Multiple vulnerabilities in Tenable products (August 4, 2026)
Multiple vulnerabilities have been discovered in Tenable products. Some of them allow an attacker to cause remote arbitrary code execution, data integrity breach and SQL injection (SQLi).
CSIRTS triage
- What
- Multiple vulnerabilities including remote code execution, data integrity breach, and SQL injection.
- Who is affected
- Tenable product installations affected by the disclosed CVEs.
- Urgency
- Critical; remote code execution and SQL injection allow direct system compromise and data access.
- Action
- Apply Tenable security patches for the listed CVEs immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0962/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2025-661990.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-234791.3% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 67% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-64740.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-64720.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-154690.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-64790.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-72610.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-61040.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-694190.44% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-67350.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all EPSS-scored CVEs.
Referenced CVEs
+7 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Apple macOS (Tahoe, Sonoma, and Sequoia): Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] Golang Go: Multiple vulnerabilitiescert-bund
- medium[UPDATE] [medium] Golang Go: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] PostgreSQL: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Solaris third-party components: Multiple vulnerabilitiescert-bund
- criticalCVE-2026-18667: A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated…nvd
- unknownMultiple vulnerabilities in IBM products (July 31, 2026)cert-fr-avis
- high[UPDATE] [high] PHP: Multiple vulnerabilitiescert-bund
- unknownF5 Products Multiple Vulnerabilitieshkcert
- criticalSiemens Desigo CCcisa
- high[UPDATE] [high] Oracle MySQL: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] Apache HTTP Server: Multiple vulnerabilitiescert-bund
More from CERT-FR Avis de sécurité
- unknownVulnerability in Sonicwall SonicOS (August 6, 2026)2026-08-06
- unknownMultiple vulnerabilities in Wallix products (August 6, 2026)2026-08-06
- unknownMultiple vulnerabilities in Cisco products (August 6, 2026)2026-08-06
- unknownMultiple vulnerabilities in Nextcloud products (August 6, 2026)2026-08-06
- unknownMultiple vulnerabilities in KeyCloak (August 6, 2026)2026-08-06