{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/endpoint-security-windows-14.0-14.1--2026-08-30/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Endpoint Security Windows (14.0, 14.1 \u003c 2026-08-30)"],"_cs_severities":["medium"],"_cs_tags":["vulnerability","security-policy-bypass"],"_cs_type":"threat","_cs_vendors":["Kaspersky"],"content_html":"\u003cp\u003eA security vulnerability has been identified in Kaspersky Endpoint Security for Windows that allows an attacker to bypass established security policies. The flaw affects versions 14.0 and 14.1 of the application that have not applied the security update released on August 30, 2026. This vulnerability is significant as it potentially permits the subversion of security controls, enabling unauthorized system activity that would otherwise be blocked by the agent. Defenders must ensure all instances of the affected versions are patched according to the vendor's guidance to maintain endpoint integrity and policy enforcement.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an attacker to circumvent configured security policies on the targeted endpoint. This impacts the ability of the security software to provide protection, increasing the risk of further malicious activity, unauthorized access, or persistence that would typically be prevented by the security agent.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the deployment of the security update released on August 30, 2026, for all instances of Kaspersky Endpoint Security for Windows 14.0 and 14.1. Audit the environment to identify any endpoints running these specific legacy versions and ensure they are patched immediately.\u003c/p\u003e\n","date_modified":"2026-09-01T17:59:18Z","date_published":"2026-09-01T17:59:18Z","id":"https://feed.craftedsignal.io/briefs/2026-09-kaspersky-policy-bypass/","summary":"A security policy bypass vulnerability exists in Kaspersky Endpoint Security for Windows, affecting versions 14.0 and 14.1, which allows attackers to circumvent configured security enforcement.","title":"Security Policy Bypass in Kaspersky Endpoint Security for Windows","url":"https://feed.craftedsignal.io/briefs/2026-09-kaspersky-policy-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Endpoint Security Windows (14.0, 14.1 \u003c 2026-08-30)","version":"https://jsonfeed.org/version/1.1"}