Tenable adds code security to its exposure platform
Mon, 20th Jul 2026 (Yesterday)
Tenable has expanded its Tenable One Exposure Management Platform to include application security risk data, bringing static code vulnerability information into its broader exposure management system.
The update is designed to link software flaws with the wider technology environments they affect, including runtime systems, cloud workloads, identities and attack paths.
The expanded platform combines application security findings with exposure data collected across other parts of an organisation's attack surface. This includes telemetry from Tenable's own tools and information from third-party security products covering endpoint protection, cloud security, vulnerability management and operational technology security.
It also draws on business context from systems such as configuration management databases. The aim is to help security teams identify which code vulnerabilities have the greatest real-world impact, rather than treating all software flaws in isolation.
Code context
The change reflects a broader problem for security teams as software development accelerates and the volume of code under review grows. Organisations often use separate tools for software security testing and infrastructure security, creating gaps when teams try to determine whether a coding flaw presents a practical threat to operations.
Tenable said those gaps are becoming more acute as generative AI tools help developers produce software more quickly. Citing research from the Cloud Security Alliance, the company said AI-assisted development can increase code delivery speed by three to four times while potentially introducing flaws at a much higher rate.
By integrating static code vulnerability data, the platform is intended to provide what Tenable describes as code-to-runtime visibility. In practice, this means security teams can trace a software weakness from the codebase into the systems and assets where it is deployed, then compare that weakness with other known exposures across the business.
Tenable One ingests, analyses and normalises data from application development and security sources, including AI application security tools such as Claude Security. It then correlates that information with broader exposure data so software weaknesses can be prioritised alongside other forms of cyber risk.
Broader market
The expansion comes as cyber security vendors try to give customers more unified views of risk rather than separate dashboards for infrastructure, cloud and software development. For large organisations, one of the main operational challenges is not simply finding vulnerabilities but deciding which ones require immediate action.
The updated platform is intended to shift customers from reactive application scanning to more proactive prioritisation. Instead of reviewing code issues as a stand-alone stream of alerts, security teams can assess them in relation to the systems, users and business processes connected to those weaknesses.
Application security data integrations are now available to all Tenable One customers. Tenable serves more than 40,000 customers globally, according to the company.
Eric Doerr, Chief Product Officer at Tenable, outlined the company's view on the need for added context in software security workflows.
"By bringing application security data into Tenable One, we're giving customers the context they've been missing. Security teams don't need to wade through a sea of vulnerabilities. With Tenable One, they can see exactly where they are exposed the moment an exposure is created, whether an agentic AI security tool discovers a new zero-day in an open-source library or human error introduces risk. For the first time, security teams can see code flaws and prioritise remediation alongside all other forms of risk for more effective risk reduction," Doerr said.