CVE-2026-19681Disclosure(tenable / security_center)

LOWCVSS 9.4 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by uploading a specially crafted file, potentially resulting in arbitrary command execution on the underlying operating system.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • security_center

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
security_center

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-14: 3Technical Details · 2026-08-14: 308-14
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-19681 Authenticated Command Injection in Security Center File Upload https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-19681

    Post summary

    The text announces CVE-2026-19681, describing it as an authenticated command injection vulnerability in a file upload feature of Security Center, without detailing exploit code, active attacks, or mitigation steps.

    00000148
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-19681 An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by uploading a spec… https://www.cve.org/CVERecord?id=CVE-2026-19681 ----- Traducción: CVE-2026-19681 Exi… https://infoflow.cloud`

    Post summary

    The post discloses an authenticated command injection flaw in Security Center’s file upload handling; no PoC, exploit code, patch, or evidence of active exploitation is provided.

    0000034
    98 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-19681 An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by uploading a spec… https://www.cve.org/CVERecord?id=CVE-2026-19681

    Post summary

    The post announces CVE‑2026‑19681 as an authenticated command‐injection flaw in Security Center’s file upload process, but offers no proof of concept, tool, or mitigation details.

    000001.5K
    58.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptenablesecurity_center---

Explore more