Forum Widgets
Recent Discussions
Arcon Converged Identity (CI) Platform
Summary Tenable One Vulnerability Management and Tenable Security Center now fully support the Arcon Converged Identity (CI) PAM solution. Using the existing Arcon PAM authentication type alongside Digital Vault API configuration, customers with Arcon CI-PAM can seamlessly retrieve credentials during scans. Change No new scan configuration fields or credential types are required. Customers using Arcon CI-PAM should configure the Authentication URL and Engine URL to point to the Digital Vault API base path (e.g. dv/api/sdk), as with Arcon DV deployments. Impact No changes to existing scan configurations are required. Customers currently using the legacy Arcon PAM API path are unaffected. Release Date 8 September 2026 for Tenable One Vulnerability Management, Nessus and Tenable Security Center22Views0likes0CommentsNew Microsoft Azure Key Vault Integration
Summary We are pleased to announce that Tenable's credentialed scanning now supports Microsoft Azure Key Vault as a Privileged Access Management (PAM) integration. This will be available in Tenable One Vulnerability Management and Tenable Nessus Immediately. Change Tenable's credentialed scanning has been updated to include Microsoft Azure Key Vault as a new authentication method. Security teams can now store privileged credentials in Azure Key Vault and have Tenable retrieve them automatically at scan time using OAuth2 client-credentials authentication with a Microsoft Entra ID service principal. Credentials such as sensitive passwords and SSH private keys are maintained centrally inside the vault, they are never stored in Tenable scan policies and can be rotated seamlessly without requiring manual policy updates. The Azure Key Vault integration supports the following credential types: SSH Windows (SMB) Database (Oracle, SQL Server, MySQL, PostgreSQL, DB2, MongoDB) VMware ESXi SOAP API VMware vCenter API Nutanix Prism Central Each Key Vault secret is expected to hold a JSON object containing one or more of the fields username, password, ssh_key, ssh_keyphrase, and domain, so a single secret can drive both password and SSH private-key-based target authentication. For SSH targets, privilege escalation may optionally reference a separate Key Vault secret whose password field is used as the sudo/su password. For more information see our Microsoft Azure Key Vault Integration user documentation: https://docs.tenable.com/Integrations.htm Impact No impact to current scans are expected; If customers encounter issues with this integration, please open a ticket with Technical Support. Release Date September 3, 2026 for Tenable One Vulnerability Management and Nessus TBD for Tenable Security Center91Views0likes0CommentsNew Windows DACL Compliance Check Types Now Available
Summary Tenable is pleased to announce the release of three new atomic compliance check types for Windows auditing: FILE_DACL, REGISTRY_DACL, and SERVICE_DACL. These check types give audit authors a cleaner, more expressive way to assess discretionary access control list (DACL) permissions on files, registry keys, and services. Change These check types improve upon FILE_ACL, REGISTRY_ACL, and SERVICE_ACL check types. The rename to DACL reflects the correct Windows security terminology and aligns with how permission auditing is actually described in benchmarks and hardening guidance. The Audits & Compliance team will be using these check types for all published audits going forward and will be updating existing content to use them. Impact Easier check writing - Each permission check is a single, self-contained atomic check. There is no need to pair a check with a companion ACL structure. The access control criteria are expressed directly in the check itself, reducing the surface area for authoring errors. Easier tailoring - Because all relevant information lives within the atomic check block, policy customization is straightforward. Reviewers, implementers, and content consumers can read exactly what a check requires without cross-referencing a separate structure in the .audit file. Documentation - Usage and examples are available in the Nessus Compliance Checks Reference: FILE_DACL https://docs.tenable.com/nessus/compliance-checks-reference/Content/FILE_DACL.htm REGISTRY_DACL https://docs.tenable.com/nessus/compliance-checks-reference/Content/REGISTRY_DACL.htm SERVICE_DACL https://docs.tenable.com/nessus/compliance-checks-reference/Content/SERVICE_DACL.htm Target Release Date August 27, 2026104Views0likes0CommentsArcon PAM New Digital Vault API Support
