Multiple XSS vulnerabilities in Kaspersky Anti Targeted Attack Platform versions before…
Multiple XSS vulnerabilities in Kaspersky Anti Targeted Attack Platform versions before 7.1.7 allow remote code injection attacks.
The French CERT (CERT-FR) has published an advisory regarding multiple cross-site scripting (XSS) vulnerabilities affecting Kaspersky Anti Targeted Attack Platform versions prior to 7.1.7. These vulnerabilities enable attackers to perform remote indirect code injection attacks against the platform.
The affected product is an enterprise-grade threat detection and response solution, making these vulnerabilities particularly concerning for organizations relying on this platform for security operations. Two CVE identifiers have been assigned to track these issues: CVE-2026-28348 and CVE-2026-28350.
Kaspersky has released security updates addressing these vulnerabilities in version 7.1.7. Organizations running affected versions should consult the vendor's security bulletin and apply the available patches to mitigate the risk of exploitation.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0648
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free