
Critical Vulnerabilities Discovered in Tenable Security Center Allowing Remote Code Execution and SQL Injection
CybersecurityVulnerabilitiesExploitsSoftwareSecurity
Multiple vulnerabilities were discovered in Tenable Security Center on 21 July 2026, as reported by CERT-FR. The flaws enable attackers to execute arbitrary remote code, perform SQL injection (SQLi), and bypass security policies. No specific CVE identifiers, affected versions, or technical details about the exploitation mechanisms were provided in the notice. The vulnerabilities were disclosed via the French government’s cybersecurity agency (ANSSI) under advisory CERTFR-2026-AVI-0905. The impacts include potential unauthorized system access and manipulation of database queries. The source of the vulnerabilities is explicitly attributed to Tenable Security Center.