Summary Tenable is proud to announce expanded support for the Arcon Privileged Access Management (PAM) integration in Nessus. The integration now supports the Arcon PAM Digital Vault (DV) API. Customers who have migrated to Arcon DV deployments can now retrieve credentials through Nessus scans without requiring new credential types or additional scan configuration fields. This integration automatically selects the correct API path based on the Authentication URL and Engine URL configured in the scan credential. If the configured URLs contain dv/api/sdk, the Digital Vault path is used; otherwise the legacy path is used. No new scan configuration fields are required. Further information regarding these changes and configuration guidance for both API paths can be found in the Arcon section of Tenable's Integrations documentation page. Change The Arcon PAM credential now supports the Digital Vault API path alongside the existing legacy API. The DV path uses a distinct authentication endpoint and credential retrieval endpoint. These differences are handled automatically by the integration based on the URLs the user configures. Customers on DV deployments should set the Authentication URL and Engine URL to point to the DV base path (e.g. dv/api/sdk). Impact Existing scan configurations using the legacy API path remain unaffected. No changes to existing scan configurations or credentials are required for customers already using the legacy API. Release Date August 25, 2026 for Tenable One Vulnerability Management and Nessus TBD for Tenable Security Center141Views1like0CommentsVMware Integration vSphere 9.0 Compatibility
Summary We are pleased to announce that Tenable's VMware integration for vulnerability scanning now supports VMware vSphere 9.0 (ESXi 9.0 and vCenter Server 9.0). These updates will be available in Tenable Vulnerability Management, Nessus, and Tenable Security Center. Change Tenable has updated its VMware integration to support VMware ESXi 9.0 and VMware vCenter Server 9.0. Authenticated vulnerability scans can now be performed on these targets without the need for additional credential setup. VMware vSphere 9.0 compatibility covers the following scenarios: VMware ESX SOAP API authenticated scans against ESXi 9.0 hosts VMware vCenter API authenticated scans against vCenter Server 9.0 VMware vCenter auto-discovery flows for 9.0 hosts For more information see our user documentation: Welcome to Tenable for VMware Impact No impact to current scans are expected; existing ESXi 8.x and earlier vCenter scans continue to work as before. If customers encounter issues with this integration, please open a ticket with Technical Support. Tenable will engage with VMware as needed to identify and resolve any issues. Release Date Available Immediately (May 27, 2026) for Tenable Vulnerability Management, Nessus, and Tenable Security Center Note: TDB for updates to enable VMware ESXi 9.0 and VMware vCenter Server 9.0 compatibility with Compliance and Audit scanning.Harry_NINT21 days agoProduct Team694Views0likes3CommentsResearch Release Highlight - VMware ESXi 7.0 SEoL Update
Summary Tenable is updating the VMware ESX / ESXi Unsupported Version Detection plugin (56997) to track the vendor's End of General Support (EoGS) date rather than the End of Technical Guidance (EoTG) date. Change Before this update, Plugin 56997 determined unsupported status for VMware vSphere/ESXi 7.0 using the vendor's End of Technical Guidance (EoTG) date of April 2, 2027. EoTG marks the point at which the vendor's support becomes best-effort only; it does not reflect when the vendor actually stops shipping security patches. After this update, Plugin 56997 will use the vendor's End of General Support (EoGS) date instead, which is when the vendor discontinues security patches and critical bug fixes. This date for VMware vSphere/ESXi 7.0 EoGS is October 2, 2025. Impact Customers running VMware vSphere/ESXi 7.0 outside of the EoGS support window will now see a correct “unsupported” finding from Plugin 56997. This will introduce new critical findings into scan results for customers who have the unsupported version. Hosts that had previously been identified as unsupported should see no change to those findings. Detection plugins 56997 - VMware ESX / ESXi Unsupported Version Detection Target Release Date November 2, 2026astranahan28 days agoProduct Team147Views0likes0CommentsResearch Release Highlight: HTTP/3 Detection Support in NASL Plugins
Summary This update introduces a significant infrastructure enhancement for NASL plugins, enabling support for the HTTP/3 protocol. While the underlying framework now supports HTTP/3, there are currently no plugins that leverage the HTTP/3 protocol. Individual plugins will be updated by Tenable as appropriate to utilize this capability over time. Change The core of this update will allow NASL plugins to dynamically negotiate and utilize either HTTP/1 or HTTP/3 for requests. We are releasing http3_detect.nasl (Plugin ID: Pending) as the initial plugin to leverage this new framework, providing the foundation for future protocol-aware detections over UDP. To utilize HTTP/3, customers must explicitly enable 'UDP port scanning', 'Search for SSL/TLS/DTLS services' and set an appropriate port range in ‘Search for DTLS on’ within their scan policy settings. Care should be taken as UDP port scanning can significantly slow down scans. Customer Impact Existing plugins remain unaffected and will continue to operate over HTTP/1 unless specifically updated by the Tenable Research team. The introduction of http3_detect.nasl serves as the first step in broader protocol support without impacting current scan performance for non-UDP focused scans. Target Release Date August 10, 2026114Views0likes0CommentsNew AWS Secrets Manager PAM Integration
