Plugins Pipeline

At Tenable, we use a multitude of approaches to deliver the best possible coverage to our customers and use a number of factors to prioritize vulnerabilities. Browse upcoming plugins that the Tenable Research team is prioritizing by CVE, detection status or keyword search. Please note that this page does not represent an exhaustive list of plugins that Tenable Research intends to provide coverage for nor for which plugin coverage is provided.

Plugins are categorized into one of the following detection statuses:

  • Development: Tenable Research team is actively working on providing a detection.
  • Testing: The plugin is in the production build & release pipeline.
  • Released: The plugin has been published on the displayed date.
TitleCVEsUpdatedStatus
Security Update for Zoho ManageEngine Endpoint CentralCVE-2026-31822026/7/31testing
oracle_linux ELSA-2026-26168: ELSA-2026-26168: gimp security update (IMPORTANT)CVE-2026-4154, CVE-2026-4150, CVE-2026-4153, CVE-2026-48872026/7/31testing
oracle_linux ELSA-2026-47736: ELSA-2026-47736: fence-agents security update (IMPORTANT)CVE-2026-599392026/7/31testing
oracle_linux ELSA-2026-46990: ELSA-2026-46990: sssd security, bug fix, and enhancement update (IMPORTANT)CVE-2026-14474, CVE-2026-144762026/7/31testing
oracle_linux ELSA-2026-47117: ELSA-2026-47117: libgcrypt security update (MODERATE)CVE-2026-419892026/7/31testing
oracle_linux ELSA-2026-22146: ELSA-2026-22146: PackageKit security update (IMPORTANT)CVE-2026-416512026/7/31testing
oracle_linux ELSA-2026-48703: ELSA-2026-48703: vim security update (IMPORTANT)CVE-2026-57456, CVE-2026-59858, CVE-2026-55693, CVE-2026-574552026/7/31testing
oracle_linux ELSA-2026-45115: ELSA-2026-45115: kernel security update (IMPORTANT)CVE-2026-52993, CVE-2025-40026, CVE-2026-530592026/7/31testing
oracle_linux ELSA-2026-47731: ELSA-2026-47731: gstreamer1-plugins-bad-free security update (IMPORTANT)CVE-2026-59691, CVE-2026-596922026/7/31testing
oracle_linux ELSA-2026-46391: ELSA-2026-46391: grafana security, bug fix, and enhancement update (IMPORTANT)CVE-2026-447402026/7/31testing
oracle_linux ELSA-2026-48021: ELSA-2026-48021: python-pillow security update (IMPORTANT)CVE-2026-59197, CVE-2026-540582026/7/31testing
CLONE - Multiple Vulnerabilities in SAP (July 2026)CVE-2026-58233, CVE-2026-44752, CVE-2026-44745, CVE-2026-44753, CVE-2026-44771, CVE-2026-27690, CVE-2026-44760, CVE-2026-33454, CVE-2026-44767, CVE-2026-40453, CVE-2026-44747, CVE-2026-43512, CVE-2026-44768, CVE-2025-68161, CVE-2026-40860, CVE-2026-43515, CVE-2026-24315, CVE-2026-44770, CVE-2026-44759, CVE-2026-41293, CVE-2026-0487, CVE-2026-44769, CVE-2026-44761, CVE-2026-401282026/7/31development
Security Update for SQLiteCVE-2026-513022026/7/30development
Security Update for Tanium PatchCVE-2026-113912026/7/30development
Multiple Vulnerabilities in Autodesk AutoCAD ProductsCVE-2026-16463, CVE-2026-17550, CVE-2026-164652026/7/30development
