integrations
21 TopicsTenable Product Update Newsletter — July 2026
Check out our July newsletter to learn about the latest product and research updates, events, and educational content. Plus, this month we’re featuring the launch of the CyberAgents Exchange, powered by Tenable. Keep reading to read more about the new open-source AI exchange! Tenable One - Platform updates Integrate application security data into Tenable One for code-to-runtime security Your codebase is growing faster than your security program, and in the age of AI, developers are introducing security findings at 10 times the rate of their peers. It is critical to see code as part of your entire attack surface. Application security data now integrates directly into Tenable One to further close visibility gaps and ensure secure code development in the AI era. Whether code is human- or machine-written, you can now integrate application security risks, like those from Snyk, Claude Security, or any other application security tool via Tenable One Connectors — directly alongside your existing exposure data. What this means for you: Achieve full code-to-runtime visibility by bringing application security risks together with the rest of your exposure data in one place. Fix code flaws before they become incidents by identifying your most business-critical code flaws and fixing them early in the development lifecycle. Measure organizational exposure and transform technical static code vulnerabilities into clear risk metrics on business resilience. Read the blog post Explore the guided demo Check out Open Connector documentation and Snyk Connector documentation Improved workflow orchestration capabilities in Tenable One Vulnerability Management and Tenable One New enhancements to Tenable's workflow orchestration capabilities are now generally available. This release streamlines remediation workflows and improves operational efficiency with the following key updates: Plugin output in tickets: You can now attach Plugin Output directly to tickets, providing immediate context and critical information while eliminating the need for further navigation. Tenable Hexa AI for ServiceNow: You can now leverage Tenable Hexa AI for ServiceNow incident and initiative creation to match already available Jira functionality. Review the exposure management release notes Review the Tenable Vulnerability Management release notes Tenable unified scoring is now live Tenable has unified its risk prioritization standard, moving the high-fidelity Vulnerability Priority Rating (VPR) model out of beta to become the sole standard. To sharpen your prioritization, an updated asset classification engine also delivers more accurate Asset Criticality Ratings (ACR) for your assets. Because VPR and ACR feed directly into your Cyber Exposure Score (CES) and Asset Exposure Score (AES), your console will automatically update to reflect a precise understanding of your exposure. These recalculations occur automatically, though completion times depend on the size of your environment. To prevent errors in your saved views, you must manually update any filters or combinations that still use VPR v1. No data migration is required. Visit Tenable Connect for more details Learn more about Tenable One scoring The CyberAgents Exchange, powered by Tenable Tenable launches the industry’s first open-source AI exchange (and we want your agents on it) Security teams are building AI agents in isolation, reinventing the wheel with no neutral place to share what actually works. The CyberAgents Exchange, powered by Tenable, is the only purpose-built, cybersecurity-native registry for AI agents, skills, MCP servers, and multi-agent playbooks in the current market. Built by defenders. For defenders: Purpose-built for security teams to solve the exposure problems practitioners actually face. Collective defense for the agentic era: Anyone can contribute; everyone benefits. Agents and skills are shared under open licenses with no fees or gates. Trust through transparency: Every agent links directly to its source repository, so there are no bundled binaries or black boxes. Build your reputation. Elevate your craft: Contributing is career capital. We give practitioners a platform to earn validation and build an undeniable resume. Join the community, build your reputation, and start automating risk reduction. Explore the directory and submit your builds Tenable One Cloud Exposure Tenable One Cloud Exposure achieves FedRAMP High authorization Tenable is committed to being the trusted partner of choice for the public sector, providing the advanced protection required for the U.S. government’s most sensitive environments. We are proud to announce that Tenable One Cloud Exposure has achieved FedRAMP High and Impact Level 5 (IL5) authorization. Purpose-built for sensitive government cloud environments, this high-level authorization delivers: Unified visibility: Gain a single view across infrastructure, identities, and workloads — even in air-gapped environments. Zero-trust enforcement: Leverage advanced identity analytics to enforce least privilege principles and align with DoW CIO mandates. Blast radius reduction: Map the Web of Risk to see how vulnerabilities connect to identities and sensitive data, stopping problems before they snowball. Cost reduction: Support fiscal modernization by eliminating tool sprawl and reducing costs without compromising security. Read the press release Learn more about our FedRAMP High solutions Take control of your sensitive data When data classification engines scan the cloud, they often flag false positives, like internal test data, mock databases, or benign corporate email domains, as critical risks. With Tenable’s new data classification exclusions, customers can fine-tune their data scans to get to the bottom of what’s actually sensitive. Exclude by resource scope: Narrow exclusions to specific data types or resources using user-friendly Explorer-based queries. Exclude specific values: Filter out known text patterns or regex strings (like internal email domains). Target precise locations: Use OR logic to pinpoint exact databases, schemas, tables, file extensions, or object paths. Learn how to create a data classification exclusion Read about the recent releases here Tenable One Web App Scanning Authenticate web app scans with OAuth 2.0 You can now scan protected applications and APIs using OAuth 2.0 authentication within Tenable One Web App Scanning. Configure these options under your scan credential settings using three supported flows: Authorization code: For user-driven logins, with optional PKCE and Selenium scripting for complex identity providers. Client credentials: For machine-to-machine API scans without user interaction. Device code: For headless and device-style authentication. To prevent scans from silently losing access, authorization verification continuously validates your session via response patterns, headers, or HTTP status codes across all credential types. Integrate these capabilities immediately through your existing credentials API without changing endpoints. You can call the List Credential Types endpoint to programmatically discover the new fields. Review the documentation Review the release notes Tenable One OT Exposure Extended OT visibility for grid operators and disconnected