Vulnerability Updates for CrowdStrike and Tenable Security Software
Critical Vulnerability Found in CrowdStrike and Tenable Products Requires Immediate Attention
CrowdStrike and Tenable recently released advisories regarding a high-severity vulnerability found in their respective products.
Vulnerability Overview
- The flaw, tracked as CVE-2026-40050, allows an unauthenticated attacker to read arbitrary files from the server file system.
- The vulnerability affects CrowdStrike’s LogScale product and has already been mitigated for LogScale SaaS customers.
- LogScale self-hosted customers have been instructed to update to a patched version immediately to prevent potential exploitation.
According to CrowdStrike, “The issue has been fixed in all supported versions of LogScale.”
Tenable’s Similar Vulnerability
- Tenable also identified a similar vulnerability, tracked as CVE-2026-33694, in their Nessus vulnerability scanner on Windows systems.
- An attacker could exploit this vulnerability via junctions to delete arbitrary files with System privileges, leading to arbitrary code execution with elevated privileges.
- Separate advisories were issued for Nessus and Nessus Agent, highlighting the importance of prompt action to mitigate these risks.
