| CVE-2026-19682 | critical | 9.9 | A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker… | Aug 14, 2026 | Aug 19, 2026 |
| CVE-2026-19681 | critical | 9.9 | An authenticated command injection vulnerability exists in Security Center related to file upload pr… | Aug 14, 2026 | Aug 19, 2026 |
| CVE-2026-19680 | high | 7.1 | A SQL injection vulnerability exists in Security Center that could allow an attacker to access unaut… | Aug 14, 2026 | Aug 19, 2026 |
| CVE-2026-19679 | high | 8.8 | An input validation vulnerability exists in Security Center's file upload handling, where insufficie… | Aug 14, 2026 | Aug 19, 2026 |
| CVE-2026-19639 | medium | 4.3 | An improper access control vulnerability exists where an authenticated non-administrative applicatio… | Aug 14, 2026 | Aug 19, 2026 |
| CVE-2026-19636 | medium | 5.3 | An issue was identified in which CSRF tokens were generated using a predictable method, potentially … | Aug 14, 2026 | Aug 19, 2026 |
| CVE-2026-19635 | high | 8.8 | A local privilege escalation vulnerability exists in Security Center. An attacker with write access … | Aug 14, 2026 | Aug 19, 2026 |
| CVE-2026-19631 | medium | 4.9 | A SQL injection vulnerability exists in Security Center that could allow an authenticated administra… | Aug 14, 2026 | Aug 19, 2026 |
| CVE-2026-19629 | high | 8.1 | A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Secu… | Aug 14, 2026 | Aug 19, 2026 |
| CVE-2026-19628 | high | 7.2 | A command injection vulnerability exists in Tenable Security Center. An authenticated administrator … | Aug 14, 2026 | Aug 19, 2026 |
| CVE-2026-19626 | critical | 9.9 | A remote code execution vulnerability exists in Tenable Security Center's report generation function… | Aug 14, 2026 | Aug 19, 2026 |
| CVE-2026-18667 | critical | 9.6 | A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privi… | Aug 3, 2026 | Aug 5, 2026 |
| CVE-2026-64881 | high | 8.8 | The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow int… | Jul 21, 2026 | Aug 18, 2026 |
| CVE-2026-64880 | high | 7.1 | Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL que… | Jul 21, 2026 | Aug 18, 2026 |
| CVE-2026-64879 | critical | 9.9 | A filename supplied during file upload is not properly sanitized before being used in system command… | Jul 21, 2026 | Aug 18, 2026 |
| CVE-2026-64878 | critical | 9.9 | Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument … | Jul 21, 2026 | Aug 18, 2026 |
| CVE-2026-64877 | high | 8.4 | An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access… | Jul 21, 2026 | Aug 18, 2026 |
| CVE-2026-15265 | critical | 9.1 | A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged atta… | Jul 14, 2026 | Aug 25, 2026 |
| CVE-2026-57588 | low | 3.3 | A SQL injection vulnerability in Nessus allows an attacker to craft a malicious scan result file tha… | Jun 25, 2026 | Jun 26, 2026 |
| CVE-2026-57587 | medium | 5.3 | A SQL injection vulnerability in Nessus allows a remote, unauthenticated attacker who controls rever… | Jun 25, 2026 | Jun 26, 2026 |
| CVE-2026-13007 | high | 7.5 | Tenable Identity Exposure contains multiple unauthenticated API endpoints under /w/api/* that expose… | Jun 23, 2026 | Aug 19, 2026 |
| CVE-2026-47358 | high | 7.5 | Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL re… | May 19, 2026 | Jul 24, 2026 |
| CVE-2026-47357 | high | 7.5 | Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url … | May 19, 2026 | Jul 24, 2026 |
| CVE-2026-47356 | high | 7.5 | Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url… | May 19, 2026 | Jul 24, 2026 |
| CVE-2026-33694 | high | 7.8 | This vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files… | Apr 23, 2026 | Aug 21, 2026 |