environments Our latest Tenable One OT Exposure release expands visibility for grid operators and disconnected environments, and introduces productivity and performance enhancements to accelerate analyst workflows. OT agent for disconnected environments: Secure air-gapped and isolated networks without deploying sensors or requiring live connectivity, featuring offline scan profiles, a local agent interface tailored for field technicians, and centralized Network Areas to resolve duplicate IP conflicts across distributed sites. Power substation anomaly detection: Passively monitor GOOSE streams and alert on anomalous activity (e.g., code revision changes) to protect utility and grid operations from unauthorized modifications or replay attacks. Yokogawa DCS activity detection: Get deep visibility into engineering activities on Yokogawa Centum VP systems to detect changes to critical operations and unauthorized access, including controller start/stop, code edits, function block changes, tag writes/deletes, and more. Simplified enterprise management: Manage all ICP subnets from a single Enterprise Manager interface — define CIDR boundaries, toggle monitoring per-site, and eliminate the need for per-ICP configuration for monitoring different network areas. Analyst workflow improvements: Reuse investigations with Saved Views, review Assets and Findings details faster with a quick-access side panel, and secure syslog transport with TLS support. Explore the user guide Review the release notes Tenable Security Center Reimagined vulnerability analysis, flexible deployment, and streamlined operations Tenable Security Center 6.9, now available in early access, modernizes vulnerability analysis and expands enterprise deployment flexibility with a reimagined query experience and deeper PAM and credential integrations. Explore Findings: A redesigned vulnerability query interface with expanded filtering and VPR key drivers surfaced directly in the findings detail panel. Tenable Nessus scanners via Tenable Sensor Proxy: Deploy Tenable Nessus scanners through Tenable Sensor Proxy for flexible, scalable enterprise and Tenable Enclave Security environments. Windows LAPS and PAM Kerberos support: Dynamically retrieve scan credentials via Windows LAPS and Kerberos Target Authentication across all supported PAM integrations. Performance improvements: Submit diagnostic bundles directly to Tenable Support, suppress rollover scans during freeze windows, and benefit from a modernized data architecture that reduces disk usage. Explore the user guide Download the early access release Tenable Ecosystem Now available: PyTenable 26.6.1 PyTenable 26.6.1 has officially been released, introducing a new temporal versioning scheme (YEAR.MONTH.PATCH) to better align with rapid API changes and enable critical updates to older modules. Marshmallow v4 support: Resolved issues preventing the use of newer Marshmallow versions. APA export: Added support in the current Tenable One package. Streamlined testing: Refactored workflow processes mean you no longer need Act and Docker installed just to run the test suite. Bug fixes: Addressed various minor issues introduced by recent API changes. Moving forward, support will be provided for the current month minus three releases, so we highly recommend pinning your software to a specific release and testing against the latest. Visit the PyTenable GitHub repository Training and product education Tenable One Exposure Management Platform introduction course includes CTEM This introductory course in Tenable University now incorporates the foundations of the Continuous Threat Exposure Management (CTEM) framework to identify exposures, prioritize remediations, and reduce risk across your modern attack surface. Practitioners and partners will learn the fundamentals of continuous hybrid asset discovery, risk-based scoring, and validating critical attack paths to effectively manage security posture. This no-cost course serves as the essential primer and recommended prerequisite for the Specialist tier. Access the course on demand in Tenable University On-demand Tenable One Exposure Management Platform Specialist course now available This brand-new paid Tenable University training course provides comprehensive Continuous Threat Exposure Management (CTEM) lifecycle training across the entire Tenable One architecture. The Specialist-level course delivers deep technical coverage of the Tenable One Exposure Management Platform, including: Tenable One Vulnerability Management Tenable One Attack Surface Management Tenable One Identity Exposure Tenable One OT Exposure Tenable One Cloud Exposure Tenable One Web App Scanning Practitioners will gain proficiency in third-party data integration, advanced asset tagging, and context-aware analytics (such as Attack Path Analysis and Exposure Signals) to drive risk-based prioritization and deliver actionable executive dashboards. Eligible for Continuing Education (CE) credit. Learn more and purchase online Tenable events and webinars Customer office hours These are recurring ask-me-anything sessions for Tenable Security Center, Tenable One Vulnerability Management, Tenable One Cloud Exposure, Tenable One Identity Exposure, and Tenable One OT Exposure. Time-zone-appropriate sessions are available for the Americas, Europe (including the Middle East and Africa), and Asia-Pacific (APAC). Learn more and register Virtual events Now on demand — Tenable customer update, July 2026: Watch the most recent quarterly customer update session. This informative, fast-paced overview explores how to better secure your expanding attack surface and consolidate critical security data. Products covered include: Tenable One, Tenable One AI Exposure, Tenable One Vulnerability Management, and Tenable Security Center. Watch on demand See all upcoming live and on-demand webinars Read Tenable documentation.221Views0likes0CommentsNow available: Integrate application security data into Tenable One for code-to-runtime security
Your codebase is growing faster than your security program, and in the age of AI, developers are introducing security findings at 10 times the rate of their peers. It is critical to see code as part of your entire attack surface. We’re excited to announce that application security data can now be integrated in Tenable One to further close visibility gaps and ensure secure code development in the AI era. Whether code is human or machine-written, you can now integrate application security risks—like those from Snyk, Claude Security, or any other application security tool via Tenable One Connectors—directly alongside your existing exposure data. What this means for you: Achieve full code-to-runtime visibility by bringing application security risks together with the rest of your exposure data in one place. Fix code flaws before they become incidents by identifying your most business-critical code flaws and fix them early in the development lifecycle. Measure organizational exposure and transform technical static code vulnerabilities into clear risk metrics on business resilience. Ready to integrate application security data into Tenable One? Read the blog post Explore the guided demo Check out Open Connector and Snyk Connector documentation26Views0likes0CommentsGA Release - Tenable ServiceNow Apps Now Australia Compatible!
