Multiple vulnerabilities in Tenable Security Center (August 14, 2026)
Multiple vulnerabilities have been discovered in Tenable Security Center. Some of them allow an attacker to cause remote arbitrary code execution, privilege escalation and SQL injection (SQLi).
CSIRTS triage
- What
- Multiple vulnerabilities in Tenable Security Center allow remote arbitrary code execution, privilege escalation, and SQL injection attacks.
- Who is affected
- All Tenable Security Center instances are at risk.
- Urgency
- Critical severity with RCE exploitability; patch immediately to prevent system compromise.
- Action
- Update Security Center to the latest patched version addressing all listed CVEs.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Security Center
Get an email when a new Security Center advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1023/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2026-196791.6% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 73% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-196350.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-196282.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 79% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-196260.79% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 53% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-196360.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-118560.60% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 46% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-196310.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-115860.49% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-120640.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-196821.9% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 78% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownUSN-8651-1: curl vulnerabilityubuntu
- highexploited[NEW] [high] Atlassian Products (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, and Jira): Multiple vulnera…cert-bund
- medium[UPDATE] [medium] cURL: Multiple vulnerabilitiescert-bund
- medium[UPDATE] [medium] cURL: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Apple macOS, iOS and iPadOS: Multiple vulnerabilitiescert-bund
- unknownApple Products Multiple Vulnerabilitieshkcert
- criticalCVE-2026-19682: A command injection vulnerability exists in Security Center where a remote, unauthenticated at…nvd
- criticalCVE-2026-19681: An authenticated command injection vulnerability exists in Security Center related to file upl…nvd
- highCVE-2026-19680: A SQL injection vulnerability exists in Security Center that could allow an attacker to access…nvd
- highCVE-2026-19679: An input validation vulnerability exists in Security Center's file upload handling, where insu…nvd
- mediumCVE-2026-19639: An improper access control vulnerability exists where an authenticated non-administrative appl…nvd
- mediumCVE-2026-19636: An issue was identified in which CSRF tokens were generated using a predictable method, potent…nvd
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Oracle Virtualization (August 19, 2026)2026-08-19
- unknownMultiple vulnerabilities in Oracle Weblogic (August 19, 2026)2026-08-19
- unknownMultiple vulnerabilities in Axis products (August 19, 2026)2026-08-19
- unknownMultiple vulnerabilities in Google Chrome (August 19, 2026)2026-08-19
- unknownMultiple vulnerabilities in Oracle MySQL (August 19, 2026)2026-08-19