{"record":"Tenable evidence record","url":"https://nexalign.io/vendors/tenable","vendor":{"slug":"tenable","name":"Tenable","domain":"tenable.com","category":"grc","categoryLabel":"Governance, risk and compliance"},"lastChecked":"2026-07-18T10:19:36.829Z","coverage":{"earliest":"2022-10-24T21:12:00.000Z","latest":"2026-07-18T10:19:36.829Z"},"terms":{"isRanking":false,"isRating":false,"statesSuitability":false,"note":"This is a record of what public sources hold about a named company. It states no ranking, no rating and no suitability verdict, and none may be derived from it. An absent or small record means the public registers publish little under that name; it is not evidence that a product is secure. A larger advisory count generally reflects wider deployment and more scrutiny rather than a weaker product.","licence":"https://nexalign.io/vendors#licence","corrections":"info@nexalign.io"},"totals":{"evidenceItems":70,"kindsOfSource":5,"attributedAdvisories":56,"knownExploited":0,"registerEntriesNotAttributable":0,"practitionerThreads":1,"independentItems":6,"vendorPublishedItems":0,"shareFromSourcesTheVendorDoesNotControl":1},"sources":[{"source":"European Vulnerability Database","operator":"ENISA, European Union","classification":"authoritative","items":29,"latest":"2026-07-14T15:02:37.000Z"},{"source":"CERT-Bund security advisories","operator":"BSI, Federal Republic of Germany","classification":"authoritative","items":27,"latest":"2026-07-15T10:31:40.204Z"},{"source":"Analyst, review and reference sources","operator":"Recognised analysts, review marketplaces and technology press","classification":"independent","items":7,"latest":"2026-07-18T10:19:36.829Z"},{"source":"Engineering discussions","operator":"Hacker News, public threads","classification":"independent","items":5,"latest":"2026-04-22T16:14:32.000Z"},{"source":"Practitioner discussions","operator":"Reddit, public threads","classification":"independent","items":2,"latest":"2026-05-09T14:19:42.000Z"}],"advisories":{"shown":6,"total":56,"truncated":true,"fullList":"https://nexalign.io/vendors/tenable/advisories","items":[{"id":"WID-SEC-2026-2351","description":"Affected products: Tenable Security Nessus","severity":"high","cvss":9.1,"knownExploited":false,"date":"2026-07-15T10:31:40.204Z","sources":["https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2351"]},{"id":"CVE-2026-15265","description":"A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitrary files outside the intended plugin directory, potentially leading…","severity":"critical","cvss":9.3,"knownExploited":false,"date":"2026-07-14T15:02:37.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43701"]},{"id":"WID-SEC-2026-2086","description":"Affected products: Tenable Security Nessus","severity":"medium","cvss":5.3,"knownExploited":false,"date":"2026-06-26T11:11:31.686Z","sources":["https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2086"]},{"id":"CVE-2026-57587","description":"A SQL injection vulnerability in Nessus allows a remote, unauthenticated attacker who controls reverse DNS records for a scanned host to inject malicious SQL into the scan results database…","severity":"low","cvss":2.1,"knownExploited":false,"date":"2026-06-25T13:47:27.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-39408"]},{"id":"CVE-2026-57588","description":"A SQL injection vulnerability in Nessus allows an attacker to craft a malicious scan result file that, when imported by a privileged user, injects malicious SQL into the scan results…","severity":"low","cvss":1.6,"knownExploited":false,"date":"2026-06-25T13:47:27.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-39409"]},{"id":"CVE-2026-13007","description":"Tenable Identity Exposure contains multiple unauthenticated API endpoints under /w/api/* that expose sensitive application configuration data including cleartext LDAP credentials, SAML…","severity":"high","cvss":8.5,"knownExploited":false,"date":"2026-06-23T15:59:50.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-38487"]}]},"practitionerThreads":{"shown":1,"total":1,"truncated":false,"items":[{"title":"Cybersecurity firm Tenable's CEO Amit Yoran dies after battle with cancer","context":"Hacker News","url":"https://news.ycombinator.com/item?id=42599545","date":"2025-01-05T03:33:10.000Z"}]},"independentCoverage":{"shown":5,"total":6,"truncated":true,"items":[{"title":"Tenable Cloud Security Reviews & Ratings 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/product/tenable-cloud-security","date":null},{"title":"Tenable, Inc. - Wikipedia","host":"en.wikipedia.org","url":"https://en.wikipedia.org/wiki/Tenable,_Inc.","date":null},{"title":"Tenable Reviews, Ratings & Features 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/vulnerability-assessment/vendor/tenable","date":null},{"title":"What is your primary use case for Tenable SC?","host":"peerspot.com","url":"https://www.peerspot.com/questions/what-is-your-primary-use-case-for-tenable-sc","date":null},{"title":"Tenable Vulnerability Management Features | G2","host":"g2.com","url":"https://www.g2.com/products/tenable-vulnerability-management/features","date":null}]},"vendorPublished":{"shown":0,"total":0,"truncated":false,"items":[]},"openQuestions":["Pricing, contract terms, notice periods and support commitments are not part of any public register. They come from the vendor and belong in a negotiation record.","Certification status such as ISO 27001, SOC 2 or BSI C5 has to be checked against the current certificate and its stated scope. A valid certificate can still exclude the product being bought."]}