Release Date: June 22, 2026 Included Applications and Versions: Service Graph Connector for Tenable: Version 6.3.0 Tenable for ITSM: Version 6.2.0 Vulnerability Response Integration with Tenable: Version 30.4.1 WHAT'S NEW? Tenable is excited to announce the General Availability for our ServiceNow apps, fully compatible with the Australia Platform Release. This rollout introduces significant feature updates, bug fixes, and stability enhancements across our core integration codebase: Configurable Asset Ingestion Limits: Resolves payload failures by collecting and deduping IP, FQDN, and MAC data on a per-asset basis before submitting to the Tenable Vulnerability Management API. It features an adjustable asset property ceiling that defaults to 100 records and can be scaled up to 1,000 for complex environments via a custom system property config. Predictive Asset Dropped Warning Logs: Adds clear localized logs inside ServiceNow that capture the impacted Configuration Item sys_id, the total volume of asset records received, and a structural breakdown of any metrics dropped when violating max limits. Codebase Security Hardening: Completely eliminates the deprecated global GlideEncrypter API call from our source codebase. This satisfies strict compliance criteria following customer instance health assessment scans that flag deprecated commands as security risks. Optimized OS Transformation Handling: Mitigates transactional script processing delays and timeout failures within the core cleanse() operation method. The updated connector parses choice items more efficiently against massive database environments with large sys_choice table counts. OT Device Schema Correction: Fixes data transformation crashes and java.lang.IllegalArgumentException errors when processing complex IT/OT hybrid nodes like workstations populated via WMI queries. The ingestion rules seamlessly process structural repetitions found within the hotFixes and devicesAndDrives sections of the API response without stalling the import set queue. PLATFORM COMPATIBILITY: Supported ServiceNow Releases: Australia, Zurich, Yokohama, and Xanadu. Supported Tenable Platforms: Tenable Vulnerability Management, Tenable Security Center version 5.7 or later, and Tenable OT Security QUESTIONS? We are here to help! Reach out to us at connect.tenable.com! -Ecosystem Product Management127Views0likes0CommentsTenable Product Update Newsletter — June 2026
Check out our June newsletter to learn about the latest product and research updates, events, and educational content. Tenable One - Platform Updates Improve exposure prioritization in Tenable One with continuous security control validation As frontier AI models accelerate vulnerability discovery, the work of validating, prioritizing, and remediating vulnerabilities alongside other security weaknesses to understand the true exposure they create has become much more urgent. Validation in exposure management is a key capability to help you understand which exposures attackers can actually reach by understanding the accessibility and exposure. Prioritize exposures more effectively by seeing which attack paths active prevention and detection controls mitigate. Accelerate investigations and triage by filtering top attack paths and attack techniques based on the presence of security controls. Understand control context and status by viewing security control information in the node details view. Check out continuous control validation in Tenable One: Read the blog post Explore the guided demo Read more about Attack Technique Details Tenable One Vulnerability Management Implement granular custom roles for enhanced access control Give your teams exactly the access they need to do their jobs — without exposing sensitive scan settings, sensors, or compliance reports. Streamline access control by building custom roles. You can now build granular custom roles that dictate exactly what your users can see and do within the platform. With straightforward, one-click toggles, you can grant read or full-write access to specific tools like scans, sensors, or reports. Your existing custom roles will automatically transition to this new format, so existing custom roles will transition seamlessly with no manual migration required. Take the guided walkthrough Read the documentation Review the best practice guide Gain comprehensive visibility into endpoint application risk Managing decentralized endpoint applications introduces visibility gaps. Focus your patching on the software your employees actually use, instead of chasing thousands of generic alerts. Get a single view of all software running on your endpoints with the new Endpoint Application Visibility and Exposures One-Stop Shop report. Prioritize fixes based on how widely an app is deployed and its actual risk to your business, rather than just relying on generic severity scores. Access the endpoint application visibility report Enhance your threat analysis expertise with specialist training You can now access the updated instructor-led Tenable One Vulnerability Management Specialist Course in Tenable University, featuring: Streamlined curriculum focusing on advanced analysis, enabling you to interpret data and counter threats faster. Deep dives into critical new features, including Vulnerability Intelligence and Exposure Response. Refreshed educational experience with hands-on lab exercises to solidify your expertise. Learn more about this course and other instructor-led and on-demand Tenable University training and certification offerings: Course details Tenable training and certification Tenable One Cloud Exposure Transform disparate alerts into one threat story with Tenable cloud detection and response Cloud detection and response (CDR) in Tenable One Cloud Exposure is now generally available, adding near-real-time behavioral detection across multi-cloud environments. Tenable CDR capabilities include: AI-powered threat stories: AI-powered threat stories automatically correlate related detections by actor, resource, and tactic, transforming hundreds of raw alerts into a clear narrative of the attack, allowing teams to start investigating instantly. Runtime vulnerability validation: Uses active scanning to confirm cloud resources that are reachable from the internet. Dual coverage: Combines agentless detections with an optional eBPF runtime sensor, giving security teams comprehensive near-real-time visibility across cloud workloads without sacrificing deployment flexibility or coverage. Guided response: As the agentic engine of Tenable One, Tenable Hexa AI is the intelligence layer that reasons across live exposure context, threat findings, and environment history to deliver a prioritized, actionable response plan, in plain language, at attacker speed. With Tenable CDR, teams can leverage AI-driven pathways to investigate and remediate with speed, drive informed, actionable resolution, close the exposure gap, and extend attack path analysis to holistic remediation of real threats. Watch the guided demo Tenable One OT Exposure Tenable OT Security 4.7 (early access) This release expands visibility for grid operators and disconnected environments, and introduces a variety of productivity enhancements to accelerate analyst workflows: Power substation anomaly detection: Passively monitor GOOSE streams and alert on anomalous activity to protect utility and grid operations from unauthorized modifications or replay attacks. Yokogawa DCS activity detection: Get deep visibility into engineering activities on Yokogawa systems to easily detect critical operations and unauthorized access. OT agent for disconnected environments: Secure air-gapped networks without deploying sensors or requiring live connectivity, featuring offline scan profiles and a local agent UI. Workflow and enterprise management enhancements: Centrally manage subnets from a single Enterprise Manager interface, and speed up recurring investigations with new Saved Views, a quick-access Asset Side Panel, and TLS Syslog support. Explore the user guide Review the release notes Tenable Security Center Tenable Security Center 6.8 Focus on the vulnerabilities that matter with AI-powered VPR insights and mitigation guidance. This release streamlines your operations with unified asset repositories for IPv4, IPv6, and Agents, and improves efficiency with new background query processing and scan optimization capabilities. View the full release notes Tenable Nessus Maximize your Nessus capabilities with the Tenable Documentation hub Optimize your vulnerability assessments and accelerate troubleshooting with the official Tenable Nessus Documentation hub. Want to ensure you’re getting the absolute most out of your vulnerability assessments? Whether you’re a seasoned security pro fine-tuning your environment or just setting up your first Nessus Pro or Expert deployment, the hub provides everything you need to optimize your security workflows and troubleshoot: Stay ahead of the curve: Instantly access the latest release notes, system requirements, and seamless upgrade guides. Optimize your assessments: Find step-by-step instructions for configuring and launching scans. Streamline your reporting: Learn exactly how to customize, generate, and export compliance-ready scan results in PDF, HTML, or CSV formats to keep your stakeholders informed. Bookmark the documentation site to quickly discover new features, resolve configuration questions, and keep your attack surface secure. Tenable Nessus documentation Tenable Patch Management Synchronize asset tags across patching workflows Sync your existing security tags directly with your patching workflows to eliminate manual setup and fix vulnerabilities faster. If you already group your devices using tags or asset lists in Tenable One Vulnerability Management or Tenable Security Center, those groups will automatically synchronize with your patch console. You can target them for patch schedules and deployment waves without rebuilding them from scratch. This update also extends full patch support to SUSE Linux 15 SP6 (Server & Desktop). Get the full update details on Tenable Connect Tenable events and webinars Customer office hours These are recurring ask-me-anything sessions for Tenable Security Center, Tenable One Vulnerability Management, Tenable One Cloud Exposure, Tenable One Identity Exposure, and Tenable One OT Exposure. Time-zone-appropriate sessions are available for the Americas, Europe (including the Middle East and Africa), and Asia-Pacific (APAC). Learn more and register Virtual events Tenable customer update, July 2026: Join the next quarterly customer update session at 11 a.m. EST/3 p.m. BST/5 p.m. CEST July 16. This informative, fast-paced overview will explore how to better secure your expanding attack surface and consolidate critical security data. Products covered include: Tenable One, Tenable One AI Exposure, Tenable One Vulnerability Management, and Tenable Security Center. Register See all upcoming live and on-demand webinars Tenable Research Research security operations Read the latest insights from top security and data science researchers: Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect Key findings from the Verizon DBIR 2026 Read Tenable documentation.632Views1like0Comments[GA] Tenable Patch Management v10.1.972.14 (Server) is LIVE!
