VORANT. Threat Intelligence Sign in Get the full feed

Tenable Nessus Agent flaw enables RCE

medium vulnerability

A vulnerability in Tenable Nessus Agent allows remote code execution and security policy bypass; patches are available.

The French national cybersecurity agency (ANSSI/CERT-FR) issued an advisory regarding a vulnerability in Tenable Nessus Agent that could allow an attacker to execute arbitrary code remotely and bypass security policy controls. The affected versions include Nessus Agent 11.2.x prior to 11.2.1 and versions prior to 11.1.4.

Tenable has released a security bulletin (tns-2026-18) addressing the flaw, tracked as CVE-2026-15265. Organizations using affected versions of Nessus Agent should apply the vendor-provided patches as soon as possible. No indication of active exploitation is mentioned in the advisory.

Mentioned in this report

Vulnerabilities CVE-2026-15265

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0886

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free