Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Tenable

Tenable Vendor Cyber Rating & Cyber Score

tenable.com

Tenable is the exposure management company, exposing and closing the cybersecurity gaps that erode business value, reputation and trust. The company’s AI-powered exposure management platform radically unifies security visibility, insight and action across the attack surface, equipping modern organizations to protect against attacks from IT infrastructure to cloud environments to critical infrastructure and everywhere in between. By protecting enterprises from security exposure, Tenable reduces business risk for more than 44,000 customers around the globe. Learn more at tenable.com.


Tenable A.I CyberSecurity Scoring

Tenable
Company Information
Website:http://www.tenable.com
Employees number:2,355
Number of followers:193,459
NAICS:541514
Industry Type:Computer and Network Security
Homepage:tenable.com
Tenable Risk Score (AI oriented)
Between 600 and 649
logo
TenableComputer and Network Security
Updated:
27/04/2026
645/1000
Poor
Caa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Tenable Global Score (TPRM)
xxxx
logo
TenableComputer and Network Security
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Tenable
TenablePoor
Current Score
645Caa (POOR)
01000
4 incidents
-32.75 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
653Before Incident
MAY 2026
650Before Incident
APRIL 2026
650Before Incident
Vulnerability
27 Apr 2026Tenable
Tenable: Nessus Agent Vulnerability on Windows Enables Arbitrary Code Execution with SYSTEM Privileges

Critical Privilege Escalation Flaw in Tenable’s Nessus Agent for Windows Exposes Systems to Full Takeover

645After Incident
CRITICAL-5
TEN1777263819
Critical Privilege Escalation Flaw in Tenable’s Nessus Agent for Windows Exposes Systems to Full Takeover A newly disclosed vulnerability in Tenable’s Nessus Agent for Windows allows attackers to execute malicious code with SYSTEM-level privileges, the highest access level in Windows, posing a severe risk to enterprise security. The flaw, classified as a symlink (junction) attack, enables threat actors with local access to manipulate the agent’s file operations, leading to arbitrary file deletion and, ultimately, full arbitrary code execution. ### How the Exploit Works The vulnerability exploits a privilege escalation weakness in the Nessus Agent service. By creating a malicious Windows junction a symbolic link that redirects file operations an attacker can trick the agent into deleting critical system files. Once the operating environment is corrupted, the attacker can deploy a malicious payload that executes with SYSTEM privileges, granting unrestricted control over the machine. This includes the ability to install rootkits, disable security tools, and persist across reboots. ### Impact and Risk The flaw affects Nessus Agent installations on Windows, particularly in enterprise environments where the agent is deployed for continuous vulnerability scanning. Since Nessus Agents are often installed on high-value servers and workstations, successful exploitation could lead to catastrophic security breaches, including lateral movement within networks and compromise of sensitive systems. ### Patch and Mitigation Tenable has released Nessus Agent version 11.1.3, which addresses the vulnerability. The company urges all users to upgrade immediately, emphasizing that timely patching is critical to reducing exposure. The fix follows responsible disclosure practices, with Tenable maintaining active collaboration with security researchers to ensure rapid vulnerability resolution. Security teams are advised to prioritize this update, especially in environments where Nessus Agents run on internet-facing or high-value Windows systems.
INCIDENT DETAILS -
TYPE
Privilege Escalation
IMPACT
Systems Affected: Windows systems with Nessus Agent installedOperational Impact: Full arbitrary code execution with SYSTEM privileges, potential lateral movement within networks, compromise of sensitive systems
MARCH 2026
648Before Incident
FEBRUARY 2026
646Before Incident
JANUARY 2026
704Before Incident
DECEMBER 2025
707Before Incident
Vulnerability
23 Dec 2025Tenable
Tenable and LevelBlue: LevelBlue Integrates Unlimited Tenable Vulnerability Scanning Into Its USM Platform

702After Incident
LOW-5
TENLEV1766519861
LevelBlue Expands Tenable Partnership to Offer Unlimited Vulnerability Scanning at No Extra Cost LevelBlue has deepened its collaboration with Tenable, now providing unlimited enterprise-grade vulnerability scanning for all customers using its Unified Security Management (USM) platform—without additional fees. The move aims to address a persistent challenge in vulnerability management: not the lack of scanning, but the ability to act on findings effectively. While unlimited scanning increases visibility, the real shift lies in prioritization, remediation, and operational execution. The USM platform enhances raw scan data with advanced filtering, categorization, and risk-based prioritization, helping teams focus on critical vulnerabilities. Automated executive reporting also tracks risk posture over time, aiding compliance and leadership oversight. For organizations requiring broader coverage—such as attack surface monitoring (ASM), OT, web applications, or dark web exposure—LevelBlue offers a seamless upgrade to its fully managed vulnerability program. Since the scanner is pre-configured, migration involves only a license change, reducing operational friction. Customers retain flexibility: they can keep existing Tenable licenses (via bi-directional integration with Tenable One or Security Center) or consolidate under the embedded USM scanner, simplifying vendor management and potentially lowering costs. Managed delivery options further streamline operations, allowing LevelBlue to handle Tenable instances while maintaining client visibility. The integration also reshapes how MSSPs and partners package vulnerability services. By embedding enterprise-grade scanning at no extra cost, LevelBlue shifts scanning from a premium add-on to a baseline capability. This approach contrasts with competitors who treat vulnerability scanning as an incremental expense, instead positioning it as part of a unified security stack. Beyond scanning, the update emphasizes exposure management—correlating Tenable findings with live detections, contextual prioritization, and end-to-end remediation tracking. The result is a continuous, actionable view of risk, moving beyond static reports to real-time reduction of exposure. For security teams and service providers, the change signals a broader industry trend: reducing tool sprawl while improving outcomes through tighter integration between vulnerability data and security operations.
INCIDENT DETAILS -
TYPE
Vulnerability Management Enhancement
IMPACT
Operational Impact: Improved operational efficiency and risk reduction through integrated vulnerability management and exposure management.
NOVEMBER 2025
709Before Incident
OCTOBER 2025
702Before Incident
Breach
21 Oct 2025Tenable
Salesloft

