CVE-2026-15265(tenable / nessus_agent)

LOWCVSS 9.4 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitrary files outside the intended plugin directory, potentially leading to remote code execution.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-22CWE-347

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nessus_agent

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Affected systems

Vendors
Products
nessus_agent

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-28: 109-28
Full discourse1 post
  • Michael Petychakis@mpetyx

    September 2026 tech watchlist. The stuff that actually matters if you run Kubernetes, Postgres, Spring or a GraphQL gateway. Spring dropped a mass CVE batch on 20 Aug. One CRITICAL (CVE-2026-59270, embedded LDAP server exposes admin bind). Fixes for Boot 3.x / Framework 6.x are Enterprise-only. If you're on Boot 3.5 with open source, you are unpatched. Move to Boot 4.1. PostgreSQL 18.6 / 17.11 fix 28 CVEs, the biggest batch ever. Twelve are CVSS 8.8 code execution. One is PG18-only in pg_stat_statements. Also: PG14 stops getting fixes on 12 Nov 2026. GitLab CVE-2026-19478, CVSS 9.4. Unauthenticated code injection via a GraphQL directive. Affects 18.2 to 19.2.3. Patch to 19.2.4+. "ChainDrop" npm worm (4 Aug). 400+ packages republished with malicious preinstall hooks: keyv, cacheable-request, cache-manager, flat-cache. It spread through GitHub Actions trusted publishing, so the packages had valid provenance. Check your lockfiles. AI coding tools got hit too. Claude Code CVE-2026-54316 (CVSS 9.1, fixed 2.1.163). Gemini CLI CVE-2026-12537 (CVSS 10.0). Cursor CVE-2026-15265 (git.exe planting in repo root). Pin versions in CI. Kubernetes 1.37 is out (pod-level resources, Pod Certificates GA). 1.34 hits EOL on 28 Oct. Gateway API 1.6 moved TCPRoute/UDPRoute to Standard, useful if you're still replacing Ingress NGINX. Apollo Federation 2.15 composition is Rust-only and needs Router 2.16+. Apollo Gateway is frozen at 2.14. If you're on Gateway, the migration clock is running. GitHub Copilot Business/Enterprise moves to upfront seat payment. Existing customers from 1 Oct. Six models deprecated on 1 Sep (Opus 4.5/4.6, Sonnet 4.5/4.6, Gemini 3.1 Pro, Raptor Mini). Amazon OpenSearch Service reset its lifecycle: OpenSearch 1.3 and 2.11-2.19 lose standard support on 7 Nov 2027. Legacy versions on Extended Support pay 2x compute from 7 Nov 2026. M&A: Cursor acquired by SpaceX. AWS acquiring DuckLabs (DuckDB stays MIT). CrowdStrike Falcon coming to the Anthropic Claude Marketplace. Also: Rails 7.2 security support ended 9 Aug. Hanami 3.0 is GA (needs Ruby 3.3+). Node 24 goes to Maintenance on 20 Oct. Grafana 13.2 deprecates scripted dashboards. Three decisions I'm making this month: Spring 4.1 as the floor for new Kotlin services, a PG14 exit date, and Router 2.16 LTS over Gateway.

    10010157
    3.9K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apptenablenessus_agent---
Apptenablenessus_agent11.2.0--

Explore more