Compression Bomb Vulnerability in Tanium Threat Response
CVE-2026-75476

3.1LOW

Key Information:

Vendor

Tanium

Vendor
CVE Published:
19 August 2026

What is CVE-2026-75476?

A vulnerability in Tanium's Threat Response product enables the exploitation of compression bomb attacks, which can lead to excessive resource consumption and denial of service. This type of attack leverages specially crafted inputs that, when decompressed, can overwhelm system resources, causing performance degradation or downtime. Organizations using Tanium Threat Response need to ensure their systems are updated and protected against these types of vulnerabilities to maintain a secure environment. For more details on mitigation strategies, refer to Tanium's official documentation.

Affected Version(s)

Threat Response 4.9 < 4.9.437

Threat Response 4.12 < 4.12.308

Threat Response 4.17 < 4.17.277

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.