CVE-2025-36640: Tenable Nessus Agent

High severity, CVSS 8.8. EPSS: 0.1% chance of exploitation in the next 30 days.

A vulnerability has been identified in the installation/uninstallation of the Nessus Agent Tray App on Windows Hosts which could lead to escalation of privileges.

Affected products

  • Tenable Nessus Agent: before 10.9.3 (fixed in 10.9.3); from 11.0.0, before 11.0.2 (fixed in 11.0.2)

Published 2026-01-13. Last modified 2026-06-17.