Synopsis
Security Center leverages third-party software to help provide underlying functionality. Several of the third-party components (apache, OpenSSL, postgreSQL, PHP, redis) were found to contain vulnerabilities, and updated versions have been made available by the providers.
Out of caution and in line with best practice, Tenable has opted to upgrade these libraries to address the potential impact of the issues. Security Center Patch SC202607.1 updates the following components:
- postgresql to version 16.14
- Apache to version 2.4.67
- OpenSSL to version 3.5.4
- PHP to version 8.2.31
- redis to version 8.2.6 (6.7.x and 6.8.0 only)
Additionally, several vulnerabilities were reported to Tenable and addressed within this patch. Please see the full list of resolved issues below.
Security Center - SQL Injection CVE-2026-64877 Critical 9.6 9.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N/E:P/RL:U/RC:C Security Center - Command Injection CVE-2026-64878 Critical 9.0 9.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:ND/RL:ND/RC:C Security Center - Command Injection CVE-2026-64879 Critical 9.0 9.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:ND/RL:ND/RC:C Security Center - Blind SQL Injection CVE-2026-64880 High 7.1 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N/E:ND/RL:ND/RC:C Security Center - Improper File Validation CVE-2026-64881 High 8.8 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:ND/RL:ND/RC:C Apache HTTP Server CVE-2026-23918 High 8.8 7.9 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Apache HTTP Server CVE-2026-24072 High 8.8 7.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Apache HTTP Server CVE-2026-33523 Medium 6.5 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Apache HTTP Server CVE-2026-33857 Medium 5.3 4.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Apache HTTP Server CVE-2026-34032 Medium 5.3 4.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Apache HTTP Server CVE-2026-34059 High 7.5 6.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N OpenSSL CVE-2025-11187 Medium 6.1 5.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H OpenSSL CVE-2025-15467 High 8.1 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H OpenSSL CVE-2025-15468 Medium 5.9 4.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H OpenSSL CVE-2025-15469 Medium 5.5 4.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N OpenSSL CVE-2025-66199 Medium 5.9 4.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H OpenSSL CVE-2025-68160 Medium 4.7 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H OpenSSL CVE-2025-69418 Medium 4 3.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N OpenSSL CVE-2025-69419 High 7.4 6.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N OpenSSL CVE-2025-69420 High 7.5 6.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H OpenSSL CVE-2025-69421 High 7.5 6.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H OpenSSL CVE-2026-22795 Medium 5.5 4.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H OpenSSL CVE-2026-22796 Medium 5.3 4.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L PHP CVE-2026-7568 Low 3.3 2.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N PHP CVE-2026-7263 Low 3.3 2.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N PHP CVE-2026-7259 Medium 5.5 4.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H PHP CVE-2026-7262 Medium 5.5 4.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H PHP CVE-2026-7258 Medium 5.5 4.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H PHP CVE-2026-6104 Medium 5.5 4.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H PHP CVE-2026-42371 Medium 5.5 4.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H PHP CVE-2026-6735 Medium 6.1 5.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N PHP CVE-2025-14179 Medium 6.5 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N PHP CVE-2026-7261 Medium 6.5 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H PHP CVE-2026-6722 High 8.1 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H PostgreSQL CVE-2026-2003 Medium 4.3 3.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N PostgreSQL CVE-2026-2004 High 8.8 7.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H PostgreSQL CVE-2026-2005 High 8.8 7.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H PostgreSQL CVE-2026-2006 High 8.8 7.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H PostgreSQL CVE-2026-6472 Medium 5.4 4.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N PostgreSQL CVE-2026-6473 High 8.8 7.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H PostgreSQL CVE-2026-6474 Medium 4.3 3.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N PostgreSQL CVE-2026-6475 High 8.8 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H PostgreSQL CVE-2026-6477 High 8.8 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H PostgreSQL CVE-2026-6478 Medium 6.5 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N PostgreSQL CVE-2026-6479 High 7.5 6.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H PostgreSQL CVE-2026-6637 High 8.8 7.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H PostgreSQL CVE-2026-6638 Low 3.7 3.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N Redis CVE-2026-23479 High 8.8 7.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Redis CVE-2026-25243 High 8.8 7.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Redis CVE-2026-23631 High 8.1 6.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Redis CVE-2026-25588 High 8.8 7.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Redis CVE-2026-25589 High 8.8 7.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Solution
Tenable has released Security Center Patch SC202607.1 to address these issues. The installation files can be obtained from the Tenable Downloads Portal: https://www.tenable.com/downloads/security-center
This page contains information regarding security vulnerabilities that may impact Tenable's products. This may include issues specific to our software, or due to the use of third-party libraries within our software. Tenable strongly encourages users to ensure that they upgrade or apply relevant patches in a timely manner.
Tenable takes product security very seriously. If you believe you have found a vulnerability in one of our products, we ask that you please work with us to quickly resolve it in order to protect customers. Tenable believes in responding quickly to such reports, maintaining communication with researchers, and providing a solution in short order.
For more details on submitting vulnerability information, please see our Vulnerability Reporting Guidelines page.
If you have questions or corrections about this advisory, please email [email protected]
Tenable One
Request a demo
The world’s leading AI-powered exposure management platform.
Thank You
Thank you for your interest in Tenable One.
A representative will be in touch soon.
Form ID: 7469
Form Name: one-eval
Form Class: c-form form-panel__global-form c-form--mkto js-mkto-no-css js-form-hanging-label c-form--hide-comments
Form Wrapper ID: one-eval-form-wrapper
Confirmation Class: one-eval-confirmform-modal
Simulate Success