Summary Tenable is proud to announce our new AWS Secrets Manager Privileged Access Management (PAM) integration. Customers can store scan credentials in AWS Secrets Manager and have Tenable retrieve them at scan time directly inside Tenable. These updates are immediately available for Tenable Vulnerability Management and Tenable Nessus, with plans to release this feature at a later date for Tenable Security Center. Change With this addition, scans can authenticate to targets using credentials fetched from AWS Secrets Manager using AWS Signature Version 4. This integration retrieves the secrets (username, password, optional SSH key, and optional domain) at scan time and uses them for credentialed checks, eliminating the need to store target credentials in Tenable Vulnerability Management or Tenable Nessus. AWS Secrets Manager authentication method supports the following credential types: Windows SSH Database (PostgreSQL, MongoDB, Cassandra, DB2, MySQL, SQL Server, Oracle) VMware ESX SOAP API VMware vCenter API Nutanix Prism Central Support is provided for both long-lived IAM user access keys and temporary AWS STS session tokens. Additionally, you can utilize the Escalation Credential ID to reference a separate AWS secret for SSH credential privilege escalation. Impact No impact to current scans are expected; If customers encounter issues with this integration, please open a ticket with Technical Support. For comprehensive details regarding this integration, please refer to the Tenable user documentation. Release Date July 16 2026 for Tenable Vulnerability Management and Nessus; TBD for Tenable Security Center101Views0likes0CommentsNew Akeyless PAM Integration
Tenable is pleased to announce a new integration with Akeyless Privileged Access Manager (PAM) for streamlined privileged access in credentialed vulnerability scans. This integration is available in Tenable Vulnerability Management and Tenable Nessus. Supported Credential Types SSH — including privilege escalation (e.g., sudo) and SSH key-based authentication SMB (Windows) — including domain and Kerberos authentication Database — Oracle, SQL Server, MySQL, PostgreSQL, MongoDB, DB2, Cassandra, Sybase ASE ESXi — VMware vSphere hypervisor credentials vCenter — VMware vCenter Server credentials Nutanix — Nutanix Prism Central credentials Supported Authentication Methods The integration supports three methods for authenticating to Akeyless: Access Key — authenticate using an Akeyless Access ID and Access Key Universal Identity (UID) — authenticate using a Universal Identity token, supplied directly or read from a file on the scanner host Certificate (mTLS) — authenticate using a client certificate and private key Impact There is no disruption to existing scan configurations. Customers using Akeyless for privileged access management are encouraged to adopt this integration for credentialed scanning to consolidate credential management and reduce risk from static credentials. For comprehensive details regarding this integration, please refer to the Tenable user documentation. Release Date July 14, 2026 for T.VM and Nessus; TDB for T.SC50Views0likes0CommentsHashiCorp Vault Integration - New SSH Certificate Authentication
Summary Tenable is proud to announce the addition of SSH Certificate authentication to our HashiCorp Vault integration. This feature allows customers to leverage HashiCorp Vault’s SSH Secrets Engine to retrieve signed SSH certificates during credentialed scanning for use in SSH authentication to target systems. Hence providing a more secure and streamlined approach to privileged access management. This update is now available in Tenable Vulnerability Management and Tenable Nessus, with plans to release for Tenable Security Center at a later date. By using the HashiCorp Vault with the SSH Signed Certificates option, users can centralize the management of their SSH secrets while reducing sprawling. Documentation for the Hashicicorp integration will be available on our documentation page. Supported Credential Types The HashiCorp Vault integration supports: SSH, including (least privilege, privilege escalation, SSH key authentication and SSH Signed Certificates). SMB (Windows), including domain configuration. SNMPv3 Database integration, including the following database types: Oracle SQL Server MySQL MongoDB PostgreSQL DB2 Cassandra Sybase ASE VMware vCenter API VMware ESX SOAP API Nutanix Prism Central Impact There is no impact to existing scan configurations.. Release Date Immediate; July, 6th 2026 for T.VM and Nessus, TDB for T.SC139Views0likes0Comments