[Web App Scanning] vBulletin 5.0.x <= 5.7.5 / 6.x <= 6.2.1 Remote Code ExecutionCVE-2026-615112026/7/30testing
[Web App Scanning] Apache Tomcat Denial of ServiceCVE-2026-662992026/7/30testing
[Web App Scanning] Advanced Responsive Video Embedder Plugin for WordPress 10.8.7 Authentication BypassCVE-2026-180722026/7/30testing
Multiple Vulnerabilities in JetBrains PhpStormCVE-2026-64809, CVE-2026-648082026/7/30development
Security Update for Microsoft 365 Copilot (July 2026)CVE-2026-48561, CVE-2026-586172026/7/30development
Multiple Vulnerabilities in Ricoh PrintersCVE-2026-632262026/7/30development
gitlab CVE-2026-16553: Insufficiently Protected Credentials in GitLab (CVE-2026-16553)CVE-2026-165532026/7/30development
gitlab CVE-2026-6267: Insertion of Sensitive Information Into Sent Data in GitLab (CVE-2026-6267)CVE-2026-62672026/7/30development
gitlab CVE-2026-15975: Allocation of Resources Without Limits or Throttling in GitLab (CVE-2026-15975)CVE-2026-159752026/7/30development
gitlab CVE-2026-14341: Missing Authorization in GitLab (CVE-2026-14341)CVE-2026-143412026/7/30development
gitlab CVE-2026-15831: Generation of Incorrect Security Tokens in GitLab (CVE-2026-15831)CVE-2026-158312026/7/30development
gitlab CVE-2026-15077: Improper Neutralization of Input Used for LLM Prompting in GitLab (CVE-2026-15077)CVE-2026-150772026/7/30development
gitlab CVE-2026-3093: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab (CVE-2026-3093)CVE-2026-30932026/7/30development
gitlab CVE-2026-13113: Time-of-check Time-of-use (TOCTOU) Race Condition in GitLab (CVE-2026-13113)CVE-2026-131132026/7/30development
gitlab CVE-2026-4672: Missing Authorization in GitLab (CVE-2026-4672)CVE-2026-46722026/7/30development
gitlab CVE-2026-12436: Improperly Controlled Modification of Dynamically-Determined Object Attributes in GitLab (CVE-2026-12436)CVE-2026-124362026/7/30development
gitlab CVE-2026-14351: Exposure of Sensitive Information Through Metadata in GitLab (CVE-2026-14351)CVE-2026-143512026/7/30development
gitlab CVE-2026-6336: Incorrect Authorization in GitLab (CVE-2026-6336)CVE-2026-63362026/7/30development
[Web App Scanning] JetBrains TeamCity Remote Code ExecutionCVE-2026-630772026/7/29testing
debian_linux dla-4701: Debian dla-4701 : chromium - security updateCVE-2026-15903, CVE-2026-15905, CVE-2026-16415, CVE-2026-16422, CVE-2026-16419, CVE-2026-16416, CVE-2026-16413, CVE-2026-16418, CVE-2026-15902, CVE-2026-16424, CVE-2026-16417, CVE-2026-16423, CVE-2026-16420, CVE-2026-15899, CVE-2026-15900, CVE-2026-15904, CVE-2026-16421, CVE-2026-16414, CVE-2026-159012026/7/28development
nutanix NXSA-AHV-11.0.1.6: Nutanix AHV: NXSA-AHV-11.0.1.6CVE-2026-37555, CVE-2026-1519, CVE-2026-403562026/7/27development
