CVE-2026-64881: Tenable Security Center
High severity, CVSS 8.8. EPSS: 2.2% chance of exploitation in the next 30 days.
The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation failure enables command injection when chained with a related vulnerability.
Affected products
- Tenable Security Center: from 6.6.0, up to and including 6.8.0
Published 2026-07-21. Last modified 2026-08-18.