Back Scworld CrowdStrike and Tenable address critical vulnerabilities in security products
Security Week reports that two major cybersecurity firms, CrowdStrike and Tenable, have recently informed their customers significant vulnerabilities discovered and subsequently patched within their product offerings.
CrowdStrike issued an advisory for CVE-2026-40050, a critical unauthenticated path traversal vulnerability impacting its LogScale product. This flaw could permit a remote attacker to read arbitrary files from the server. While -Gen SIEM customers are unaffected and LogScale SaaS users have had the vulnerability mitigated, self-hosted LogScale customers are urged to update to a patched version. CrowdStrike stated the vulnerability was found internally with no evidence of exploitation in the wild.
Concurrently, Tenable published advisories for CVE-2026-33694, a high-severity vulnerability affecting its Nessus vulnerability scanner on Windows. This issue could allow an attacker to delete arbitrary files with System privileges or execute arbitrary code.
Source: Security Week
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
