VORANT. Threat Intelligence Sign in Get the full feed

Kaspersky Endpoint Security flaw bypasses policy

routine vulnerability

A vulnerability in Kaspersky Endpoint Security for Windows 14.0/14.1 allows security policy bypass; fixed by the August 30, 2026 update.

CERT-FR issued an advisory regarding a vulnerability in Kaspersky Endpoint Security for Windows versions 14.0 and 14.1 that lack the update released on August 30, 2026. The flaw allows an attacker to bypass the product's security policy, potentially weakening endpoint protection controls on affected systems.

Kaspersky published a corresponding security bulletin (12430#310826) on August 31, 2026, with corrective patches available. Organizations running the affected versions without the referenced update should apply the vendor patch as soon as possible to restore intended policy enforcement. No indication of active exploitation is provided in the advisory.

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1101

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free