# CERT-FR flags multiple Nessus vulnerabilities

Published: 2026-10-02 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/5ec6dd2e-d81c-5cbd-afce-fe6d98b85fcd/cert-fr-flags-multiple-nessus-vulnerabilities

> CERT-FR warns of multiple Tenable Nessus flaws before 10.12.5 enabling SQL injection, data exposure, integrity loss and remote denial of service.

CERT-FR published an advisory covering nine CVEs affecting Tenable Nessus versions prior to 10.12.5. The vulnerabilities span SQL injection, remote denial of service, and breaches of data confidentiality and integrity, as detailed in Tenable's own security bulletin tns-2026-26 published 1 October 2026. No exploitation in the wild is mentioned in the advisory.

Defenders running Nessus should prioritize upgrading to version 10.12.5 or later as referenced in the vendor bulletin. No indicators of compromise, threat actors, or active campaigns are associated with this disclosure; it is a standard vulnerability advisory requiring patch management action.

## Mentioned in this report

- Vulnerabilities: CVE-2026-103946, CVE-2026-103947, CVE-2026-103948, CVE-2026-103950, CVE-2026-103951, CVE-2026-103952, CVE-2026-103953, CVE-2026-103954, CVE-2026-103955

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1247

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/5ec6dd2e-d81c-5cbd-afce-fe6d98b85fcd/cert-fr-flags-multiple-nessus-vulnerabilities.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
