Tenable has expanded its Tenable One Exposure Management Platform to unify application security risk with the rest of an organisation’s exposure data, closing a blind spot created by generative AI accelerating how fast vulnerable code reaches production.
Tenable® Holdings, Inc. (NASDAQ: TENB) said the expansion integrates static code vulnerability data into Tenable One, delivering complete code-to-runtime visibility across the entire attack surface. Security teams have long struggled with vulnerable code reaching production faster than it can be reviewed, a problem the company said is exacerbated by generative AI, which empowers developers to ship code three to four times faster while potentially introducing flaws at ten times the rate, according to an April 2026 Cloud Security Alliance study.
From reactive scanning to proactive prioritisation
Application security teams and developers typically rely on siloed tools that lack the contextual infrastructure intelligence to determine whether a code vulnerability poses a real-world threat to the business, Tenable said, creating an exploitable blind spot. Tenable One now ingests, analyses and normalises data from application development and security sources, including AI application security tools such as Claude Security, and connects it with telemetry from endpoint protection, cloud security, vulnerability management and operational technology security tools, alongside business context from configuration management databases.
With the expansion, Tenable One shifts organisations from reactive application scanning to proactive risk prioritisation, connecting code risks to the runtime systems, cloud workloads, identities and attack paths they put at risk.
“Bringing application security data into Tenable One, we’re giving our customers the context they’ve been missing. Security teams don’t need to wade through a sea of vulnerabilities. With Tenable One, security teams know exactly where they are exposed the moment an exposure is created — whether an agentic AI security tool discovers a new zero-day in an open-source library or a human error introduces risk,” said Eric Doerr, Chief Product Officer, Tenable.
Application security data integrations are now available for all Tenable One customers.