Tenable is pleased to announce the GA release of TPM v10.1.972.14 (Server). This quality release provides a hotfix build that resolves an issue found in the upgrade from 10.0.971 to 10.1.972.12. Release Highlights Upgrade Task Sequencing: Resolves an issue where the order of upgrade tasks was incorrect from 10.0.971 to 10.1.972.12. Intent Object Validation: Resolved an issue where using DeploymentWaves objects from a Simple Patching Strategy in an Advanced Patching Strategy blocked upgrades. Validation Enforcement and Migration Stability: Enforced validation to prevent the usage of Simple Patching Strategy generated intent objects in Advanced Patching Strategies. Migration Stability: Addresses a specific failure that arises if a customer used a Simple Patching Strategy's DeploymentWaves object in a separate Advanced Patching Strategy. Upgrade Path SaaS: Your SaaS Tenant is already upgraded! On-Prem: Download the latest Server installer from the Tenable Downloads Portal. Customer-Facing Resources: Release Date: May 07, 2026 Release Version: 10.1.972.14 (Server) Changelog: View Release Notes Docs: TPM Complete Documentation Questions? We’re a ping away! Reach us at connect.tenable.com. Happy Patching! – Tenable Patch Product Management195Views0likes0CommentsApril 2026 Tenable Product Newsletter
Check out our April newsletter to learn about the latest product and research updates, upcoming and on-demand webinars and educational content — all to help you get more value from your Tenable solutions. EXPOSURE 2026 The Tenable Exposure Management Conference There’s still time to register for EXPOSURE 2026, the first and only in-person event dedicated to exposure management for the AI era. Join us in Boston, Mass., from May 19-21, 2026, to: Get a practical blueprint for securing your AI attack surface. Hear real-world strategies from the industry’s top security executives. Master new techniques in hands-on labs and exclusive training sessions. Register now! Product update: Standardizing Tenable risk scoring Coming July 1: A new standard for VPR For the past several months, many customers have utilized VPR (Beta) to gain deeper insights into exploitability. We are excited to announce that on July 1, this model will be promoted to the primary Vulnerability Priority Rating (VPR) across the Tenable platform. By standardizing on this advanced model, we are retiring legacy VPR scoring to ensure every customer benefits from our most sophisticated threat intelligence. We're also enhancing our asset classification engine. As a result, customers with access to Asset Criticality Ratings (ACR) will see these scores more accurately reflect real-world business risk. Read the full update on Tenable Connect. Tenable Cloud Security Stop chasing ghosts. Start fixing what's actually exposed. This month, we’re trading “potential risk” for proof. Spotlight: Reachability, validated Network Scanner results now feed directly into our core risk engine. Instead of flagging every internet-facing asset, Tenable dynamically confirms what’s actually reachable across AWS, GCP, Azure, and OCI, so you chase toxic combinations on truly exposed assets, not shadows behind a WAF. Also new Unified accounts page. One view for every cloud and identity account. Goodbye, provider silos. More wins for your team Protect dev velocity. Exclude unresolvable CVEs from container scans so noise doesn’t break builds. Effortlessly scale triage. Turn any Explorer investigation into a permanent automation rule. Automate least privilege. Auto-generate custom roles for over-privileged Entra ID and GCP groups based on real usage. Find what others miss. Updated engine surfaces vulnerabilities buried in nested JAR files. View full release notes → Tenable Vulnerability Management Introducing VM-Native OT Discovery Safely identify and profile connected PLCs, HMIs, and IoT devices using the vulnerability management toolset you already own. No specialized hardware or complex deployments required. Turn your existing IT security tools into a safe OT discovery engine today and get visibility into your IT/OT security gap. Watch the guided demo to see this new capability in action. Review the latest documentation for Scan Templates and Discovery Settings to get started. Find and fix hidden risks across your infrastructure To protect your environment, you need a clear view of every asset and vulnerability. New reports and dashboards give you visibility to find hidden exposures in your Java, database, and operating system layers before they lead to a disruption. Identify every Java vulnerability: Go beyond a simple update to secure Java and see how unmanaged applications expand your risk. Java visibility and exposures dashboard: Get a full view of your Java ecosystem to find legacy flaws and library exploits that could give attackers access to your internal network. Java visibility and exposures report: Turn complex scan data into a clear map of your assets to find hidden weaknesses in unpatched installations before they cause a disruption. Prioritize your database security: Protecting your data depends on knowing which databases are most vulnerable. This new report and dashboard help your team close exposures and meet audit requirements by highlighting critical gaps. Database application visibility and exposures dashboard: Use this one-stop shop to see all supported and unsupported databases in one place. You can quickly see which assets are exploitable or have been active for too long, so you know what to patch first. Database visibility and exposures report: Streamline your compliance audits and vulnerability assessments with a clear breakdown of your database risks and best practices. Inventory your assets and improve scan accuracy: Full visibility requires knowing exactly what is running on your network. Operating system and application inventory with data troubleshooting report: Get a high-level summary of your OS and application instances. Includes specific queries to help you identify and fix scan fidelity issues for data accuracy and effective security operations. Tenable Nessus We’re thrilled to announce that Tenable Nessus v10.12 is now available for early access, with general availability expected later this month. This release streamlines your workflow with a revised interface and updated security protocols. Organize scans: Simply drag and drop existing scans from a list view directly into a folder or directory for easier organization. Import files: Instantly import a scan file (like .nessus) by dragging it from the local desktop into Nessus. OpenSSL 3.5 support: Nessus now fully supports OpenSSL 3.5, ensuring your vulnerability assessment operations meet the latest cryptographic standards. FIPS-140.3 support: Support for the FIPS 140-3 standard has been added. View Nessus 10.12 product documentation for more info Tenable Security Center Tenable Security Center 6.8 Focus on the vulnerabilities that truly matter with AI-powered VPR insights and clear mitigation guidance. This release