# Tenable Security Center gets patch for many flaws

Published: 2026-07-21 · Severity: medium
Canonical: https://vorant.io/reports/2afcbc0f-50c0-5f11-879d-c5ce1bbfe3a2/tenable-security-center-gets-patch-for-many-flaws

> Tenable patched dozens of vulnerabilities in Security Center, including remote code execution, SQL injection, and security bypass issues.

ANSSI (CERT-FR) issued an advisory covering multiple vulnerabilities in Tenable Security Center, affecting all versions without the SC202607.1 patch. The flaws span several vulnerability classes including remote code execution, SQL injection, and security policy bypass, though the advisory does not specify further technical detail on exploitation vectors or in-the-wild activity.

Tenable published the corresponding security bulletin (tns-2026-19) referencing a large number of CVEs. No indicators of compromise, threat actor attribution, or active exploitation were noted in the advisory. Organizations running affected Security Center deployments should apply the vendor patch as soon as possible to mitigate the described risks.

## Mentioned in this report

- Vulnerabilities: CVE-2025-11187, CVE-2025-14179, CVE-2025-15467, CVE-2025-15468, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-2003, CVE-2026-2004, CVE-2026-2005, CVE-2026-2006, CVE-2026-22795, CVE-2026-22796, CVE-2026-23479, CVE-2026-23631, CVE-2026-23918 (poc), CVE-2026-24072, CVE-2026-25243, CVE-2026-25588, CVE-2026-25589, CVE-2026-33523, CVE-2026-33857, CVE-2026-34032, CVE-2026-34059, CVE-2026-42371, CVE-2026-6104, CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479, CVE-2026-64877, CVE-2026-64878, CVE-2026-64879

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0905

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/2afcbc0f-50c0-5f11-879d-c5ce1bbfe3a2/tenable-security-center-gets-patch-for-many-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
