product announcement
57 Topics[GA Release] Tenable App for Splunk v6.1.1 and Tenable Add-on for Splunk v8.0.3 Now Live!
Hi everyone! Tenable App for Splunk v6.1.1 and Tenable Add-on for Splunk v8.0.3 are officially GA and available now on Splunkbase! Release Date: July 27, 2026 Download: Tenable App for Splunk on Splunkbase Tenable Add-on for Splunk on Splunkbase Docs & User Guide: Tenable App for Splunk Documentation Tenable Add-on for Splunk Documentation What’s New? Bumped the minimum required Python version to 3.13 as per Splunk standards. Compatibility Matrix: Browser: Google Chrome, Mozilla Firefox OS: Platform Independent Splunk Enterprise version: 10.2.x, 10.0.x, 9.4.x and 9.3.x Supported Splunk Deployment: Splunk Cluster, Splunk Standalone, and Distributed Deployment Questions or Feedback? If you have feedback or questions, we’d love to hear from you! - Tenable Ecosystem Product Management3Views0likes0CommentsTenable Product Update Newsletter — July 2026
Check out our July newsletter to learn about the latest product and research updates, events, and educational content. Plus, this month we’re featuring the launch of the CyberAgents Exchange, powered by Tenable. Keep reading to read more about the new open-source AI exchange! Tenable One - Platform updates Integrate application security data into Tenable One for code-to-runtime security Your codebase is growing faster than your security program, and in the age of AI, developers are introducing security findings at 10 times the rate of their peers. It is critical to see code as part of your entire attack surface. Application security data now integrates directly into Tenable One to further close visibility gaps and ensure secure code development in the AI era. Whether code is human- or machine-written, you can now integrate application security risks, like those from Snyk, Claude Security, or any other application security tool via Tenable One Connectors — directly alongside your existing exposure data. What this means for you: Achieve full code-to-runtime visibility by bringing application security risks together with the rest of your exposure data in one place. Fix code flaws before they become incidents by identifying your most business-critical code flaws and fixing them early in the development lifecycle. Measure organizational exposure and transform technical static code vulnerabilities into clear risk metrics on business resilience. Read the blog post Explore the guided demo Check out Open Connector documentation and Snyk Connector documentation Improved workflow orchestration capabilities in Tenable One Vulnerability Management and Tenable One New enhancements to Tenable's workflow orchestration capabilities are now generally available. This release streamlines remediation workflows and improves operational efficiency with the following key updates: Plugin output in tickets: You can now attach Plugin Output directly to tickets, providing immediate context and critical information while eliminating the need for further navigation. Tenable Hexa AI for ServiceNow: You can now leverage Tenable Hexa AI for ServiceNow incident and initiative creation to match already available Jira functionality. Review the exposure management release notes Review the Tenable Vulnerability Management release notes Tenable unified scoring is now live Tenable has unified its risk prioritization standard, moving the high-fidelity Vulnerability Priority Rating (VPR) model out of beta to become the sole standard. To sharpen your prioritization, an updated asset classification engine also delivers more accurate Asset Criticality Ratings (ACR) for your assets. Because VPR and ACR feed directly into your Cyber Exposure Score (CES) and Asset Exposure Score (AES), your console will automatically update to reflect a precise understanding of your exposure. These recalculations occur automatically, though completion times depend on the size of your environment. To prevent errors in your saved views, you must manually update any filters or combinations that still use VPR v1. No data migration is required. Visit Tenable Connect for more details Learn more about Tenable One scoring The CyberAgents Exchange, powered by Tenable Tenable launches the industry’s first open-source AI exchange (and we want your agents on it) Security teams are building AI agents in isolation, reinventing the wheel with no neutral place to share what actually works. The CyberAgents Exchange, powered by Tenable, is the only purpose-built, cybersecurity-native registry for AI agents, skills, MCP servers, and multi-agent playbooks in the current market. Built by defenders. For defenders: Purpose-built for security teams to solve the exposure problems practitioners actually face. Collective defense for the agentic era: Anyone can contribute; everyone benefits. Agents and skills are shared under open licenses with no fees or gates. Trust through transparency: Every agent links directly to its source repository, so there are no bundled binaries or black boxes. Build your reputation. Elevate your craft: Contributing is career capital. We give practitioners a platform to earn validation and build an