Multiple vulnerabilities in Tenable Security Center (July 21, 2026)
Multiple vulnerabilities have been discovered in Tenable Security Center. Some of them allow an attacker to cause remote arbitrary code execution, SQL injection (SQLi), and security policy bypass.
CSIRTS triage
- What
- Multiple vulnerabilities in Tenable Security Center allow for remote code execution and SQL injection.
- Who is affected
- Users and administrators of Tenable Security Center.
- Urgency
- Remediation is necessary to prevent potential exploitation, although the severity is unknown.
- Action
- Review the advisory and apply the necessary updates.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Tenable Security Center
Get an email when a new Tenable Security Center advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0905/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2025-661990.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all scored CVEs.
- Moderate exploitation riskCVE-2026-234791.3% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 67% of all scored CVEs.
- Low exploitation riskCVE-2026-64740.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all scored CVEs.
- Low exploitation riskCVE-2026-64720.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all scored CVEs.
- Low exploitation riskCVE-2025-154690.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all scored CVEs.
- Low exploitation riskCVE-2026-64790.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all scored CVEs.
- Low exploitation riskCVE-2026-72610.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all scored CVEs.
- Low exploitation riskCVE-2026-61040.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all scored CVEs.
- Low exploitation riskCVE-2025-694190.44% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all scored CVEs.
- Low exploitation riskCVE-2026-67350.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all scored CVEs.
Referenced CVEs
+4 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownMultiples vulnérabilités dans les produits IBM (31 juillet 2026)cert-fr-avis
- high[UPDATE] [high] PostgreSQL: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] PHP: Multiple vulnerabilitiescert-bund
- unknownF5 Products Multiple Vulnerabilitieshkcert
- criticalSiemens Desigo CCcisa
- high[UPDATE] [high] Oracle MySQL: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Solaris third-party components: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Apple macOS (Tahoe, Sonoma, and Sequoia): Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] Apache HTTP Server: Multiple vulnerabilitiescert-bund
- unknownNCSC-2026-0267 [1.00] [M/H] Vulnerabilities fixed in Apple MacOSncsc-nl
- unknownApple Products Multiple Vulnerabilitieshkcert
- medium[UPDATE] [medium] Redis: Multiple vulnerabilities allow execution of arbitrary program codecert-bund
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans le noyau Linux de Red Hat (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux d'Ubuntu (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux de SUSE (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux de Debian LTS (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans Progress MOVEit Transfer (31 juillet 2026)2026-07-31