Tenable Nessus SQL injection flaws patched
Multiple SQL injection vulnerabilities in Tenable Nessus versions before 10.12.0 allow attackers to execute malicious SQL queries.
Tenable has disclosed multiple SQL injection (SQLi) vulnerabilities affecting Nessus versions prior to 10.12.0. These flaws enable an attacker to inject and execute arbitrary SQL commands against the application's database. SQL injection vulnerabilities can lead to unauthorized data access, modification, or deletion, depending on the database privileges and the application's architecture.
The vulnerabilities are tracked as CVE-2026-57587 and CVE-2026-57588. Tenable released security bulletin TNS-2026-17 on June 24, 2026, providing patches in Nessus version 10.12.0. Organizations running affected versions should prioritize upgrading to the patched release to mitigate exploitation risk.
Given that Nessus is a widely-deployed vulnerability scanner with privileged access to network infrastructure and sensitive scan data, these SQLi flaws represent a significant risk if exploited. However, there is no indication of active in-the-wild exploitation at this time.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0804
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free