Critical Vulnerabilities in Tenable Security Center Prompt Urgent Patch Release

Critical Vulnerabilities in Tenable Security Center Prompt Urgent Patch Release

First seen 21 Jul 2026, 16:27 UTC Tenablenvd.nist.gov 90% similarity 74.0

Article Content

Browse articles
ThreatCluster

Tenable has released Security Center Patch SC202607.1 to address multiple vulnerabilities in third-party components, including Apache, OpenSSL, PostgreSQL, PHP, and Redis. The patch resolves critical issues such as SQL Injection (CVE-2026-64877) and Command Injection (CVE-2026-64878). A total of six vulnerabilities were reported and addressed, with CVE-2026-64880 classified as high severity. Users are urged to upgrade to the latest versions of the affected libraries to mitigate potential risks. The vulnerabilities could allow unauthorized access or data manipulation, impacting systems using Tenable Security Center versions 6.6.0, 6.7.2, and 6.8.0. Timely application of this patch is crucial for maintaining security.

Key Points: • Tenable released a critical patch addressing multiple vulnerabilities in Security Center. • Key vulnerabilities include SQL Injection (CVE-2026-64877) and Command Injection (CVE-2026-64878). • Users are strongly advised to upgrade affected third-party components immediately.

ThreatCluster AI

Timeline

2026-07-20
Security Patch SC202607.1 released
Tenable issued a patch to address vulnerabilities in Security Center, affecting versions 6.6.0, 6.7.2, and 6.8.0.
Tenable
2026-07-21
CVE-2026-64877 published
A critical SQL Injection vulnerability was disclosed, affecting Security Center.
Tenable
2026-07-21
CVE-2026-64878 published
A critical Command Injection vulnerability was disclosed, affecting Security Center.
Tenable
2026-07-21
CVE-2026-64880 published
A high severity Blind SQL Injection vulnerability was disclosed, affecting Security Center.
Tenable

Community

Browse all →