CVE-2026-19681: Command Injection
An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by uploading a specially crafted file, potentially resulting in arbitrary command execution on the underlying operating system.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Tenable Security Centerto a version that resolves this vulnerability.Fixed in 6.9.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19681?
CVE-2026-19681 has a critical severity rating of 9.9.
How can CVE-2026-19681 be exploited?
CVE-2026-19681 can be exploited by an attacker uploading a specially crafted file that triggers command injection.
What software is affected by CVE-2026-19681?
CVE-2026-19681 affects Microsoft Security Center.
What are the potential consequences of CVE-2026-19681?
Exploitation of CVE-2026-19681 could lead to arbitrary command execution on the underlying operating system.
How do I fix CVE-2026-19681?
To fix CVE-2026-19681, apply the latest security updates provided by Microsoft for Security Center.