CVE-2026-15265: Tenable Nessus Agent

Critical severity, CVSS 9.1. EPSS: 0.6% chance of exploitation in the next 30 days.

A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitrary files outside the intended plugin directory, potentially leading to remote code execution.

Affected products

  • Tenable Nessus Agent: before 11.1.4 (fixed in 11.1.4); version 11.2.0 only

Published 2026-07-14. Last modified 2026-08-25.