VORANT. Threat Intelligence Sign in Get the full feed

Tenable Identity Exposure patches 100+ flaws

high vulnerability

Tenable has patched over 100 vulnerabilities in Identity Exposure versions prior to v3.93.5, including flaws enabling remote code execution, SQL injection, and data breaches.

France's CERT-FR issued an advisory for multiple vulnerabilities discovered in Tenable Identity Exposure affecting all versions prior to v3.93.5. The security update addresses over 100 CVEs spanning a wide range of vulnerability classes including remote code execution, SQL injection, denial of service, security policy bypass, and confidentiality breaches. The sheer volume of patched flaws suggests either a comprehensive security audit or coordinated disclosure of accumulated issues.

Tenable Identity Exposure is an Active Directory security solution used to detect attack paths and privilege escalation risks in enterprise environments. Given its access to sensitive directory data and authentication infrastructure, these vulnerabilities could allow attackers to compromise identity management systems, potentially enabling lateral movement across enterprise networks. The advisory lists impacts including arbitrary code execution, SQL injection, and data integrity violations.

Tenable released security bulletin TNS-2026-16 on June 23, 2026, providing patches in version 3.93.5. Organizations running earlier versions should prioritize this update given the product's privileged access to directory infrastructure and the presence of remote code execution vulnerabilities.

Mentioned in this report

Vulnerabilities CVE-2025-11187CVE-2025-13034CVE-2025-14017CVE-2025-14524CVE-2025-14819CVE-2025-15079CVE-2025-15224CVE-2025-15467CVE-2025-15468CVE-2025-15469CVE-2025-55130CVE-2025-55131CVE-2025-55132CVE-2025-55247CVE-2025-55248CVE-2025-55315pocCVE-2025-59465CVE-2025-59466CVE-2025-66199CVE-2025-68160CVE-2025-69418CVE-2025-69419CVE-2025-69420CVE-2025-69421CVE-2026-13007CVE-2026-1965CVE-2026-2673CVE-2026-3783CVE-2026-3784CVE-2026-3805CVE-2026-4873CVE-2026-5545CVE-2026-5773CVE-2026-6253CVE-2026-6276CVE-2026-6429CVE-2026-7009CVE-2026-7168CVE-2026-7383CVE-2026-9076

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0796

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free