Our takeTenable released a patch for critical vulnerabilities in Security Center 6.6.0–6.8.0. Update now if you self-host it (some enterprises); most smaller teams use the hosted Tenable.io or Vulnerability Management and can ignore this one.Cyber Resilience desk
Sources (13)
- cccs · cccs
- cisa_kev · cisa_kev
- cisa_advisories · cisa_advisories
- cccs · cccs
- cccs · cccs
- cccs · cccs
- cccs · cccs
- cccs · cccs
- cccs · cccs
- hackernews · hackernews
- bleeping · bleeping
- securityweek · securityweek
- helpnet · helpnet
What this means for you — Security leader:Tenable Security Center 6.6.0–6.8.0 has critical flaws per AV26-724; patch is available now. Prioritize this if SC feeds your vuln-management workflow — it's a high-value target sitting on top of your asset inventory.
What this means for you — Lean IT orgs:If you use Tenable Security Center to scan your network, update it now — this tool sees everything on your network, so a hole in it is a hole in your visibility. Most lean-IT shops use Tenable's cloud product instead and aren't affected.
What this means for you — MSP:Flag any client running self-hosted Tenable Security Center (6.6.0–6.8.0) and push the patch across the fleet; cloud-hosted Tenable.io/Tenable.sc-as-a-service clients aren't exposed.
What this means for you — Researcher:AV26-724: critical vulnerabilities in Tenable Security Center 6.6.0–6.8.0, patch available July 20, 2026 — CVE details and exploitability not yet broken out in the advisory.