Tenable patches Enclave Security, Security Center flaws
ANSSI advisory details multiple vulnerabilities in Tenable Enclave Security and Security Center allowing remote code execution and privilege escalation.
The French national cybersecurity agency (ANSSI/CERT-FR) issued an advisory relaying Tenable security bulletins tns-2026-24 and tns-2026-25, covering multiple vulnerabilities in Tenable Enclave Security (versions prior to 1.9.0) and Security Center (versions prior to 6.9.0). The flaws, tracked as CVE-2026-19626, CVE-2026-19628, CVE-2026-19629, and CVE-2026-19635, allow an attacker to achieve remote arbitrary code execution and privilege escalation.
No evidence of active exploitation is mentioned in the advisory; it is a standard vendor patch notification relayed by CERT-FR. Organizations running affected Tenable products should consult the vendor's security bulletins and apply the available patches to remediate the vulnerabilities.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1097
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free