undeniable resume. Join the community, build your reputation, and start automating risk reduction. Explore the directory and submit your builds Tenable One Cloud Exposure Tenable One Cloud Exposure achieves FedRAMP High authorization Tenable is committed to being the trusted partner of choice for the public sector, providing the advanced protection required for the U.S. government’s most sensitive environments. We are proud to announce that Tenable One Cloud Exposure has achieved FedRAMP High and Impact Level 5 (IL5) authorization. Purpose-built for sensitive government cloud environments, this high-level authorization delivers: Unified visibility: Gain a single view across infrastructure, identities, and workloads — even in air-gapped environments. Zero-trust enforcement: Leverage advanced identity analytics to enforce least privilege principles and align with DoW CIO mandates. Blast radius reduction: Map the Web of Risk to see how vulnerabilities connect to identities and sensitive data, stopping problems before they snowball. Cost reduction: Support fiscal modernization by eliminating tool sprawl and reducing costs without compromising security. Read the press release Learn more about our FedRAMP High solutions Take control of your sensitive data When data classification engines scan the cloud, they often flag false positives, like internal test data, mock databases, or benign corporate email domains, as critical risks. With Tenable’s new data classification exclusions, customers can fine-tune their data scans to get to the bottom of what’s actually sensitive. Exclude by resource scope: Narrow exclusions to specific data types or resources using user-friendly Explorer-based queries. Exclude specific values: Filter out known text patterns or regex strings (like internal email domains). Target precise locations: Use OR logic to pinpoint exact databases, schemas, tables, file extensions, or object paths. Learn how to create a data classification exclusion Read about the recent releases here Tenable One Web App Scanning Authenticate web app scans with OAuth 2.0 You can now scan protected applications and APIs using OAuth 2.0 authentication within Tenable One Web App Scanning. Configure these options under your scan credential settings using three supported flows: Authorization code: For user-driven logins, with optional PKCE and Selenium scripting for complex identity providers. Client credentials: For machine-to-machine API scans without user interaction. Device code: For headless and device-style authentication. To prevent scans from silently losing access, authorization verification continuously validates your session via response patterns, headers, or HTTP status codes across all credential types. Integrate these capabilities immediately through your existing credentials API without changing endpoints. You can call the List Credential Types endpoint to programmatically discover the new fields. Review the documentation Review the release notes Tenable One OT Exposure Extended OT visibility for grid operators and disconnected environments Our latest Tenable One OT Exposure release expands visibility for grid operators and disconnected environments, and introduces productivity and performance enhancements to accelerate analyst workflows. OT agent for disconnected environments: Secure air-gapped and isolated networks without deploying sensors or requiring live connectivity, featuring offline scan profiles, a local agent interface tailored for field technicians, and centralized Network Areas to resolve duplicate IP conflicts across distributed sites. Power substation anomaly detection: Passively monitor GOOSE streams and alert on anomalous activity (e.g., code revision changes) to protect utility and grid operations from unauthorized modifications or replay attacks. Yokogawa DCS activity detection: Get deep visibility into engineering activities on Yokogawa Centum VP systems to detect changes to critical operations and unauthorized access, including controller start/stop, code edits, function block changes, tag writes/deletes, and more. Simplified enterprise management: Manage all ICP subnets from a single Enterprise Manager interface — define CIDR boundaries, toggle monitoring per-site, and eliminate the need for per-ICP configuration for monitoring different network areas. Analyst workflow improvements: Reuse investigations with Saved Views, review Assets and Findings details faster with a quick-access side panel, and secure syslog transport with TLS support. Explore the user guide Review the release notes Tenable Security Center Reimagined vulnerability analysis, flexible deployment, and streamlined operations Tenable Security Center 6.9, now available in early access, modernizes vulnerability analysis and expands enterprise deployment flexibility with a reimagined query experience and deeper PAM and credential integrations. Explore Findings: A redesigned vulnerability query interface with expanded filtering and VPR key drivers surfaced directly in the findings detail panel. Tenable Nessus scanners via Tenable Sensor Proxy: Deploy Tenable Nessus scanners through Tenable Sensor Proxy for flexible, scalable