Multiple vulnerabilities in Tenable Security Center (August 14, 2026)
Multiple vulnerabilities have been discovered in Tenable Security Center. Some of them allow an attacker to cause remote arbitrary code execution, privilege escalation and SQL injection (SQLi).
CSIRTS triage
- What
- Multiple vulnerabilities in Tenable Security Center allow remote arbitrary code execution, privilege escalation, and SQL injection attacks.
- Who is affected
- All Tenable Security Center instances are at risk.
- Urgency
- Critical severity with RCE exploitability; patch immediately to prevent system compromise.
- Action
- Update Security Center to the latest patched version addressing all listed CVEs.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Security Center
Get an email when a new Security Center advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1023/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2026-196791.6% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 73% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-196350.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-196282.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 80% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-196260.88% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 56% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-196360.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-118560.60% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 46% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-196310.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-115860.49% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-120640.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-196822.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 79% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[UPDATE] [medium] cURL: Multiple vulnerabilitiescert-bund
- highexploited[NEW] [high] Atlassian Products (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, and Jira): Multiple vulnera…cert-bund
- high[NEW] [high] Hitachi Energy RTU500: Multiple Vulnerabilitiescert-bund
- medium[UPDATE] [medium] cURL: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] cURL: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Tenable products (August 31, 2026)cert-fr-avis
- high[NEW] [high] Apple macOS, iOS and iPadOS: Multiple vulnerabilitiescert-bund
- unknownNCSC-2026-0325 [1.00] [M/H] Vulnerabilities patched in Atlassian productsncsc-nl
- unknownNCSC-2026-0319 [1.00] [M/H] Vulnerabilities resolved in Apple iOS and iPadOSncsc-nl
- unknownUSN-8651-1: curl vulnerabilityubuntu
- unknownApple Products Multiple Vulnerabilitieshkcert
- criticalCVE-2026-19682: A command injection vulnerability exists in Security Center where a remote, unauthenticated at…nvd
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Sonicwall Network Security Manager (September 4, 2026)2026-09-04
- unknownMultiple vulnerabilities in Debian Linux kernel (September 4, 2026)2026-09-04
- unknownMultiple vulnerabilities in VMware products (September 4, 2026)2026-09-04
- unknownMultiple vulnerabilities in Elastic Kibana (September 4, 2026)2026-09-04
- unknownMultiple vulnerabilities in Google Chrome (September 4, 2026)2026-09-04