Tenable Patches Dozens of Flaws in Enclave, Sensor Proxy
CERT-FR advises multiple vulnerabilities in Tenable Enclave Security and Sensor Proxy could allow remote code execution, SQL injection, and data integrity compromise.
CERT-FR issued an advisory covering a large batch of vulnerabilities disclosed by Tenable affecting Enclave Security (unpatched prior to correctif SC202607.2) and Sensor Proxy versions prior to 1.4.2. The flaws span multiple vulnerability classes including remote code execution, SQL injection, data integrity compromise, and security policy bypass, with dozens of CVEs referenced across two Tenable security bulletins (tns-2026-20 and tns-2026-21) published in late July and early August 2026.
No evidence of active exploitation is mentioned in the advisory, and the vulnerability details are not further specified by the vendor beyond the bulletin references. CERT-FR's guidance is limited to directing affected organizations to apply the vendor-supplied patches referenced in the Tenable bulletins. Given the volume of CVEs and the security-tooling nature of the affected products (used for vulnerability and exposure management), organizations running these Tenable products should prioritize patching to prevent downstream compromise of security monitoring infrastructure.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0962
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free