CVE-2026-33694Disclosure(tenable / nessus)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch tenable nessus systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

This vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privileges. As a result, this condition potentially facilitates arbitrary code execution, whereby an attacker may exploit the vulnerability to execute malicious code with elevated SYSTEM privileges.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-59

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nessus
  • nessus_agent

Threat summary

  • Patch or workaround signal is available
  • 10 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • General: 3 classified signals
  • Peaked 5d ago at 2 mentions (2026-04-24); latest day: 1
  • 10 total mentions across 7 days

Affected systems

Vendors
Products
nessusnessus_agent

Deep dive

Activity timeline10 mentions / 7d
01122Mentions · 2026-04-23: 1Mentions · 2026-04-24: 2Mentions · 2026-04-26: 1Mentions · 2026-04-27: 2Mentions · 2026-04-28: 2Mentions · 2026-04-29: 1Mentions · 2026-05-07: 1Patch / Workaround · 2026-04-24: 2Patch / Workaround · 2026-04-26: 1Patch / Workaround · 2026-04-27: 1Technical Details · 2026-04-23: 1Technical Details · 2026-04-24: 2Technical Details · 2026-04-26: 1Technical Details · 2026-04-27: 1Technical Details · 2026-04-28: 1Technical Details · 2026-05-07: 104-2304-2404-2604-2704-2804-2905-07
Signal classification3 categories
Disclosure
440.0%
Patch
330.0%
General
330.0%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-04-231
Disclosure1
2026-04-242
Disclosure1Patch1
2026-04-261
Patch1
2026-04-272
General1Patch1
2026-04-282
Disclosure1General1
2026-04-291
General1
2026-05-071
Disclosure1
Full discourse10 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    🚨 الأداة الي المفروض تكتشف الثغرات اكتشف فيها ثغرة تسبب اختراق النظام كامل اكتشف Tenable Nessus ثغرة خطيرة تسمح للمهاجم بحذف ملفات (System32) ورفع صلاحياته لـ SYSTEM! رقم الثغرة: CVE-2026-33694 | التقييم: 7.4 (High). التفاصيل التقنية : 🧵👇 1/4 https://t.co/2mdwc1ht50

    Post summary

    Tenable Nessus identified CVE-2026-33694, a high‑severity flaw that permits an attacker to delete System32 files and elevate privileges to SYSTEM, but no PoC, exploit code, or active exploitation is reported.

    35035236.9K
    49.3K followersView on X
  • cheddar@cheddar420yolo
    General

    @The_Cyber_News May I assume this refers to CVE-2026-33694 since that detail is omitted for some reason? https://www.cve.org/CVERecord?id=CVE-2026-33694

    Post summary

    The tweet merely questions whether a CVE refers to a specific identifier, providing no substantive details about the vulnerability, exploitation, or mitigation.

    00040655
    1.7K followersView on X
  • Elusive@ElusivePrivacy
    Patch

    🛡️ Two security vendors patched serious flaws in their own products this week. CrowdStrike: CVE-2026-40050, a critical unauthenticated path traversal in LogScale — remote attackers could read arbitrary server files. Self-hosted customers need to update. Tenable: CVE-2026-33694, a high-severity Nessus flaw on Windows allowing arbitrary file deletion and code execution with elevated privileges. 📄 Source: SecurityWeek 👉 Follow @VulnerabilityNw — patch tracking on our Telegram → http://t.me/VulnerabilityNews

    Post summary

    The note reports that CrowdStrike and Tenable have released patches for CVE‑2026‑40050 and CVE‑2026‑33694, outlining their severity and urging users to update.

    02020172
    185 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: High arbitrary code execution vulnerability in #Nessus (agent). #CVE-2026-33694 CVSS: 7.4. This can lead malicious code execution with SYSTEM privileges. https://ccb.belgium.be/advisories/warning-arbitrary-code-execution-vulnerability-nessus-can-be-exploited-elevate #Patch #Patch #Patch

    Post summary

    An advisory was issued for CVE‑2026‑33694, highlighting an arbitrary code execution flaw in Nessus agents, and it explicitly states that a patch is available.

    01001243
    7.2K followersView on X
  • Autumn Good@autumn_good_35
    Patch

    Security Advisory | Tenable® CVE ID: CVE-2026-33694 Risk Factor: High [R1] Nessus Agent Version 11.1.3 Fixes Arbitrary File Deletion https://www.tenable.com/security/tns-2026-12 [R1] Nessus Versions 10.11.4 and 10.12.0 Fixes Arbitrary File Deletion https://www.tenable.com/security/tns-2026-13

    Post summary

    Tenable issued a security advisory for CVE‑2026‑33694, highlighting a high‑risk arbitrary file deletion flaw and providing links to patches for relevant Nessus products.

    00011575
    6.8K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Nessus Agent の脆弱性 CVE-2026-33694 が FIX:Windows Junction の悪用と SYSTEM 権限取得 https://iototsecnews.jp/2026/04/27/nessus-agent-vulnerability-on-windows-enables-arbitrary-code-execution-with-system-privileges/ この脆弱性の原因は、Windows のファイル・システムが持つ Junction というリダイレクト機能を、Nessus Agent のような高い権限を持つサービスが適切に検証せずに処理してしまったことにあります。攻撃者はこの仕組みを悪用して、本来は触れることのできない重要なシステムファイルを削除対象へとすり替えます。その結果としてシステムが破壊され、最終的には OS の最高権限である SYSTEM 権限で不正なコードが実行されてしまいます。ご利用のチームは、十分にご注意ください。 #CVE202633694 #NessusAgent #Tenable #Vulnerability

    Post summary

    The article announces CVE‑2026‑33694, describing how Nessus Agent can exploit Windows Junction to gain SYSTEM privileges. No exploit code, active attacks, or patches are mentioned.

    0100087
    487 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidad en productos Tenable ❗ CVE-2026-33694 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-tenable-4/ https://t.co/DsJ9HACNMf

    Post summary

    The post notes a Tenable product vulnerability (CVE-2026-33694) and directs readers to a link for more information, but it offers no actionable details about exploitation, patches, or technical aspects.

    00000140
    6.7K followersView on X
  • cybersecuritypath@cybrsecpath
    General

    Nessus Agent Flaw CVE-2026-33694 Lets Attackers Get SYSTEM Access https://thecybrdef.com/nessus-agent-cve-2026-33694-system-access-vulnerability/

    Post summary

    The snippet alerts to the existence of CVE‑2026‑33694 in Nessus Agent and links to a source, but offers no further technical or mitigation information.

    0000052
    7 followersView on X
  • ThreatLevel@ThreatLevelAI
    Disclosure

    ⚫ Planned Fix LPE → RCE in Tenable Nessus 🔍 Details • Authentication needed • Deployment: Typically internal • Exploitable with default configuration • No active exploitation • No public PoC CVE-2026-33694 full analysis 👇 https://threatlevel.io/CVE-2026-33694?utm_source=x&utm_campaign=NC60IxLl

    Post summary

    CVE-2026-33694 is a local privilege escalation turning into a remote code execution vulnerability in Tenable Nessus requiring authentication and typically deployed internally; no exploitation or PoC is known, but a fix is planned.

    00000101
    6 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33694 This vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privileges. As a result, this condition potentially f… https://www.cve.org/CVERecord?id=CVE-2026-33694

    Post summary

    The entry reports that CVE-2026-33694 lets an attacker create a junction to delete arbitrary files as SYSTEM, but does not provide PoC, exploit code, active exploitation, or patch information.

    00000116
    57.2K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apptenablenessus---
Apptenablenessus_agent---

Explore more