Tenable Security Updates – 15 July 2026

Tenable has released security updates to address several vulnerabilities across Nessus, Nessus Agent, and Tenable Identity Exposure.

The addressed vulnerabilities could allow the attacker to perform SQL injection attacks, obtain sensitive information, or execute arbitrary code on the affected systems.

Sample of addressed vulnerabilities:

1. Tenable Nessus Agent Path Traversal Vulnerability (CVE-2026-15265):

  • CVSS: 9.1
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: High
  • User Interaction: None
  • Consequences: Remote Code Execution

2. Tenable Identity Exposure Information Disclosure Vulnerability (CVE-2026- 13007):

  • CVSS: 7.5
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Obtain Information
Vulnerabilities
  • CVE-2026-13007
  • CVE-2026-15265
  • CVE-2026-57587
  • CVE-2026-57588
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Tenable Security Updates

References