PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-33694 Tenable, Inc. CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-23T19:17:28.073Z and has not been modified since then. This vulnerability affects Tenable Nessus and Nessus Agent products, allowing an attacker to create a junction and delete arbitrary files with SYSTEM privileges, potentially facilitating arbitrary code execution with elevated SYSTEM privileges. Security teams responsible for these products should review and apply vendor advisories to mitigate this vulnerability. The vulnerability has a CVSS score of 7.4 and a CVSS severity of HIGH. Evidence is limited, and defenders should verify affected product deployments and apply vendor guidance.

Vendor
Tenable, Inc.
Product
Tenable Nessus, Tenable Nessus Agent
CVSS
HIGH 7.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-23
Original CVE updated
2026-08-21
Advisory published
2026-04-23
Advisory updated
2026-08-21

Who should care

Security teams responsible for Tenable Nessus and Nessus Agent products should review and apply vendor advisories to mitigate this vulnerability. This includes teams managing Nessus deployments, security operations centers, and vulnerability management teams. These teams should assess their exposure, apply patches or mitigations, and monitor for potential exploitation attempts.

Technical summary

The vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privileges, potentially facilitating arbitrary code execution with elevated SYSTEM privileges. Affected products include Tenable Nessus versions up to 10.11.3 and Nessus Agent versions up to 11.1.2. The vulnerability has a CVSS score of 7.4 and a CVSS severity of HIGH. This condition may allow attackers to execute malicious code with elevated SYSTEM privileges. Tenable Nessus and Nessus Agent products are affected, and security teams should review and apply vendor advisories to mitigate this vulnerability.

Defensive priority

This vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privileges, potentially facilitating arbitrary code execution with elevated SYSTEM privileges.

Recommended defensive actions

  • Review and apply vendor advisories for Tenable Nessus and Nessus Agent products
  • Inventory and check for vulnerable product versions
  • Implement compensating controls to monitor and restrict SYSTEM privilege usage
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The vulnerability affects Tenable Nessus and Nessus Agent products. Vendor advisories are available for mitigation. Evidence is limited, and defenders should verify affected product deployments and apply vendor guidance. The CVE record was published on 2026-04-23T19:17:28.073Z and has not been modified since then. Affected products include Tenable Nessus versions up to 10.11.3 and Nessus Agent versions up to 11.1.2.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-23T19:17:28.073Z and has not been modified since then.