Multiple vulnerabilities in Tenable Identity Exposure (June 24, 2026)
Multiple vulnerabilities have been discovered in Tenable Identity Exposure. Some of them allow an attacker to cause remote arbitrary code execution, remote denial of service, and a breach of data confidentiality.
CSIRTS triage
- What
- Multiple vulnerabilities allow for remote arbitrary code execution, denial of service, and data confidentiality breaches.
- Who is affected
- Deployments of Tenable Identity Exposure.
- Urgency
- Remediation is urgent due to the critical nature of the vulnerabilities and potential exploitation.
- Action
- Update to the latest version of Tenable Identity Exposure.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Identity Exposure
Get an email when a new Identity Exposure advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0796/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2025-661990.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-427890.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-216371.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 63% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-341801.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 60% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-552480.67% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 49% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-351880.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-427661.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 61% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-90760.62% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 47% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-154690.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-19650.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Apple macOS, iOS and iPadOS: Multiple vulnerabilitiescert-bund
- medium[UPDATE] [medium] Erlang/OTP: Multiple vulnerabilities allow bypassing security measurescert-bund
- unknownDSA-6464-1 erlang - security updatedebian
- medium[UPDATE] [medium] OpenSSL: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] OpenSSL: Multiple Vulnerabilitiescert-bund
- high[UPDATE] [high] cURL: Multiple vulnerabilitiescert-bund
- unknownNCSC-2026-0319 [1.00] [M/H] Vulnerabilities resolved in Apple iOS and iPadOSncsc-nl
- unknownMultiple vulnerabilities in Splunk products (20 August 2026)cert-fr-avis
- high[NEW] [high] IBM App Connect Enterprise: Multiple vulnerabilitiescert-bund
- medium[UPDATE] [medium] cURL: Multiple vulnerabilitiescert-bund
- medium[UPDATE] [medium] cURL: Multiple vulnerabilitiescert-bund
- unknownNCSC-2026-0307 [1.00] [M/H] Vulnerabilities resolved in Oracle Database Productsncsc-nl
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Keycloak (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in Cisco IOS XE (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in LibreNMS (August 24, 2026)2026-08-24
- unknownMultiple vulnerabilities in Metabase (August 24, 2026)2026-08-24
- unknownVulnerability in SPIP (August 21, 2026)2026-08-21