streamlines your operations with unified asset repositories for IPv4, IPv6, and Agents, and improves efficiency with new background query processing and scan optimization tools. Foundational visibility for cyber-physical systems with VM-native OT Discovery We recently added native OT discovery capabilities in Tenable Security Center, allowing you to quickly map unknown/unmanaged cyber-physical systems (PLCs, IoT devices, etc.) using the tools you already own. Get insight into mission-critical OT assets across your network without risking disruption or the need for additional agents or add-on purchases. Find out how to configure your first scan here. View full release notes → Tenable OT Security Introducing Tenable OT Security 4.6 Our latest release introduces a variety of new features and performance enhancements, including refined scan controls and streamlined workflows for large-scale enterprise environments. Massive subnet scaling: Now supports up to 5,000 subnets per ICP, significantly increasing visibility for distributed large enterprise deployments. Centralized network management: A new Monitored Networks page includes bulk-add capabilities and the ability to stage inactive networks before monitoring. Precision scanning: New scan customization options allow you to define specific credential usage per scan for safe discovery of sensitive assets. Streamlined platform navigation: Updated workflow for SSO/SAML users allows you to instantly pivot back to the Tenable One platform with a single click. Remote agent updates and query restrictions: Update OT agents directly from the ICP, remove local site visits or manual CLI intervention, and restrict specific protocol queries with OT agents. Enhanced diagnostics: Deeper metadata in asset log exports for faster troubleshooting. IoT connector updates: Major stability and performance upgrades for Milestone, AvigilonES, and Exacq Edge integrations for IoT asset discovery. Update required: Tenable OT Security 4.5 Service Pack (version 4.5.61) All customers running version 4.5 should apply this upgrade immediately for optimal system stability and performance when processing high volumes of network conversations. This update also addresses communication gaps with Rockwell Stratix devices and Nessus scans. View full release notes → Tenable Identity Exposure Sharper signal. Steadier platform. This month, we are making the detections you rely on more precise, and the platform underneath more resilient. Detections that cut through the noise Golden Ticket IoA, now directory-aware. Smarter logic means fewer false positives and fewer missed hits in multi-domain environments. Richer PetitPotam context. Detections now surface hostnames and source IPs, so triage starts with answers, not questions. Platform you can count on Accurate API pagination. Iterate through result sets cleanly for faster, more reliable reporting. Self-healing listeners. RabbitMQ and Sysvol connections now auto-recover after restarts or network blips. View full release notes → Tenable PCI ASV Tenable PCI ASV interface update The Tenable PCI ASV interface will change on or around May 8, 2026, to simplify your compliance workflow. Changes will not affect your data, scan history, attestation records, or scan configurations. Here’s what’s changing: Renamed actions: Submit PCI is becoming Import to ASV Workbench, and the In Remediation tab changes to Scan Customer Review. Easier review: A new Accept button and compliance dialog let you confirm requirements in fewer clicks, with a progress indicator to track your status in real-time. Unified vulnerability view: Failures and Disputes merge into a single Vulnerability Review & Disputes tab. Updated Navigation: The Submit to ASV Review button is moving to a more intuitive position in the workflow. The changes will happen automatically. You don’t need to take action. Questions? Contact Tenable Support or your Customer Success Manager. Tenable Training and Product Education Enhanced Tenable Vulnerability Management training now available Maximize your security investment with the redesigned Introduction to Tenable Vulnerability Management course, available at no cost in Tenable University. This updated experience includes interactive elements, demonstration videos, and knowledge checks to help you quickly gain practical expertise. You will navigate the latest user interface with ease while implementing recommended settings to optimize your platform configuration from day one. Tenable Connect Join the Tenable Connect Office Hours group Missed a live Office Hours session? No problem! We are excited to launch the official Office Hours group to provide you with a centralized hub for Office Hours sessions and support. When you join the group, you’ll be able to: Watch recordings: Access the library of past regional Office Hours sessions at your convenience. Review key Q&As: Review important questions and expert answers from every call so you can find solutions without watching the full video. Search with ease: Use Tenable Connect’s unified search to find specific topics discussed across any of our recorded sessions. Don't miss a beat! Join the group to catch up on the latest sessions and stay ahead of the curve. And register for upcoming live Office Hours sessions here. Tenable Webinars Tune in for product updates, demos, how-to advice, and Q&A. See all upcoming live and on-demand webinars at tenable.com/webinars. On-demand Tenable customer update: April 2026: Watch this quarterly Tenable customer update to learn how to use AI to augment your security team, secure your expanding AI attack surface, uncover hidden risk across your connected IT/OT environments, and more. Products covered: Tenable One, AI Exposure, Tenable Vulnerability Management, OT functionality, third-party data connections, and Tenable Security Center. Customer Office Hours Recurring ask-me-anything sessions for Tenable One, Tenable Security Center, Tenable Vulnerability Management, Tenable Cloud Security, Tenable Identity Exposure and Tenable OT Security. Time-zone-appropriate sessions are available for the Americas, Europe (including Middle East and Africa), and Asia Pacific (APJ). Register here. Tenable Research Research Security Operations blog posts Subscribe to the Research team blog posts here. The hidden cost of AI speed: Unmanaged cyber risk Supply chain attack on Axios npm package: Scope, impact, and remediations Research release highlights Potential Vulnerabilities: Tenable Research is officially introducing Potential Vulnerabilities. A potential vulnerability is a finding that has a lower degree of certainty as to whether the assessed application is or is not vulnerable. Improvement to printer OS fingerprinting: Scanned printers will now have an OS artifact surfaced in their scan host metadata if the target has been identified as a printer when the Scan Network Printers policy option is disabled. Content coverage highlights Almost 4,500 new published vulnerability plugins. More than 130 new audits delivered to customers. Read Tenable documentation.305Views0likes0CommentsGA Announcement – Tenable App for Microsoft Sentinel v3.1.2
