Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4508 articles · 223853 vulns · 37/41 feeds (7d)
← Back to list
9.9
CVE-2026-19626PATCHED
tenable · security_center

Remote Code Execution

Description

A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by supplying specially crafted input that is later processed unsafely during server-side report rendering, resulting in arbitrary code execution with the privileges of the service account.

Affected Products

VendorProductVersions
tenablesecurity_center0

References

  • https://www.tenable.com/security/tns-2026-22(vendor-advisory)

Related News (4 articles)

Tier B
CERT-FR21d ago
Bulletin d'actualité CERTFR-2026-ACT-038 (07 septembre 2026)
→ No new info (linked only)
Tier B
CERT-FR28d ago
Multiples vulnérabilités dans les produits Tenable (31 août 2026)
→ No new info (linked only)
Tier C
VulDB44d ago
CVE-2026-19626 | Tenable Security Center up to 6.8.x Report Generation code injection
→ No new info (linked only)
Tier B
CERT-FR45d ago
Multiples vulnérabilités dans Tenable Security Center (14 août 2026)
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.9 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
6.9.0
CWECWE-95
PublishedAug 14, 2026
Trending Score5
Source articles4
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-18667
Sensor Proxy Version 1.4.2 Fixes One Vulnerability
Trending: 6
HIGHCVE-2026-19628
Remote Code Execution
Trending: 2
CRITICALCVE-2026-19681
Command Injection
CRITICALCVE-2026-19682
Command Injection
CRITICALCVE-2026-64878
Command Injection

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 14, 2026
Discovered by ZDM
Aug 14, 2026
Patch Available
Aug 15, 2026