Tenable Security Center Multiple Vulnerabilities (TNS-2026-19)

critical Nessus Plugin ID 328966

Synopsis

An instance of Security Center installed on the remote system is affected by multiple vulnerabilities.

Description

According to its self-reported version, the Tenable Security Center running on the remote host is between 6.6.0 and 6.8.0. It is, therefore, affected by multiple vulnerabilities as referenced in the TNS-2026-19 advisory.

- Tenable Security Center is affected by a SQL injection vulnerability. (CVE-2026-64877)

- Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue. (CVE-2026-23918)

- Stack buffer overflow in PostgreSQL module refint allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a refint cascade primary key and facilitates user- controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. (CVE-2026-6637)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Apply security patch SC-202607.1 or later.

See Also

https://www.tenable.com/security/TNS-2026-19

http://www.nessus.org/u?d5587a0b

Plugin Details

Severity: Critical

ID: 328966

File Name: securitycenter_6_8_0_tns_2026_19.nasl

Version: 1.2

Type: Combined

Agent: unix

Family: Misc.

Published: 7/22/2026

Updated: 7/23/2026

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.9

Percentile: 99.36

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-7261

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: Critical

Base Score: 9.5

Threat Score: 9

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

CVSS Score Source: CVE-2026-6722

Vulnerability Information

CPE: cpe:/a:tenable:security_center

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/20/2026

Vulnerability Publication Date: 4/9/2024

Reference Information

CVE: CVE-2025-11187, CVE-2025-14179, CVE-2025-15467, CVE-2025-15468, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-2003, CVE-2026-2004, CVE-2026-2005, CVE-2026-2006, CVE-2026-22795, CVE-2026-22796, CVE-2026-23918, CVE-2026-24072, CVE-2026-33523, CVE-2026-33857, CVE-2026-34032, CVE-2026-34059, CVE-2026-42371, CVE-2026-6104, CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479, CVE-2026-64877, CVE-2026-64878, CVE-2026-64879, CVE-2026-64880, CVE-2026-64881, CVE-2026-6637, CVE-2026-6638, CVE-2026-6722, CVE-2026-6735, CVE-2026-7258, CVE-2026-7259, CVE-2026-7261, CVE-2026-7262, CVE-2026-7263, CVE-2026-7568