CVE-2026-19626: Tenable Security Center
Critical severity, CVSS 9.9. EPSS: 1.9% chance of exploitation in the next 30 days.
A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by supplying specially crafted input that is later processed unsafely during server-side report rendering, resulting in arbitrary code execution with the privileges of the service account.
Affected products
- Tenable Security Center: before 6.9.0 (fixed in 6.9.0)
Published 2026-08-14. Last modified 2026-08-19.