Release Date: April 16, 2026 Hi everyone! We’re excited to announce the general availability (GA) of version 3.1.2 of the Tenable App for Microsoft Sentinel! This release includes minor enhancements and version updates to help you get the most from your integration. Resources Download & Install: Tenable App for Microsoft Sentinel – Azure Marketplace Documentation: Installation & Upgrade Guide What’s New Multiple rsyslog Support: Updated the Tenable IE (TIE) data connector UI to support multiple rsyslog configurations. Schema Updates: Updated the Tenable VM Vulnerability and Tenable WAS Vulnerability table schemas within the ARM Template for the Tenable Vulnerability Management data connector. SDK Optimization: Updated the Tenable Vulnerability SDK method to utilize indexed_at instead of last_found for improved data handling. We recommend you upgrade to v3.1.2 to ensure full support for these latest schema changes and connector enhancements. Questions? We’re here to help! Reach out to us in connect.tenable.com — Ahmad Maruf Principle Product Manager, Tenable Ecosystem112Views0likes0Comments[GA] Tenable Patch Management v10.0.971.26 is officially LIVE!
We are pleased to announce the General Availability of Tenable Patch Management (TPM) v10.0.971.26! This quality-focused update delivers critical stability and performance fixes for both On-Premise and SaaS environments. Enhanced Reliability & Precision Reporting This release addresses high-priority issues including strategy corruption, database scaling, and compliance reporting accuracy. Top Fixes to Pitch: Strategy Integrity: Fixes a critical defect where simplified patching strategies could become corrupted or fail to load "How to Patch" configurations. Precision Reporting: Corrects compliance percentage variables to eliminate "over 100%" reporting errors. Improved SaaS Reliability: Resolves "502 Bad Gateway" errors and database deadlocks by optimizing connection pooling and PostgreSQL-specific ports. Patch Filter Conditions: Corrects errors in Patch Filter UI and Tenable.Vpr filter handling. Added a dropdown for true/false boolean fields and updated VPR filters to require the Tenable.VprInteger format. Cloud Compatibility: Fixed the cloud install script (.sh) for successful execution when used in JAMF script payloads. Platform Modernization: Full integration of Java 25 and log4j 2.25.3 for peak security and performance. WSUS Intelligence: Improved WSUS scanning logic to mark patches as "Not Applicable" if a superseding patch is already present. P2P Configuration: New brp2p.minimum_viable_volunteer_count setting to better manage peer-to-peer download sources. Customer-Facing Resources: Release Date: March 5, 2026 Hotfix Version: 10.0.971.26 Changelog: View Release Notes Docs: TPM Complete Documentation Upgrade Path: SaaS/Cloud: Your SaaS Tenants are upgraded to v10.0.971.26 automatically. Please upgrade your clients accordingly. On-Premise: Customers can download the latest version of server and clients from the TPM Downloads portal immediately. Questions? We’re a ping away! Reach us at connect.tenable.com. Happy Upgrading! - Ahmad Maruf Tenable Patch Product Management156Views0likes0CommentsFebruary 2026 Tenable Product Newsletter
Greetings! Check out our February newsletter to learn about the latest product and research updates, upcoming and on-demand webinars and educational content — all to help you get more value from your Tenable solutions. Exposure 2026 Save 50% on the security conference of the year Don’t miss Exposure 2026, the first-ever conference dedicated exclusively to proactive, unified exposure management. Join us in Boston, Mass., from May 19-21, 2026, to get: Hands-on instruction with Exposure Management Strategy or Tenable One Technical Training Practical resources and real-world insights from Tenable leaders and industry experts Register before March 31 to save 50% off admission and training with early bird pricing. Tenable One Say hello to the Tenable One Open Connector We know your security stack is disparate, but your visibility shouldn't be. That's why we're thrilled to introduce the Tenable One Open Connector — a powerful new way to bridge the gaps across your attack surface and create a truly unified, context-aware view of risk. Bring your own data: Don't wait for a pre-built connector. Whether it’s pentesting reports or external vulnerability scans, you can now ingest data from across your entire stack on your own terms. Seamless uploads: Use in-platform drag-and-drop functionality to upload CSV, Excel, or ZIP files in seconds — no complex APIs or coding required. Customizable mapping: Customize exactly how you organize data for precise segmentation and more accurate reporting. Ready to unify your security data? Explore the Tenable One Open Connector. AI Exposure Tenable One AI Exposure now gives you visibility and control to close your AI exposure management gap through three core capabilities: Discover AI across your entire environment: Continuously discover shadow AI across your environment, so your security teams have a complete, risk-aware view of where AI exists, its connections, and where exposure begins. Protect AI workloads and agents: Reduce real-world AI risk by protecting the systems that power AI to close the gaps that attackers exploit across infrastructure, agents, and attack paths. Govern AI usage (add-on): Enable secure, compliant AI adoption by eliminating blind spots in how employees interact with GenAI and autonomous agents to ensure your workforce adopts generative tools within a governed framework that prevents data leakage and maintains alignment with organizational policies. For more information, visit our webpage or view the data sheet. Reach out to your customer success manager to get started today! Tenable Cloud Security At Tenable, we are obsessed with your uptime. This month’s updates focus on one goal… shortening the distance between discovering a risk and fixing it. The Highlight: Patch faster, firefight less We’ve integrated Remediation Patches (including Tenable Plugin IDs) directly into your vulnerability tables and workload profiles. The outcome: Drastically reduce Mean Time to Remediation (MTTR) by giving DevOps the exact patch name they need without all the manual research required. Where to find it: Check the new "Patch Name" column in your Vulnerabilities table or click into any Patch Profile for deep context. Validated vision: The Forrester Wave™ Q1 2026 Tenable has been named a Strong Performer in the Forrester Wave™: Cloud Native Application Protection Solutions (CNAPP), Q1 2026. Platform power: Forrester validated our vision for reducing tool sprawl, awarding Tenable a "superior" rating for simplifying exposure management. Perfect scores: We earned 5/5 scores in critical categories: CIEM, Container Orchestration Protection, Reporting, Vision, and Community. Technical