# Kaspersky Endpoint Security flaw bypasses policy

Published: 2026-09-01 · Severity: routine
Canonical: https://vorant.io/reports/894aa286-bdd3-53e8-9dd5-45c2f2cb7833/kaspersky-endpoint-security-flaw-bypasses-policy

> A vulnerability in Kaspersky Endpoint Security for Windows 14.0/14.1 allows security policy bypass; fixed by the August 30, 2026 update.

CERT-FR issued an advisory regarding a vulnerability in Kaspersky Endpoint Security for Windows versions 14.0 and 14.1 that lack the update released on August 30, 2026. The flaw allows an attacker to bypass the product's security policy, potentially weakening endpoint protection controls on affected systems.

Kaspersky published a corresponding security bulletin (12430#310826) on August 31, 2026, with corrective patches available. Organizations running the affected versions without the referenced update should apply the vendor patch as soon as possible to restore intended policy enforcement. No indication of active exploitation is provided in the advisory.

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1101

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/894aa286-bdd3-53e8-9dd5-45c2f2cb7833/kaspersky-endpoint-security-flaw-bypasses-policy.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