enterprise and Tenable Enclave Security environments. Windows LAPS and PAM Kerberos support: Dynamically retrieve scan credentials via Windows LAPS and Kerberos Target Authentication across all supported PAM integrations. Performance improvements: Submit diagnostic bundles directly to Tenable Support, suppress rollover scans during freeze windows, and benefit from a modernized data architecture that reduces disk usage. Explore the user guide Download the early access release Tenable Ecosystem Now available: PyTenable 26.6.1 PyTenable 26.6.1 has officially been released, introducing a new temporal versioning scheme (YEAR.MONTH.PATCH) to better align with rapid API changes and enable critical updates to older modules. Marshmallow v4 support: Resolved issues preventing the use of newer Marshmallow versions. APA export: Added support in the current Tenable One package. Streamlined testing: Refactored workflow processes mean you no longer need Act and Docker installed just to run the test suite. Bug fixes: Addressed various minor issues introduced by recent API changes. Moving forward, support will be provided for the current month minus three releases, so we highly recommend pinning your software to a specific release and testing against the latest. Visit the PyTenable GitHub repository Training and product education Tenable One Exposure Management Platform introduction course includes CTEM This introductory course in Tenable University now incorporates the foundations of the Continuous Threat Exposure Management (CTEM) framework to identify exposures, prioritize remediations, and reduce risk across your modern attack surface. Practitioners and partners will learn the fundamentals of continuous hybrid asset discovery, risk-based scoring, and validating critical attack paths to effectively manage security posture. This no-cost course serves as the essential primer and recommended prerequisite for the Specialist tier. Access the course on demand in Tenable University On-demand Tenable One Exposure Management Platform Specialist course now available This brand-new paid Tenable University training course provides comprehensive Continuous Threat Exposure Management (CTEM) lifecycle training across the entire Tenable One architecture. The Specialist-level course delivers deep technical coverage of the Tenable One Exposure Management Platform, including: Tenable One Vulnerability Management Tenable One Attack Surface Management Tenable One Identity Exposure Tenable One OT Exposure Tenable One Cloud Exposure Tenable One Web App Scanning Practitioners will gain proficiency in third-party data integration, advanced asset tagging, and context-aware analytics (such as Attack Path Analysis and Exposure Signals) to drive risk-based prioritization and deliver actionable executive dashboards. Eligible for Continuing Education (CE) credit. Learn more and purchase online Tenable events and webinars Customer office hours These are recurring ask-me-anything sessions for Tenable Security Center, Tenable One Vulnerability Management, Tenable One Cloud Exposure, Tenable One Identity Exposure, and Tenable One OT Exposure. Time-zone-appropriate sessions are available for the Americas, Europe (including the Middle East and Africa), and Asia-Pacific (APAC). Learn more and register Virtual events Now on demand — Tenable customer update, July 2026: Watch the most recent quarterly customer update session. This informative, fast-paced overview explores how to better secure your expanding attack surface and consolidate critical security data. Products covered include: Tenable One, Tenable One AI Exposure, Tenable One Vulnerability Management, and Tenable Security Center. Watch on demand See all upcoming live and on-demand webinars Read Tenable documentation.304Views0likes0CommentsNow available: Integrate application security data into Tenable One for code-to-runtime security
Your codebase is growing faster than your security program, and in the age of AI, developers are introducing security findings at 10 times the rate of their peers. It is critical to see code as part of your entire attack surface. We’re excited to announce that application security data can now be integrated in Tenable One to further close visibility gaps and ensure secure code development in the AI era. Whether code is human or machine-written, you can now integrate application security risks—like those from Snyk, Claude Security, or any other application security tool via Tenable One Connectors—directly alongside your existing exposure data. What this means for you: Achieve full code-to-runtime visibility by bringing application security risks together with the rest of your exposure data in one place. Fix code flaws before they become incidents by identifying your most business-critical code flaws and fix them early in the development lifecycle. Measure organizational exposure and transform technical static code vulnerabilities into clear risk metrics on business resilience. Ready to integrate application security data into Tenable One? Read the blog post Explore the guided demo Check out Open Connector and Snyk Connector documentation33Views0likes0CommentsIntroducing The CyberAgents Exchange: The Open-Source Hub for Cybersecurity AI