Salesloft-Drift OAuth Token Breach

639After Incident
CRITICAL-63
DRI1593115102125
The Salesloft-Drift OAuth incident involved attackers stealing OAuth tokens from Salesloft’s development platform, exploiting them to access customer data across integrated applications like Salesforce and Google Workspace. The breach, executed by the threat group UNC6395, leveraged voice phishing (vishing) to trick administrators into authorizing malicious apps, bypassing multi-factor authentication (MFA). Over 700 organizations were impacted as the compromised tokens enabled attackers to exfiltrate sensitive customer information, leading to widespread revocation of Drift integrations. The incident exposed systemic risks in SaaS supply chains, where trusted third-party integrations became attack vectors, enabling potential data theft, cloud credential abuse, outages, or ransomware. Beyond immediate data exposure, the breach triggered forensic investigations, regulatory fines, lawsuits, reputational damage, and operational disruptions, highlighting the cascading risks of N-th degree vendor dependencies in modern cybersecurity ecosystems.
INCIDENT DETAILS -
TYPE
Data BreachCredential TheftSupply Chain Attack
MOTIVATION
Data ExfiltrationCredential HarvestingPotential Financial Gain (e.g., Dark Web Data Sales)
IMPACT
Customer DataCloud Credentials (AWS, Snowflake)Salesforce/Google Workspace DataSalesforceGoogle WorkspaceDrift IntegrationsConnected SaaS PlatformsTemporary Disabling of Drift IntegrationsCredential RevocationsForensic InvestigationsLoss of Trust in SaaS IntegrationsReputational Harm for Salesloft/DriftPotential LawsuitsRegulatory ScrutinyHigh (Stolen Cloud Credentials)PII Exposure via Connected Apps
DATA BREACH
Customer DataCloud Credentials (AWS, Snowflake)PII (via Connected Apps)Sensitivity Of Data: High (Credentials, PII, Business Data)
SEPTEMBER 2025
763Before Incident
Breach
08 Sep 2025Tenable
Tenable

SalesDrift Supply Chain Attack Targeting Salesforce Customer Data via OAuth Token Theft

705After Incident
MEDIUM-58
TEN3532135090825
Tenable, a vulnerability assessment firm, was impacted by the SalesDrift supply chain attack targeting Salesforce customer data. An unauthorized user exploited stolen OAuth authentication tokens linked to the Salesloft Drift third-party application (integrated with Salesforce) to gain access to a portion of Tenable’s Salesforce instance.The compromised data included customer support case details (subject lines, initial descriptions) and business contact information (names, email addresses, phone numbers, and location references). While Tenable confirmed no misuse of the stolen data and stated its products and internal systems remained unaffected, the breach exposed sensitive customer interaction records and corporate contact details.Tenable responded by disabling Salesloft Drift, revoking integrations, rotating credentials, and hardening its Salesforce environment. The incident highlights risks in third-party supply chain vulnerabilities, where attackers leverage trusted vendor access to infiltrate enterprise systems. Though no direct financial or operational harm was reported, the exposure of customer support metadata and business contacts poses reputational and phishing risks.
INCIDENT DETAILS -
TYPE
Supply Chain AttackOAuth Token TheftUnauthorized Access
MOTIVATION
Data ExfiltrationPotential Espionage or Financial Gain (unconfirmed)
IMPACT
Business Contact Information (names, emails, phone numbers, locations)Support Case Subject Lines and Initial DescriptionsSalesforce InstancesSalesloft Drift IntegrationTemporary Disruption of Salesloft Drift IntegrationInvestigation and Remediation EffortsPotential Erosion of Trust Due to Supply Chain VulnerabilityLow (no PII misuse reported)
DATA BREACH
Business Contact InformationSupport Case MetadataSensitivity Of Data: Low to Moderate (No Highly Sensitive PII or Financial Data)NamesBusiness Email AddressesPhone NumbersLocation References
AUGUST 2025
763Before Incident
JULY 2025
763Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Tenable ?
?
What was Tenable's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Tenable's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Tenable's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Tenable's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Tenable's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Tenable's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Tenable's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Tenable's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Tenable's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Tenable's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Tenable's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Tenable's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Tenable ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Tenable's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?