LIVE · cybersecurity feed
Live wire
vendor

Tenable

18 CVEs published in the last four months and 1 stories. Exploited flaws first.

Critical6
High12
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-648789.9criticalsecurity centerUnvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resu46d ago
CVE-2026-196829.9criticalsecurity centerA command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit22d ago
CVE-2026-196819.9criticalsecurity centerAn authenticated command injection vulnerability exists in Security Center related to file upload processing.22d ago
CVE-2026-196269.9criticalsecurity centerA remote code execution vulnerability exists in Tenable Security Center's report generation functionality.22d ago
CVE-2026-648799.9criticalsecurity centerA filename supplied during file upload is not properly sanitized before being used in system command execution, al46d ago
CVE-2026-152659.1criticalnessus agentA path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write 53d ago
CVE-2026-648818.8highsecurity centerThe audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system comma46d ago
CVE-2026-196358.8highsecurity centerA local privilege escalation vulnerability exists in Security Center.22d ago
CVE-2026-196798.8highsecurity centerAn input validation vulnerability exists in Security Center's file upload handling, where insufficient sanitizatio22d ago
CVE-2026-648778.4highsecurity centerAn authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive dat46d ago
CVE-2026-196298.1highsecurity centerA privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" 22d ago
CVE-2026-473567.5highterrascanTerrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url parameter in 109d ago
CVE-2026-130077.5highidentity exposureTenable Identity Exposure contains multiple unauthenticated API endpoints under /w/api/* that expose sensitive app74d ago
CVE-2026-473587.5highterrascanTerrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in up109d ago
CVE-2026-473577.5highterrascanTerrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in t109d ago
CVE-2026-196287.2highsecurity centerA command injection vulnerability exists in Tenable Security Center.22d ago
CVE-2026-648807.1highsecurity centerUnsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without p46d ago
CVE-2026-196807.1highsecurity centerA SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data f22d ago

Filter the full tracker by Tenable

Our coverage of Tenable

ransomwarecritical

Detecting cloud ransomware in Azure with Tenable One’s cloud detection and response capabilities

Learn how Tenable One Cloud Exposure helps you unmask the sophisticated tactics of cybercrime group Storm-0501, which carries out Azure-based cloud ransomware campaigns. Tenable One Cloud Exposure uses AI-powered threat stories to expose Storm-0501 TTPs, backed by precision-engineered threat detection alerts. Key takeaways Storm-0501 demonstrates that cloud-first ransomware groups have shifted fro