Multiple vulnerabilities in Tenable Security Center (July 21, 2026)
Multiple vulnerabilities have been discovered in Tenable Security Center. Some of them allow an attacker to cause remote arbitrary code execution, SQL injection (SQLi), and security policy bypass.
CSIRTS triage
- What
- Multiple vulnerabilities in Tenable Security Center allow for remote code execution and SQL injection.
- Who is affected
- Users and administrators of Tenable Security Center.
- Urgency
- Remediation is necessary to prevent potential exploitation, although the severity is unknown.
- Action
- Review the advisory and apply the necessary updates.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Tenable Security Center
Get an email when a new Tenable Security Center advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0905/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2025-661990.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-234791.4% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 70% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-64740.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-64720.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-154690.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-64790.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-72610.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-61040.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-694190.56% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-67350.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all EPSS-scored CVEs.
Referenced CVEs
+4 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [hoch] Apple macOS (Tahoe, Sonoma und Sequoia): Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] PostgreSQL: Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] Apache HTTP Server: Mehrere Schwachstellencert-bund
- unknownUSN-8571-2: Apache HTTP Server regressionubuntu
- high[UPDATE] [hoch] OpenSSL: Mehrere Schwachstellencert-bund
- unknownexploitedNCSC-2026-0346 [1.01] [M/H] Kwetsbaarheden verholpen in Siemens productenncsc-nl
- unknownUSN-8734-1: PHP vulnerabilitiesubuntu
- high[UPDATE] [hoch] PostgreSQL: Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] Splunk SOAR: Mehrere Schwachstellencert-bund
- medium[UPDATE] [medium] Redis: Multiple vulnerabilities allow execution of arbitrary program codecert-bund
- unknownNCSC-2026-0321 [1.00] [M/H] Meerdere kwetsbaarheden verholpen in IBM AIX en IBM PowerVM VIOSncsc-nl
- unknownexploitedMultiple vulnerabilities in IBM products (August 21, 2026)cert-fr-avis
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans Microsoft Edge (15 septembre 2026)2026-09-15
- unknownVulnérabilité dans Microsoft Windows (15 septembre 2026)2026-09-15
- unknownMultiples vulnérabilités dans les produits Cisco (15 septembre 2026)2026-09-15
- unknownMultiples vulnérabilités dans les produits Apple (15 septembre 2026)2026-09-15
- unknownMultiples vulnérabilités dans MongoDB (14 septembre 2026)2026-09-14