Endpoint Security

Vulnerabilities Patched in CrowdStrike, Tenable Products

CrowdStrike has fixed a critical LogScale vulnerability, while Tenable addressed a high-severity Nessus flaw.

Security product

CrowdStrike and Tenable informed customers this week about potentially serious vulnerabilities found and patched in their products.

CrowdStrike published an advisory for CVE-2026-40050, a critical unauthenticated path traversal vulnerability affecting its LogScale product. The flaw can allow a remote attacker to read arbitrary files from the server filesystem.

The cybersecurity giant pointed out that Next-Gen SIEM customers are not affected and the vulnerability has been mitigated for LogScale SaaS customers.

LogScale Self-hosted customers have been advised to update to a patched version.

CrowdStrike said the vulnerability was discovered internally and there is no evidence of exploitation in the wild based on a review of log data.

Tenable published two new advisories on Thursday. They describe the same high-severity vulnerability found in the company’s Nessus vulnerability scanner, specifically on Windows.

Advertisement. Scroll to continue reading.

The vulnerability is tracked as CVE-2026-33694 and an attacker could exploit it via junctions to delete arbitrary files with System privileges. Exploitation could also lead to arbitrary code execution with elevated privileges.

Tenable published separate advisories for Nessus and Nessus Agent. 

Related: Claude’s New AI Vulnerability Scanner Sends Cybersecurity Shares Plunging

Related: CISA: Hackers Exploiting Vulnerability in Product of Taiwan Security Firm TeamT5

Related: Trend Micro Patches Critical Apex One Vulnerabilities

Related Content

Vulnerabilities

The critical-severity OS command injection vulnerability allows attackers to execute arbitrary code with root privileges.

Vulnerabilities

The browser refresh resolved critical and high-severity security defects, including a dozen use-after-free bugs.

Government

The new BOD 26-04 requires agencies to review and update vulnerability management policies with a focus on KEV catalog entries.

Vulnerabilities

Disclosed in March, the security defect enables unauthenticated attackers to write files to arbitrary locations on the system.

Vulnerabilities

The security defects could allow attackers to create or modify arbitrary files and access and modify protected resources.

Vulnerabilities

The company warned about zero-day attacks exploiting the Exchange Server vulnerability CVE-2026-42897 on May 14. 

ICS/OT

Claroty researchers have analyzed the security of Vertiv UPS network cards and the Trane Tracer SC+ HVAC controller.

Vulnerabilities

Exploiting a race condition in Microsoft Defender, the exploit leads to local privilege escalation to SYSTEM.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version