Attackers are adopting AI alarmingly fast, while frontier models are escalating exposure at an unprecedented scale. Meanwhile, security teams are building AI agents in isolation, solving the same problems, and reinventing the same tools with no neutral place to share what works. Collective defense only works if the community can act on it together. That is why we are thrilled to announce The CyberAgents Exchange, powered by Tenable. The CyberAgents Exchange is the open-source, vendor-agnostic hub for practitioners and CISOs to discover, share, and collaborate on AI agents, skills, MCP servers, and playbooks built for cybersecurity. Why The CyberAgents Exchange? The best security solutions come from practitioners closest to the problem. The Exchange is purpose-built for security teams, providing the infrastructure to automate workflows without reinventing the wheel. Here is what you can expect: Open-source and vendor-neutral: Agents work with any stack and are not locked to one platform. Trust through transparency: Every agent on the Exchange links directly to its source repository, so there are no bundled binaries or black boxes. Community-built credibility: The Exchange is curated by security professionals, for security professionals. Completely free: There are no fees to list or use agents, and the Exchange is open to any organization. Start Building Together Whether you are looking to browse production-tested agents, install skills, connect MCP servers, or compose multi-agent playbooks, the CyberAgents Exchange gives you the tools to scale your security operations. If you are already building agents, this is your platform to share your work, earn public validation, and elevate your craft. Ready to add your expertise? Head to exchange.tenable.com to get started! Navigate to the Contribute page via the top navigation bar to see step-by-step instructions on how to easily contribute an agent, skill, MCP server, or playbook to the site.104Views1like0CommentsTenable One Cloud Exposure achieves FedRAMP High and IL5 Authorization
At Tenable, we are committed to being the trusted partner of choice for the public sector, providing the advanced protection required for the U.S. government’s most sensitive environments. We are proud to announce that Tenable One Cloud Exposure has achieved FedRAMP High and Impact Level 5 (IL5) authorization. Why this matters for the federal mission This milestone significantly expands our ability to support high-security federal environments, including those used by the Department of War (DoW) and intelligence agencies. As agencies accelerate cloud modernization and AI adoption, they face an increasingly complex landscape of misconfigured workloads and fragmented security tools. Tenable One Cloud Exposure addresses these challenges by consolidating critical security functions into a single, cost-efficient platform. This authorization enables new mission-critical use cases, including classified and tactical edge deployments, ensuring operational effectiveness for the AI era. Key impact and capabilities Purpose-built for sensitive government cloud environments, this high-level authorization delivers: Unified visibility: Gain a single view across infrastructure, identities, and workloads—even in air-gapped environments. Zero trust enforcement: Leverage advanced identity analytics to enforce least privilege principles and align with DoW CIO mandates. Blast radius reduction: Map the "Web of Risk" to see how vulnerabilities connect to identities and sensitive data, stopping problems before they snowball. Cost reduction: Support fiscal modernization by eliminating tool sprawl and reducing costs without compromising security. What this means for you Starting in June, federal agencies can leverage Tenable One Cloud Exposure to protect sensitive data and mission-critical operations across all classification levels. This new authorization complements our existing FedRAMP High and IL5 authorization for Tenable Enclave Security, providing a comprehensive ecosystem for the most demanding federal security standards. Learn more about our FedRAMP High solutions here.58Views0likes0CommentsTenable product update: Standardizing Tenable risk scoring
At Tenable, we are committed to providing the most accurate, defensible, and actionable view of organizational risk. To achieve this, we must continually refine the intelligence that powers your prioritization. On July 1, 2026, we are implementing a series of foundational updates to our risk scoring engines. As part of this update, you may see changes to your risk scores, depending on the Tenable product(s) you own. These changes simplify your workflow by standardizing scoring on a single, high-fidelity model for vulnerability and asset risk. The new standard for VPR For the past several months, many of you have utilized VPR (Beta) to gain deeper insights into exploitability. We are excited to announce that on July 1, this model will be promoted to the primary Vulnerability Priority Rating (VPR) across the Tenable platform. By standardizing on this advanced model, we are