edge: The report specifically highlighted our excellence in identifying toxic combinations of permissions and our "extra mile" customer support. Impactful updates Strategic risk management: Use our new Exclusions framework to silence non-actionable findings and focus your team on risks that actually move the needle. AWS ABAC support: Achieve True Least Privilege with granular identity visibility and highly accurate permission recommendations. Automation at scale: New GraphQL API support for Projects allows you to bake security governance directly into rapid DevOps workflows. View Full Cloud Release Notes Tenable Vulnerability Management Streamline AI and MCP risk tracking Monitor artificial intelligence exposure with the updated Tracking AI Exposure dashboard and report. This release replaces complex plugin output filters with simplified plugin family filters, allowing you to identify AI-related vulnerabilities across your environment. This also introduces dedicated content for the Model Context Protocol (MCP), ensuring you can secure AI connectivity alongside your LLM deployments. By utilizing these tools, you gain insight into your AI attack surface to better prioritize exposure. See the dashboard and report here. Navigate the transition to post-quantum cryptography Secure against the threat of quantum computing with Post Quantum Ciphers Analysis report and dashboards. As quantum computers advance, the standard RSA and Elliptic Curve Cryptography (ECC) algorithms for web browsing, VPNs, and identity verification will become vulnerable. By leveraging specialized plugins you can inventory your cryptographic landscape. This allows you to: Identify where RSA and ECC are currently deployed to prioritize your transition to quantum-resistant standards. Detect remote services and Web Application Scanning (WAS) environments that lack post-quantum cipher support. Pinpoint specific vulnerable ciphers, certificates, and assets that require immediate attention. This empowers you to manage the shift to post-quantum security, ensuring your data remains protected as computing capabilities evolve. See the dashboard and report to dive in. Maximize scan efficiency while protecting host & network performance Take full control of your sensor fleet with CPU resource and plugin download concurrency controls. This empowers you to balance essential security visibility with the performance needs of your business-critical infrastructure. CPU resource management: Protect host productivity by setting specific CPU utilization limits for Windows and Linux agents within your agent profiles. This ensures your security scans run efficiently without impacting the user experience or system stability. Bandwidth optimization: Avoid network congestion by governing how many agents or scanners download plugin updates at once. These global settings allow you to throttle traffic to accommodate limited internet pipes, ensuring your network remains responsive. These tools offer flexibility to scale your deployment without compromising network or host stability. For further information, see the release notes. Tenable Security Center Introducing Tenable Security Center 6.8 Our latest release introduces several new features and enhancements to streamline your security operations. Focus on real risk: Stop chasing 60% of Common Vulnerabilities and Exposures (CVE) as High or Critical. Start focusing on the 3% of CVEs that truly matter. Enhanced VPR logic and new AI-powered insights explain why an exposure is significant and provide clear mitigation guidance based on regional and industry-specific threat actor behavior. Streamlined infrastructure: We’ve unified IPv4, IPv6, and Agent repositories into a single, flexible Asset Repository type to reduce administrative overhead and give you more freedom in how you bucket and analyze your data. You can now target any data, including agent, network scan, and passive data, into any repository. Asset grouping and customization: The Explore Assets page includes new Group By options for Microsoft ID, Network, System Type, and Asset Criticality Rating (ACR). Other enhancements to the Explore Assets page include the ability to edit ACR scores (available in Tenable Security Center Plus) directly in the Explore interface. You can also export findings and installed software for specific assets to a comma-separated values (CSV) file. Background queries: Start a query and keep working. Tenable Security Center now processes long-running asset searches in the background. Scan optimization: Prevent performance issues with new per-host timeouts that keep your scan schedules on track to prevent a single host from increasing overall scan time. Enhanced security: Use at-rest encryption for External PostgreSQL databases and expanded PAM integration for Delinea and BeyondTrust. Before you upgrade: Tenable Security Center 6.8 supports upgrades from version 6.4.0 and later. Please review the updated hardware specifications in the release notes for optimal performance. Tenable OT Security Now available: Tenable OT Security 4.5 Our latest release delivers improved scalability for enterprise environments, enhanced power grid visibility, and enhanced Tenable One platform integration. Policy violation findings widgets: New widgets for High-Risk Violations and Operational Violations replace the former Events widgets in the Overview Dashboard, making it easier to distinguish between critical exposures from non-critical operational issues. Advanced dynamic tagging: Streamline prioritization and reporting with the ability to create rule-based groups and tags with multiple filters, including asset type, risk score, and criticality. Enhanced support for IEC 61850: Improve passive detection of intelligent electronic devices with comprehensive visibility across substation and power generation infrastructures. Unified SOC visibility: You can now directly view policy violations that Tenable OT Security detects, such as unauthorized access, failed logins or risky configuration changes, within Tenable Security Center dashboards and reports to give your security operations center (SOC) and IT security teams a unified view of both OT vulnerabilities and OT policy issues. Expanded compliance mapping: Simplify how you track, measure, and report against critical security frameworks with the ability to directly map asset data and policies to NIST CSF as well as IEC 62443-3-3 to improve visibility for electrical substation and power grid environments. Role-based access controls (RBAC): Tenable Enterprise Manager now enables admins to assign users to specific ICPs using user groups, so users only view the zones they’re authorized to see while inheriting ICP-level roles. New protocol and device coverage: Tenable identifies several new vulnerabilities in this release for devices from multiple vendors, including ABB, ANDRITZ HYDRO GmbH, Barco, General Electric, Generex, HP, Lexmark, Schneider, and others. See the complete list here. Note: Upgrades from versions prior to 