Tenable Security Updates – 26 April 2026

Tenable has released security updates to address several vulnerabilities across multiple Tenable products.

The addressed vulnerabilities could allow the attacker to obtain sensitive information, enable the deletion of arbitrary files with SYSTEM privileges, or execute arbitrary code and gain access to the affected systems.

Sample of addressed vulnerabilities:

1. Tenable Nessus Agent Arbitrary File Deletion Vulnerability (CVE-2026-33694):

  • CVSS: 8.2
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: Required
  • Consequences: Gain Access

2. Tenable-OT-platform Information Disclosure Vulnerability (CVE-2026-4433):

  • CVSS: 5.4
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Obtain Information

Sample of the affected products:

  • Tenable OT Platform 4.2.40 and earlier.
  • Nessus Agent 11.1.2 and earlier.
  • Nessus 10.11.3 and earlier.
Vulnerabilities
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Tenable Security Updates

References