Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4356 articles · 196341 vulns · 36/41 feeds (7d)
← Back to list
9.9
CVE-2026-64879PATCHED
tenable · security center

Command Injection

Description

A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality.

Affected Products

VendorProductVersions
tenablesecurity center—

References

  • https://www.tenable.com/security/tns-2026-19

Related News (5 articles)

Tier B
CERT-FR14d ago
Bulletin d'actualité CERTFR-2026-ACT-034 (10 août 2026)
→ No new info (linked only)
Tier B
CERT-FR20d ago
Multiples vulnérabilités dans les produits Tenable (04 août 2026)
→ No new info (linked only)
Tier B
CERT-FR28d ago
Bulletin d'actualité CERTFR-2026-ACT-032 (27 juillet 2026)
→ No new info (linked only)
Tier C
VulDB33d ago
CVE-2026-64879 | Tenable Security Center up to 6.7.x Audit command injection
→ No new info (linked only)
Tier B
CERT-FR34d ago
Multiples vulnérabilités dans Tenable Security Center (21 juillet 2026)
→ No new info (linked only)
CVSS 3.19.9 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
0
CWECWE-78
PublishedJul 21, 2026
Last enriched33d agov2
Trending Score10
Source articles5
Independent2
Info Completeness10/14
Missing: epss, kev, exploit, iocs

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-19681
Command Injection
Trending: 11
CRITICALCVE-2026-19626
Remote Code Execution
Trending: 11
CRITICALCVE-2026-19682
Command Injection
Trending: 11
CRITICALCVE-2026-64878
Command Injection
Trending: 10
HIGHCVE-2026-19628
Remote Code Execution
Trending: 9

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 21, 2026
Discovered by ZDM
Jul 21, 2026
Updated: affectedVersions, mitreAttack
Jul 21, 2026
Patch Available
Jul 24, 2026

Version History

v2
Last enriched 33d ago
v2Tier C33d ago

Added affected version range 6.7.x and identified MITRE ATT&CK technique T1059 (Command and Scripting Interpreter) for command injection attack vector.

affectedVersionsmitreAttack
via VulDB
v133d ago

Initial creation