retiring legacy VPR scoring to ensure every customer benefits from our most sophisticated threat intelligence. The new version of VPR incorporates more threat intelligence and vulnerability metadata so that you can focus on the 1.6% of vulnerabilities that actually matter. Better context through enhanced asset classification Alongside the VPR update, we are enhancing our asset classification engine. This update improves how we identify the function and importance of assets across your entire attack surface, including Cloud, OT, and third-party devices. As a result, customers with access to Asset Criticality Ratings (ACR) for VM assets will see these scores more accurately reflect real-world business risk. What this means for you These are backend enhancements designed to provide immediate value with zero manual configuration. On July 1, your dashboards, reports, and APIs will automatically reflect these updated metrics. Because both VPR and ACR serve as inputs to Cyber Exposure Score (CES) and Asset Exposure Score (AES), customers using these scores may see changes that reflect a more accurate understanding of exposure. Customer FAQ What happens to the VPR (Beta) score in the Tenable UI? The Beta label will be removed. The high-fidelity model you’ve been previewing will become the standard VPR. The legacy version of VPR will be retired to ensure a single, unified source or truth. Do I need to rewrite my custom API scripts using VPR? No. For customers using APIs, updated values will be mapped into legacy VPR fields on the back end to ensure compatibility and a smooth transition for your scripts and third-party tools. How does this affect my SLAs? Because many organizations use VPR as their operational prioritization layer, your SLA statistics and remediation tracking will now reflect the more precise scoring model. This helps ensure your team is meeting response goals for the vulnerabilities that pose the highest actual risk. How does Enhanced Asset Classification affect my scores? The system now automatically identifies the function and criticality of assets across Cloud, OT, and third-party sources. This improved context leads to more accurate Asset Criticality Rating (ACR) adjustments. For customers with access to ACR, this ensures your most critical business assets are effectively prioritized. What actions does my team need to take, and when will the changes be reflected in my container? These updates will occur automatically within your Tenable console. Depending on the size of your environment, it may take time for score recalculations to be fully reflected across your console. For a detailed guide on our enhanced VPR, check out this FAQ. Want to see the why behind our scoring? View our scoring explained.5.7KViews8likes12CommentsGA Release - Tenable ServiceNow Apps Now Australia Compatible!
Release Date: June 22, 2026 Included Applications and Versions: Service Graph Connector for Tenable: Version 6.3.0 Tenable for ITSM: Version 6.2.0 Vulnerability Response Integration with Tenable: Version 30.4.1 WHAT'S NEW? Tenable is excited to announce the General Availability for our ServiceNow apps, fully compatible with the Australia Platform Release. This rollout introduces significant feature updates, bug fixes, and stability enhancements across our core integration codebase: Configurable Asset Ingestion Limits: Resolves payload failures by collecting and deduping IP, FQDN, and MAC data on a per-asset basis before submitting to the Tenable Vulnerability Management API. It features an adjustable asset property ceiling that defaults to 100 records and can be scaled up to 1,000 for complex environments via a custom system property config. Predictive Asset Dropped Warning Logs: Adds clear localized logs inside ServiceNow that capture the impacted Configuration Item sys_id, the total volume of asset records received, and a structural breakdown of any metrics dropped when violating max limits. Codebase Security Hardening: Completely eliminates the deprecated global GlideEncrypter API call from our source codebase. This satisfies strict compliance criteria following customer instance health assessment scans that flag deprecated commands as security risks. Optimized OS Transformation Handling: Mitigates transactional script processing delays and timeout failures within the core cleanse() operation method. The updated connector parses choice items more efficiently against massive database environments with large sys_choice table counts. OT Device Schema Correction: Fixes data transformation crashes and java.lang.IllegalArgumentException errors when processing complex IT/OT hybrid nodes like workstations populated via WMI queries. The ingestion rules seamlessly process structural repetitions found within the hotFixes and devicesAndDrives sections of the API response without stalling the import set queue. PLATFORM COMPATIBILITY: Supported ServiceNow Releases: Australia, Zurich, Yokohama, and Xanadu. Supported Tenable Platforms: Tenable Vulnerability Management, Tenable Security Center version 5.7 or later, and Tenable OT Security QUESTIONS? We are here to help! Reach out to us at connect.tenable.com! -Ecosystem Product Management129Views0likes0CommentsTenable Product Update Newsletter — June 2026