4.4 may take longer than usual due to the migration of policy events. If you have hundreds of thousands of events, upgrades can take about 30 minutes. Access the release notes to learn more. Tenable Identity Exposure Our February rollout focuses on hardening the Active Directory attack surface and ensuring the integrity of your detection engine. To maintain a resilient identity posture, we have introduced visibility into transient objects and streamlined health monitoring for your infrastructure. Hardening dynamic AD environments: This new Indicator of Exposure (IoE) detects Dynamic Objects Misconfiguration and Usage. This enhancement mitigates risk by identifying transient objects that attackers could exploit for unauthorized access or persistence. Detection engine integrity: We have optimized Domain Installation health checks to ensure your security stack operates at peak performance: Conflict resolution: The system now flags redundant "Tenable IoA GPO EVT Subscribe Listener" files within your SYSVOL. System optimization: Identifying these multiple versions ensures you are running the latest configuration, preventing detection lag or GPO conflicts. View Full Identity Release Notes Tenable Ecosystem Tenable Add-on for Splunk v8.0.2 Tenable has released version 8.0.2 of the Tenable Add-on for Splunk. This latest quality update improves data reliability by resolving a specific index_time race condition previously affecting Tenable Security Center. For more information, please read the Tenable Documentation, and visit Splunkbase to download. Tenable WAS Integration for ServiceNow VR v30.2.0 Tenable has fully integrated Tenable Web App Scanning (WAS) with the ServiceNow Vulnerability Response (VR) app (v30.2.0). This update enables security teams to automatically synchronize application metadata and DAST vulnerability findings directly into ServiceNow to unify remediation workflows. Key benefits: CMDB correlation: Automatically map WAS findings to your CMDB applications for enhanced asset context. Scalable ingestion: Uses Tenable Export APIs to retrieve data in chunks, ensuring high performance for large-scale environments. Flexible lookups: A new Lookup Strategy field enables independent configuration of CI Lookup or Product Model settings for each integration. Broad compatibility: Fully compatible with ServiceNow’s Zurich, Yokohama, Washington, and Xanadu releases. For more details, read the ServiceNow User Guide and visit the ServiceNow Store for the appropriate Tenable apps for ServiceNow. Tenable Plugin for Jira On-premises v11.0.0 Tenable has released version 11.0.0 of the Tenable Plug-in for Jira (On-Prem), adding full support for Jira 11.x Data Center environments. This update modernizes the tech stack to streamline vulnerability remediation workflows. Automatically synchronize findings from Tenable Vulnerability Management, Security Center, and Web App Scanning directly into Jira tickets. Please note: This version is not backward compatible with Jira versions earlier than 11.x; users on Jira 9.x or 10.x must upgrade their Jira environment to use this plugin. For more information, please read the Tenable Documentation and visit Atlassian Marketplace to download the newest versions. Tenable Connect The Tenable Connect Resource Center expansion now better supports your Tenable journey! Look for the question mark in the bottom right-hand corner of any Tenable Connect page for quick access to submit feature requests, and find essential onboarding materials and info on upcoming office hours. Customer Office Hours These are recurring ask-me-anything sessions for Tenable Security Center, Tenable Vulnerability Management, Tenable Cloud Security, Tenable Identity Exposure, and Tenable OT Security. Time-zone-appropriate sessions are available for the Americas, Europe (including the Middle East and Africa), and Asia Pacific (APJ). Learn more and register here. Tenable Webinars See all upcoming live and on-demand webinars here. Tenable Research Research Security Operations blog posts Subscribe to the Research team blog posts here. I pretended to be an AI agent on Moltbook, so you don’t have to LookOut: Discovering RCE and internal access on Looker (Google Cloud & On-prem) From Clawdbot to Moltbot to OpenClaw: Security experts detail critical vulnerabilities and 6 immediate hardening steps for the viral AI agent Tenable discovers SSRF vulnerability in Java TLS handshakes that creates DoS risk Research release highlights Improvements to live kernel patching detection: Tenable has improved the logic used to detect live-patched kernels to include the running kernel to support KernelCare for Alma Linux, CentOS, CentOS Stream, Fedora, Oracle Linux, Red Hat Linux, and Ubuntu Linux. Backported vulnerability detection improvements: Banners that indicate a Linux distribution will be considered backported by default. Content coverage highlights Almost 15,000 new published vulnerability plugins. More than 38 new audits were delivered to customers. Read Tenable documentation.419Views0likes0CommentsIntroducing Tenable Security Center 6.8
Our latest release, Tenable Security Center 6.8, introduces several new features and enhancements to streamline your security operations: Focus on real risk: Stop chasing 60% of Common Vulnerabilities and Exposures (CVE) as High or Critical. Start focusing on the 3% of CVEs that truly matter. Enhanced VPR logic and new AI-powered insights explain why an exposure is significant and provide clear mitigation guidance based on regional and industry-specific threat actor behavior. Streamlined infrastructure: We’ve unified IPv4, IPv6, and Agent repositories into a single, flexible Asset Repository type to reduce administrative overhead and give you more freedom in how you bucket and analyze your data. You can now target any data, including agent, network scan, and passive data, into any repository. Asset grouping and customization: The Explore Assets page includes new "Group By" options for Microsoft ID, Network, System Type, and Asset Criticality Rating (ACR). Other enhancements to the Explore Assets page include the ability to edit ACR scores (available in Tenable Security Center Plus) directly in the Explore interface. You can also export findings and installed software for specific assets to a comma-separated values (CSV) file. Background queries: Start a query and keep working. Tenable Security Center now processes long-running asset searches in the background. Scan optimization: Prevent performance issues with new per-host timeouts that keep your scan schedules on track to prevent a single host from increasing overall scan time. Enhanced security: Use at-rest encryption for External PostgreSQL databases and expanded PAM integration for Delinea and BeyondTrust. Before you upgrade: Tenable Security Center 6.8 supports upgrades from version 6.4.0 and later. Please review the latest updates to Tenable Security Center hardware specifications in the release notes for optimal performance.1.1KViews1like0Comments