerability in Asset. | Feb 20, 2026 | 8.8 | 27 | NO | NO |
CVE-2025-15344HIGH Tanium addressed a SQL injection vulnerability in Asset. | Jan 29, 2026 | 8.8 | 27 | NO | NO |
CVE-2025-15311HIGH Tanium addressed an unauthorized code execution vulnerability in Tanium Appliance. | Feb 5, 2026 | 7.8 | 25 | NO | NO |
CVE-2025-15314HIGH Tanium addressed an arbitrary file deletion vulnerability in end-user-cx. | Feb 10, 2026 | 8.1 | 24 | NO | NO |
CVE-2025-15310HIGH Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools. | Feb 10, 2026 | 7.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (54 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tanium Inc..
Media articles that mention a CVE ID that affects a product developed by Tanium Inc. — matched by CVE ID, not by vendor name.