🔥 この記事の詳細
2026-07-22 更新
B
今週中

Tenable Nessus Agentに、リモートで任意のコードが実行され、セキュリティポリシーを回避される可能性がある脆弱性

脆弱性🌐 英語ソース
📅 2026-07-22📰 cert_fr
📌 一言でいうと
Tenable Nessus Agentに、リモートで任意のコードが実行され、セキュリティポリシーを回避される可能性がある脆弱性が発見されました。影響を受けるバージョンは、11.2.xの11.2.1未満、および11.1.4未満のバージョンです。ベンダーから修正パッチが提供されており、速やかな更新が推奨されています。
🔍該当判定
  • 脆弱性診断ツール「Tenable Nessus Agent」を社内で利用している
  • Nessus Agentのバージョンが 11.2.0 以前である
  • Nessus Agentのバージョンが 11.1.3 以前である
上記いずれにも該当しない → 静観でOK
該当時の対応
ベンダーのセキュリティアドバイザリ(tns-2026-18)を確認し、最新バージョン(11.2.1以降、または11.1.4以降)へのアップデートを適用してください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Tenable Nessus Agent 脆弱性対応について

お疲れさまです。Tenable Nessus Agentの脆弱性に関する情報共有です。

■ 概要
Tenable Nessus Agentにおいて、リモートコード実行(RCE)およびセキュリティポリシー回避が可能な脆弱性が報告されました。攻撃者がこの脆弱性を悪用した場合、システム上で任意のコードを実行されるリスクがあります。

■ 影響範囲
- Nessus Agent 11.2.x (11.2.1未満)
- Nessus Agent (11.1.4未満)

■ 対応手順
1. 現在利用しているNessus Agentのバージョンを確認してください。
2. 影響を受けるバージョンである場合、ベンダーが提供する最新の修正パッチを適用してください。

■ 参考情報
- Tenable Security Bulletin tns-2026-18: https://www.tenable.com/security/tns-2026-18

対応優先度: 高
対応期限: 速やかに
Subject: [Security Advisory] Tenable Nessus Agent Vulnerability Remediation

Dear IT/Security Team,

We are sharing information regarding a vulnerability identified in Tenable Nessus Agent.

■ Overview
A vulnerability has been discovered that could allow an attacker to perform remote code execution (RCE) and bypass security policies. This poses a critical risk to the integrity of the systems where the agent is installed.

■ Affected Versions
- Nessus Agent 11.2.x (prior to 11.2.1)
- Nessus Agent (prior to 11.1.4)

■ Remediation Steps
1. Verify the current version of the Nessus Agent deployed in your environment.
2. Update the agent to the latest patched version (11.2.1 or 11.1.4 and above) as per the vendor's guidance.

■ Reference
- Tenable Security Bulletin tns-2026-18: https://www.tenable.com/security/tns-2026-18

Priority: High
Deadline: Immediate