[R1] Stand-alone Security Patch Available for Tenable Security Center Versions 6.6.0, 6.7.2 and 6.8.0: SC202607.1

DataComm Networks Incorporated, a leader in Cybersecurity partner in the Tampa Bay Area and beyond.
  • Home |
  • [R1] Stand-alone Security Patch Available for Tenable Security Center Versions 6.6.0, 6.7.2 and 6.8.0: SC202607.1

This post was originally published on this site.

[R1] Stand-alone Security Patch Available for Tenable Security Center Versions 6.6.0, 6.7.2 and 6.8.0: SC202607.1

Arnie Cabral


Security Center leverages third-party software to help provide underlying functionality. Several of the third-party components (apache, OpenSSL, postgreSQL, PHP, redis) were found to contain vulnerabilities, and updated versions have been made available by the providers. 

Out of caution and in line with best practice, Tenable has opted to upgrade these libraries to address the potential impact of the issues. Security Center Patch SC202607.1 updates the following components:

  • postgresql to version 16.14
  • Apache to version 2.4.67
  • OpenSSL to version 3.5.4
  • PHP to version 8.2.31
  • redis to version 8.2.6 (6.7.x and 6.8.0 only)

Additionally, several vulnerabilities were reported to Tenable and addressed within this patch. Please see the full list of resolved issues below.

Component CVE ID Severity CVSS v3  CVSS v3 Temporal  CVSS v3 Vector
Security Center – SQL Injection CVE-2026-64877 Critical 9.6 9.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N/E:P/RL:U/RC:C
Security Center – Command Injection CVE-2026-64878 Critical 9.0 9.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:ND/RL:ND/RC:C
Security Center – Command Injection CVE-2026-64879 Critical 9.0 9.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:ND/RL:ND/RC:C
Security Center – Blind SQL Injection CVE-2026-64880 High 7.1 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N/E:ND/RL:ND/RC:C
Security Center – Improper File Validation CVE-2026-64881 High 8.8 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:ND/RL:ND/RC:C
Apache HTTP Server CVE-2026-23918 High 8.8 7.9 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Apache HTTP Server CVE-2026-24072 High 8.8 7.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Apache HTTP Server CVE-2026-33523 Medium 6.5 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Apache HTTP Server CVE-2026-33857 Medium 5.3 4.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Apache HTTP Server CVE-2026-34032 Medium 5.3 4.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Apache HTTP Server CVE-2026-34059 High 7.5 6.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
OpenSSL CVE-2025-11187 Medium 6.1 5.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H
OpenSSL CVE-2025-15467 High 8.1 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
OpenSSL CVE-2025-15468 Medium 5.9 4.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
OpenSSL CVE-2025-15469 Medium 5.5 4.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
OpenSSL CVE-2025-66199 Medium 5.9 4.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
OpenSSL CVE-2025-68160 Medium 4.7 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
OpenSSL CVE-2025-69418 Medium 4 3.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
OpenSSL CVE-2025-69419 High 7.4 6.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
OpenSSL CVE-2025-69420 High 7.5 6.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
OpenSSL CVE-2025-69421 High 7.5 6.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
OpenSSL CVE-2026-22795 Medium 5.5 4.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
OpenSSL CVE-2026-22796 Medium 5.3 4.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
PHP CVE-2026-7568 Low 3.3 2.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
PHP CVE-2026-7263 Low 3.3 2.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
PHP CVE-2026-7259 Medium 5.5 4.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
PHP CVE-2026-7262 Medium 5.5 4.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
PHP CVE-2026-7258 Medium 5.5 4.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
PHP CVE-2026-6104 Medium 5.5 4.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
PHP CVE-2026-42371 Medium 5.5 4.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
PHP CVE-2026-6735 Medium 6.1 5.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
PHP CVE-2025-14179 Medium 6.5 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
PHP CVE-2026-7261 Medium 6.5 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
PHP CVE-2026-6722 High 8.1 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
PostgreSQL CVE-2026-2003 Medium 4.3 3.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
PostgreSQL CVE-2026-2004 High 8.8 7.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
PostgreSQL CVE-2026-2005 High 8.8 7.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
PostgreSQL CVE-2026-2006 High 8.8 7.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
PostgreSQL CVE-2026-6472 Medium 5.4 4.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
PostgreSQL CVE-2026-6473 High 8.8 7.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
PostgreSQL CVE-2026-6474 Medium 4.3 3.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
PostgreSQL CVE-2026-6475 High 8.8 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
PostgreSQL CVE-2026-6477 High 8.8 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
PostgreSQL CVE-2026-6478 Medium 6.5 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
PostgreSQL CVE-2026-6479 High 7.5 6.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
PostgreSQL CVE-2026-6637 High 8.8 7.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
PostgreSQL CVE-2026-6638 Low 3.7 3.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
Redis CVE-2026-23479 High 8.8 7.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Redis CVE-2026-25243 High 8.8 7.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Redis CVE-2026-23631 High 8.1 6.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Redis CVE-2026-25588 High 8.8 7.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Redis CVE-2026-25589 High 8.8 7.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Latest posts

Technology Trends
Travis Norris

Update Fatigue: How the relentless pace of software updates is breaking user trust — and what organizations can do about it

Somewhere between the fourteenth update notification of the week and the third forced restart during a critical deadline, something breaks. Not the software — the user. They click “Remind me later.” Then again. And again. Eventually, they stop updating altogether.

This is update fatigue — and it’s quietly becoming one of the most significant and underappreciated vulnerabilities in organizational cybersecurity today.

Read More ⇾
Kofi's Korner - Insights from DataComm's Technical Solutions Team
Kofi's Korner
Kofi Kankam

Kofi’s Korner April 2026

Rising technology costs, evolving cyber threats, and increasingly complex IT environments are forcing organizations to rethink how they plan, protect, and scale their infrastructure. In this edition of Kofi’s Korner, we explore what’s driving today’s unpredictable pricing landscape, how a layered security approach strengthens resilience, and why solutions like SecurShield IDS/IPS are critical in a firewall-first world. Discover practical insights and strategies to help your organization stay secure, compliant, and ahead of what’s next.

Read More ⇾

SecurNOC

Monitor your network devices and view their configuration changes.

SecurPortal

A live look at your events, security event charts and tickets.

Ticketing Portal

Login here to easily add and managed trouble tickets.

Remote Support

Let DataComm remotely access your computer to render aid.