Check out our June newsletter to learn about the latest product and research updates, events, and educational content. Tenable One - Platform Updates Improve exposure prioritization in Tenable One with continuous security control validation As frontier AI models accelerate vulnerability discovery, the work of validating, prioritizing, and remediating vulnerabilities alongside other security weaknesses to understand the true exposure they create has become much more urgent. Validation in exposure management is a key capability to help you understand which exposures attackers can actually reach by understanding the accessibility and exposure. Prioritize exposures more effectively by seeing which attack paths active prevention and detection controls mitigate. Accelerate investigations and triage by filtering top attack paths and attack techniques based on the presence of security controls. Understand control context and status by viewing security control information in the node details view. Check out continuous control validation in Tenable One: Read the blog post Explore the guided demo Read more about Attack Technique Details Tenable One Vulnerability Management Implement granular custom roles for enhanced access control Give your teams exactly the access they need to do their jobs — without exposing sensitive scan settings, sensors, or compliance reports. Streamline access control by building custom roles. You can now build granular custom roles that dictate exactly what your users can see and do within the platform. With straightforward, one-click toggles, you can grant read or full-write access to specific tools like scans, sensors, or reports. Your existing custom roles will automatically transition to this new format, so existing custom roles will transition seamlessly with no manual migration required. Take the guided walkthrough Read the documentation Review the best practice guide Gain comprehensive visibility into endpoint application risk Managing decentralized endpoint applications introduces visibility gaps. Focus your patching on the software your employees actually use, instead of chasing thousands of generic alerts. Get a single view of all software running on your endpoints with the new Endpoint Application Visibility and Exposures One-Stop Shop report. Prioritize fixes based on how widely an app is deployed and its actual risk to your business, rather than just relying on generic severity scores. Access the endpoint application visibility report Enhance your threat analysis expertise with specialist training You can now access the updated instructor-led Tenable One Vulnerability Management Specialist Course in Tenable University, featuring: Streamlined curriculum focusing on advanced analysis, enabling you to interpret data and counter threats faster. Deep dives into critical new features, including Vulnerability Intelligence and Exposure Response. Refreshed educational experience with hands-on lab exercises to solidify your expertise. Learn more about this course and other instructor-led and on-demand Tenable University training and certification offerings: Course details Tenable training and certification Tenable One Cloud Exposure Transform disparate alerts into one threat story with Tenable cloud detection and response Cloud detection and response (CDR) in Tenable One Cloud Exposure is now generally available, adding near-real-time behavioral detection across multi-cloud environments. Tenable CDR capabilities include: AI-powered threat stories: AI-powered threat stories automatically correlate related detections by actor, resource, and tactic, transforming hundreds of raw alerts into a clear narrative of the attack, allowing teams to start investigating instantly. Runtime vulnerability validation: Uses active scanning to confirm cloud resources that are reachable from the internet. Dual coverage: Combines agentless detections with an optional eBPF runtime sensor, giving security teams comprehensive near-real-time visibility across cloud workloads without sacrificing deployment flexibility or coverage. Guided response: As the agentic engine of Tenable One, Tenable Hexa AI is the intelligence layer that reasons across live exposure context, threat findings, and environment history to deliver a prioritized, actionable response plan, in plain language, at attacker speed. With Tenable CDR, teams can leverage AI-driven pathways to investigate and remediate with speed, drive informed, actionable resolution, close the exposure gap, and extend attack path analysis to holistic remediation of real threats. Watch the guided demo Tenable One OT Exposure Tenable OT Security 4.7 (early access) This release expands visibility for grid operators and disconnected environments, and introduces a variety of productivity enhancements to accelerate analyst workflows: Power substation anomaly detection: Passively monitor GOOSE streams and alert on anomalous activity to protect utility and grid operations from unauthorized modifications or replay attacks. Yokogawa DCS activity detection: Get deep visibility into engineering