VORANT. Threat Intelligence Sign in Get the full feed

Tenable Security Center gets patch for many flaws

medium vulnerability

Tenable patched dozens of vulnerabilities in Security Center, including remote code execution, SQL injection, and security bypass issues.

ANSSI (CERT-FR) issued an advisory covering multiple vulnerabilities in Tenable Security Center, affecting all versions without the SC202607.1 patch. The flaws span several vulnerability classes including remote code execution, SQL injection, and security policy bypass, though the advisory does not specify further technical detail on exploitation vectors or in-the-wild activity.

Tenable published the corresponding security bulletin (tns-2026-19) referencing a large number of CVEs. No indicators of compromise, threat actor attribution, or active exploitation were noted in the advisory. Organizations running affected Security Center deployments should apply the vendor patch as soon as possible to mitigate the described risks.

Mentioned in this report

Vulnerabilities CVE-2025-11187CVE-2025-14179CVE-2025-15467CVE-2025-15468CVE-2025-15469CVE-2025-66199CVE-2025-68160CVE-2025-69418CVE-2025-69419CVE-2025-69420CVE-2025-69421CVE-2026-2003CVE-2026-2004CVE-2026-2005CVE-2026-2006CVE-2026-22795CVE-2026-22796CVE-2026-23479CVE-2026-23631CVE-2026-23918pocCVE-2026-24072CVE-2026-25243CVE-2026-25588CVE-2026-25589CVE-2026-33523CVE-2026-33857CVE-2026-34032CVE-2026-34059CVE-2026-42371CVE-2026-6104CVE-2026-6472CVE-2026-6473CVE-2026-6474CVE-2026-6475CVE-2026-6477CVE-2026-6478CVE-2026-6479CVE-2026-64877CVE-2026-64878CVE-2026-64879

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0905

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free