# Multiple XSS vulnerabilities in Kaspersky Anti Targeted Attack Platform versions before…

Published: 2026-05-27 · Severity: medium
Canonical: https://vorant.io/reports/727f5d13-a626-4258-abf3-88e6edd0aa24/multiple-xss-vulnerabilities-in-kaspersky-anti-targeted-attack-platform

> Multiple XSS vulnerabilities in Kaspersky Anti Targeted Attack Platform versions before 7.1.7 allow remote code injection attacks.

The French CERT (CERT-FR) has published an advisory regarding multiple cross-site scripting (XSS) vulnerabilities affecting Kaspersky Anti Targeted Attack Platform versions prior to 7.1.7. These vulnerabilities enable attackers to perform remote indirect code injection attacks against the platform.

The affected product is an enterprise-grade threat detection and response solution, making these vulnerabilities particularly concerning for organizations relying on this platform for security operations. Two CVE identifiers have been assigned to track these issues: CVE-2026-28348 and CVE-2026-28350.

Kaspersky has released security updates addressing these vulnerabilities in version 7.1.7. Organizations running affected versions should consult the vendor's security bulletin and apply the available patches to mitigate the risk of exploitation.

## Mentioned in this report

- Vulnerabilities: CVE-2026-28348, CVE-2026-28350

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0648

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/727f5d13-a626-4258-abf3-88e6edd0aa24/multiple-xss-vulnerabilities-in-kaspersky-anti-targeted-attack-platform.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