nutanix NXSA-AHV-11.2: Nutanix AHV: NXSA-AHV-11.2CVE-2025-59375, CVE-2025-61985, CVE-2025-61662, CVE-2026-1519, CVE-2025-61984, CVE-2025-15367, CVE-2025-9086, CVE-2025-9230, CVE-2026-5121, CVE-2025-67873, CVE-2025-68973, CVE-2026-40164, CVE-2026-22801, CVE-2026-1299, CVE-2026-4878, CVE-2025-45582, CVE-2026-35535, CVE-2026-33636, CVE-2025-6176, CVE-2026-35387, CVE-2026-40356, CVE-2026-41035, CVE-2025-66293, CVE-2026-4519, CVE-2026-33412, CVE-2026-35385, CVE-2026-35386, CVE-2026-37555, CVE-2026-4424, CVE-2026-33416, CVE-2026-3497, CVE-2025-40778, CVE-2025-15366, CVE-2026-4111, CVE-2025-10158, CVE-2026-25646, CVE-2026-31431, CVE-2026-0994, CVE-2023-40403, CVE-2026-25749, CVE-2025-13601, CVE-2026-22695, CVE-2025-40780, CVE-2025-12084, CVE-2025-15467, CVE-2025-65018, CVE-2025-11083, CVE-2026-35414, CVE-2025-5987, CVE-2025-64720, CVE-2025-9714, CVE-2026-27135, CVE-2025-68114, CVE-2025-14831, CVE-2026-6100, CVE-2025-14512, CVE-2026-28421, CVE-2026-35388, CVE-2026-28417, CVE-2026-4786, CVE-2025-69419, CVE-2026-39979, CVE-2024-12086, CVE-2025-140872026/7/27development
nutanix NXSA-AHV-10.3.1.12: Nutanix AHV: NXSA-AHV-10.3.1.12CVE-2025-10911, CVE-2026-45186, CVE-2024-4741, CVE-2026-3039, CVE-2026-42944, CVE-2026-42959, CVE-2026-43618, CVE-2026-27459, CVE-2026-45447, CVE-2026-27448, CVE-2024-34459, CVE-2026-29518, CVE-2026-59462026/7/27development
nutanix NXSA-AOS-7.5.1.10: Nutanix AOS: NXSA-AOS-7.5.1.10CVE-2026-42009, CVE-2025-10911, CVE-2026-45186, CVE-2026-3039, CVE-2026-5946, CVE-2026-6893, CVE-2026-42013, CVE-2026-3833, CVE-2026-42015, CVE-2026-42011, CVE-2026-33845, CVE-2026-43964, CVE-2026-42012, CVE-2026-33846, CVE-2026-42010, CVE-2026-35177, CVE-2026-42014, CVE-2026-52602026/7/27development
nutanix NXSA-AOS-7.3.1.14: Nutanix AOS: NXSA-AOS-7.3.1.14CVE-2026-42009, CVE-2025-10911, CVE-2026-45186, CVE-2026-3039, CVE-2026-5946, CVE-2026-6893, CVE-2026-42013, CVE-2026-3833, CVE-2026-42015, CVE-2026-42011, CVE-2026-33845, CVE-2026-43964, CVE-2026-42012, CVE-2026-33846, CVE-2026-42010, CVE-2026-35177, CVE-2026-42014, CVE-2026-52602026/7/27development
Check Point SmartConsole Improper Authentication Vulnerability (CVE-2026-16232)CVE-2026-162322026/7/24development
Security Update for Perl-DBICVE-2026-15043, CVE-2026-153922026/7/23development
Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability (CVE-2026-0770)CVE-2026-07702026/7/22development
AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability (CVE-2024-54085)CVE-2024-540852026/7/22development
D-Link DNR-322L Download of Code Without Integrity Check Vulnerability (CVE-2022-40799)CVE-2022-407992026/7/22development
Qualcomm Multiple Chipsets Memory Corruption Vulnerability (CVE-2026-21385)CVE-2026-213852026/7/22development
Soliton Systems K.K FileZen OS Command Injection Vulnerability (CVE-2026-25108)CVE-2026-251082026/7/22development
Multiple Vulnerabilities in YAML SyckCVE-2026-57077, CVE-2026-57075, CVE-2026-57076, CVE-2026-137132026/7/22development
nginx nginx-CVE-2026-42533.html: Buffer overflow when using map and regexCVE-2026-425332026/7/22development
nginx nginx-CVE-2026-56434.html: Use-after-free when using ngx_http_ssi_moduleCVE-2026-564342026/7/22development