On June 26, 2026, the CERT‑FR released an alert stating that several SQL injection (SQLi) vulnerabilities have been discovered in Tenable Nessus. The flaws affect Nessus versions prior to 10.12.0 and could allow an attacker to inject malicious SQL code into the system. The vulnerabilities are catalogued as CVE‑2026‑57587 and CVE‑2026‑57588. The alert directs users to Tenable’s security bulletin tns‑2026‑17 for detailed information and patch instructions. Tenable has issued updates to address the issues. Users running older Nessus installations are advised to apply the patches immediately to mitigate the risk of exploitation. Security teams should monitor the CERT‑FR site for further guidance.
Summary of content from
Made by AI. If you spot anything of concern write us at contact@cybach.com. We’ll promptly correct irregularities.