activities on Yokogawa systems to easily detect critical operations and unauthorized access. OT agent for disconnected environments: Secure air-gapped networks without deploying sensors or requiring live connectivity, featuring offline scan profiles and a local agent UI. Workflow and enterprise management enhancements: Centrally manage subnets from a single Enterprise Manager interface, and speed up recurring investigations with new Saved Views, a quick-access Asset Side Panel, and TLS Syslog support. Explore the user guide Review the release notes Tenable Security Center Tenable Security Center 6.8 Focus on the vulnerabilities that matter with AI-powered VPR insights and mitigation guidance. This release streamlines your operations with unified asset repositories for IPv4, IPv6, and Agents, and improves efficiency with new background query processing and scan optimization capabilities. View the full release notes Tenable Nessus Maximize your Nessus capabilities with the Tenable Documentation hub Optimize your vulnerability assessments and accelerate troubleshooting with the official Tenable Nessus Documentation hub. Want to ensure you’re getting the absolute most out of your vulnerability assessments? Whether you’re a seasoned security pro fine-tuning your environment or just setting up your first Nessus Pro or Expert deployment, the hub provides everything you need to optimize your security workflows and troubleshoot: Stay ahead of the curve: Instantly access the latest release notes, system requirements, and seamless upgrade guides. Optimize your assessments: Find step-by-step instructions for configuring and launching scans. Streamline your reporting: Learn exactly how to customize, generate, and export compliance-ready scan results in PDF, HTML, or CSV formats to keep your stakeholders informed. Bookmark the documentation site to quickly discover new features, resolve configuration questions, and keep your attack surface secure. Tenable Nessus documentation Tenable Patch Management Synchronize asset tags across patching workflows Sync your existing security tags directly with your patching workflows to eliminate manual setup and fix vulnerabilities faster. If you already group your devices using tags or asset lists in Tenable One Vulnerability Management or Tenable Security Center, those groups will automatically synchronize with your patch console. You can target them for patch schedules and deployment waves without rebuilding them from scratch. This update also extends full patch support to SUSE Linux 15 SP6 (Server & Desktop). Get the full update details on Tenable Connect Tenable events and webinars Customer office hours These are recurring ask-me-anything sessions for Tenable Security Center, Tenable One Vulnerability Management, Tenable One Cloud Exposure, Tenable One Identity Exposure, and Tenable One OT Exposure. Time-zone-appropriate sessions are available for the Americas, Europe (including the Middle East and Africa), and Asia-Pacific (APAC). Learn more and register Virtual events Tenable customer update, July 2026: Join the next quarterly customer update session at 11 a.m. EST/3 p.m. BST/5 p.m. CEST July 16. This informative, fast-paced overview will explore how to better secure your expanding attack surface and consolidate critical security data. Products covered include: Tenable One, Tenable One AI Exposure, Tenable One Vulnerability Management, and Tenable Security Center. Register See all upcoming live and on-demand webinars Tenable Research Research security operations Read the latest insights from top security and data science researchers: Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect Key findings from the Verizon DBIR 2026 Read Tenable documentation.647Views1like0CommentsImprove exposure prioritization in Tenable One with continuous security control validation
The work of validating, prioritizing, and remediating vulnerabilities alongside other security weaknesses to understand the true exposure they create has become much more urgent, as frontier AI models accelerate vulnerability discovery. Validation in exposure management is a key capability to help you understand which exposures attackers can actually reach by understanding the accessibility and exploitability of an attack path. Today, we’ve added important validation capabilities in Tenable One with continuous security control validation. By factoring in your active security controls, Tenable One helps eliminate the noise of theoretically exposed assets that are functionally blocked from exploitation. What this means for you: Prioritize exposures more effectively by seeing which attack paths are mitigated by active prevention and detection controls. Accelerate investigations and triage by filtering top attack paths and attack techniques based on the presence of security controls. Understand control context and status by viewing security control information in the node details view. Ready to check out continuous control validation in Tenable One? Read the blog post Explore the guided demo Read more about Attack Technique Details125Views0likes0CommentsTenable Patch Management v10.1.972.17 is now available!
