Vulnerabilities · 60 days ago

Tenable Agent Flaw Can Undermine Managed Fleets

Tenable Agent sits on many endpoints, so a path traversal in that layer is more than a local bug. If the agent can be pushed to write outside its own plugin directory, an attacker can turn a patchable product flaw into persistent code execution on managed machines.

Tenable said it fixed CVE-2026-15265, a critical path traversal in Tenable Agent that may allow remote code execution. The same roundup also noted new patches from ESET, Tanium, and Trend Micro, and said there is no evidence of exploitation for these issues.

The main risk is not the individual host. It is the management plane you trust to stay clean, because compromise there can spread across the fleet and leave code running long after the original flaw is closed.

CVE-2026-15265

NVD KEV

CVSS 9.1 CRITICAL: a path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write… EPSS 0.6% (44th percentile).

Timeline

Sources

1 source covering this story

Entities

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-07-16

Editions

Related stories