CVE-2026-15265: exploitation status and patch state
CVE-2026-15265 · CVSS 9.1 CRITICAL · EPSS <1%
A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitrary files outside the intended plugin directory, potentially leading to remote code execution.
Is CVE-2026-15265 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at <1%.
Public exploit code: none found in monitored sources.