Security tools need patching too: Tenable Nessus 10.12.5 fixes nine flaws, and Fortra’s BoKS privileged-access manager has critical fixes
EditorialBy TrustList Editorial
Tenable fixed nine flaws in Nessus 10.12.4 and earlier on 1 October 2026, the worst rated 9.1, in 10.12.5. Fortra fixed six flaws, three critical, in its BoKS privileged-access manager (8.1.0.30, 9.0.0.7, 10.1.1.0). No exploitation reported.
- Cybersecurity
- Vulnerability Management
- Patch Management
- Identity Management Software
About Security tools need patching too: Tenable Nessus 10.12.5 fixes nine flaws, and Fortra’s BoKS privileged-access manager has critical fixes
Security tools need patching too: Tenable Nessus 10.12.5 fixes nine flaws, and Fortra’s BoKS privileged-access manager has critical fixes
2 October 2026 — Two widely used security products received fixes this week. Both run with high privileges by design, which makes their own flaws more serious than the same bug in an ordinary application. Our separate item covers a critical flaw in WatchGuard Endpoint Security published the same day.
Not yet independently verified. The Nessus details come from Tenable’s own advisory. Fortra’s advisory refused our reader, so the BoKS versions and counts come from Italy’s and Spain’s national CERTs. No exploitation has been reported for either. We will update this when it can be confirmed, and remove this note.
Tenable Nessus 10.12.5
Tenable's advisory TNS-2026-26, of 1 October 2026, covers nine vulnerabilities in Nessus 10.12.4 and earlier, fixed in 10.12.5. The two most serious:
- CVE-2026-103947 (critical, CVSS 9.1): Nessus "did not sufficiently verify the integrity of certain downloaded content before using it, which could allow an authenticated, privileged attacker to compromise the system."
- CVE-2026-103946 (high, CVSS 8.3): an SQL injection that "could allow an authenticated user to read or modify data stored by Nessus".
A vulnerability scanner holds credentials for the systems it scans and a map of their weaknesses, so a compromised scanner is a gift to an attacker.
Fortra BoKS (Core Privileged Access Manager)
According to CSIRT Italia and INCIBE-CERT, Fortra has fixed six vulnerabilities, three critical and three high, in BoKS, now sold as Fortra Core Privileged Access Manager, which controls administrator access to Unix and Linux servers. The flaws allow remote code execution, denial of service, privilege escalation and information disclosure. They are fixed in 8.1.0.30, 9.0.0.7 and 10.1.1.0, under Fortra advisories fi-2026-012 to fi-2026-019.
What to do
- Update Nessus scanners and agents to 10.12.5, including scanners managed through Tenable's other products.
- Update BoKS to the fixed release of your line, and read Fortra's advisories through your support portal.
- Limit who can sign in to security tools, since several of these flaws need an authenticated user, and review their accounts.
- Treat security tooling as tier-zero infrastructure in patch schedules: it should be among the first systems updated, not the last.
Sources
Categories & features
- Cybersecurity
- Vulnerability Management
- Patch Management
- Identity Management Software
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More CybersecurityThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.