We are pleased to announce the general availability of Tenable Patch Management v10.1.972.17 for both SaaS and On-Premise environments. This update balances critical security hardening with substantial performance optimizations and highly requested ecosystem integrations to streamline your remediation workflows. Here is everything you need to know about the new enhancements and fixes included in this release. ✨ Release highlights 1. Unified vulnerability and remediation workflow: Tenable Asset Tag integration We have deeply integrated Tenable Patch Management with your broader Tenable ecosystem, allowing you to ingest and sync Tenable Vulnerability Management Asset Tags and Tenable Security Center Asset Lists. Rather than manually reconstructing your organization's device groups, you can now leverage your existing security infrastructure directly within your patching workflows. This integration allows you to: Gain instant visibility: View and browse your Tenable Vulnerability Management Tags or Tenable Security Center Asset Lists directly inside the Tenable Patch Management console workspace. Build dynamic business units: Instantly create Business Units (BUs) using your Tenable Vulnerability Management Tags or Tenable Security Center Asset Lists using a familiar Tag -> Category -> Value syntax. Streamline patch automation: Select these newly created BUs to configure, schedule, and execute both Standard and Advanced Patching Strategies. Structure phased rollouts: Seamlessly map tag-derived BUs into Deployment Waves to manage risk and test patches across staged deployment groups. Delegate granular controls (RBAC): Assign dedicated Branch Office Administrators to manage specific BUs built from your tags and asset lists, keeping local permissions aligned with corporate risk groups. 2. Expanded fleet coverage: SUSE Linux 15 SP6 support We have expanded our cross-platform patching engine to deliver full client compliance and patch metadata support for SUSE Linux Enterprise Server (SLES) 15 SP6 across both Server and Desktop architectures. 3. Streamlined, unified licensing UI We have globally removed all legacy "Enterprise" and "Express" product labels across both SaaS and On-Premise interfaces. Legacy references to "Patch Express" have been removed, and "Enterprise" has been cleared from Patch Enterprise Roles to deliver a clean, confusion-free workspace where every deployment unlocks the full power of the patching engine. 4. Rigorous platform hardening Core binaries have been meticulously upgraded to eliminate known application vulnerabilities: Log4j upgraded to 2.25.4 (resolving CVE-2026-34478, CVE-2026-34480, and CVE-2026-34477). OpenJDK/JRE upgraded to 25.0.3 (Zulu version 25.34.17). Apache Commons FileUpload upgraded to 1.6.0 (resolving CVE-2025-48976). OpenSSL upgraded to 3.6.2. 📈 Performance and reporting optimizations To improve administrative efficiency and console speed, we have introduced several significant core enhancements: Accelerated interface queries: Added a lightweight view (v_sensor_attribute_values_unique) designed to dramatically speed up device attribute lookups across the platform. Faster device inventories: Converted the Inventory Device Data Provider into a high-performance Stored Procedure to optimize page rendering times. Intelligent date filters: Adjusted the way date-based filters handle reporting. If a specified data timeframe concludes in the future, the system dynamically displays the last available day containing completed data instead of throwing errors or empty fields. Smarter schedule automation: The deployment engine now skips cycle creation for non-recurring schedules whose start times reside in the past, keeping your database clean from legacy schedule clutter. Enforced CVE update windows: Optimization limits have been established to prevent configuration conflicts, enforcing a minimum sync interval of 15 minutes for Tenable CVE synchronization tasks. 🛠️ Platform and UI fixes This release addresses high-priority bug fixes aimed at maximizing stability and cross-dashboard reporting accuracy: Dashboard counting precision: Fixed an issue where vulnerability counts fluctuated when drilling down into specific dashboards. Similar count mismatches between high-level overviews and granular charts have been resolved for deployment failures and OneSite Health checks. Enterprise database scaling: Resolved resource deadlocks and high memory consumption bottlenecks during health rollups on exceptionally massive backend databases. Frictionless access controls: Fixed a defect with permissions management menus that occasionally triggered a 404 message or refused to load. Additionally, fixed a UI bug that caused the approval requests window to spin indefinitely if an admin lacked explicit read permissions on a specific patching strategy. License and setup integrity: Resolved an error that prevented software product licenses from being completely uninstalled via the console UI. We also resolved an edge case where deleting a Business Unit tied to an active deployment wave would block server setup actions. API validation: Corrected response handling logic for the newly introduced INITIALIZING status within the Tenable asset import REST API framework. ⚙️ Upgrade path SaaS / Cloud deployments: No manual action is required for your management plane. Your cloud instance has already been automatically updated to version v10.1.972.17. On-premise deployments: On-Premise server operators can download the latest installer package immediately by logging into the Tenable Downloads Portal. 📖 Customer resources Release version: 10.1.972.17 Release date: May 28, 2026 Changelog: View release notes Documentation: Tenable Patch Management complete documentation hub Have feedback or deployment questions? Reach out to your Tenable representative or start a thread right here in Connect!403Views1like0Comments