CVE-2026-19681
9.9
CRITICAL · CVSS 3.1 · EPSS 9.9% (pctl 95)
In your normal cycle
Critical by CVSS (9.9), but no sign of active exploitation.
Description
An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by uploading a specially crafted file, potentially resulting in arbitrary command execution on the underlying operating system.
Scoring
| CVSS | 9.9 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 9.94% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2026-08-14 |
| Last modified | 2026-08-19 |
Affected (1)
| Vendor | Product |
|---|---|
| tenable | security center |
References
→ the Explorer · watch your stack · NVD