Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
93 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.7) | 0.42% | — | Watchguard Fireware | 30/9/2026 | 6/10/2026 | A NULL pointer dereference vulnerability in the WatchGuard Fireware OS authentication process allows a remote, unauthenticated attacker to crash the management daemon by sending a specially request to the login interface, resulting in a denial of service. | |
| Analizada | Alta (7.1) | 0.21% | — | Watchguard Fireware | 29/9/2026 | 6/10/2026 | A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted… | |
| Analizada | Alta (7.1) | 0.27% | — | Watchguard Fireware | 29/9/2026 | 6/10/2026 | A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted… | |
| Analizada | Alta (8.2) | 0.34% | — | Watchguard Fireware | 29/9/2026 | 6/10/2026 | An integer underflow vulnerability in the WatchGuard Fireware OS IKE daemon (iked) allows a remote attacker who has completed the initial IKEv2 handshake to crash the iked process by sending a specially crafted encrypted IKEv2 message, resulting in a denial of service. | |
| Analizada | Alta (8.2) | 0.36% | — | Watchguard Fireware | 29/9/2026 | 6/10/2026 | An integer underflow vulnerability in the WatchGuard Fireware OS IKEv2 daemon (iked) allows a remote, unauthenticated attacker to crash the process by sending a specially crafted encrypted IKEv2 message negotiated with an AES-GCM cipher suite. | |
| Analizada | Crítica (9.2) | 0.36% | — | Watchguard Fireware | 29/9/2026 | 6/10/2026 | A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox. | |
| Analizada | Alta (8.2) | 0.36% | — | Watchguard Fireware | 29/9/2026 | 6/10/2026 | A NULL pointer dereference vulnerability in Fireware OS's NetFlow packet-processing feature allows a remote, unauthenticated attacker to cause a denial of service by sending a specially crafted IPv6 packet. | |
| Analizada | Media (6) | 0.36% | — | Watchguard Fireware | 29/9/2026 | 6/10/2026 | An improper authorization vulnerability in Fireware OS's Access Portal reverse proxy allows an authenticated, low-privileged Access Portal user to access other web applications they are not authorized for by sending a specially crafted request for a different resource which they are authorized to access. | |
| Analizada | Alta (8.7) | 0.36% | — | Watchguard Fireware | 29/9/2026 | 6/10/2026 | An uncontrolled resource consumption vulnerability in the Fireware OS login process (wgagent) allows a remote, unauthenticated attacker to cause a denial of service by sending a specially crafted request. | |
| En análisis | Alta (7.2) | 0.23% | — | Watchguard FirewareAI | 29/9/2026 | 30/9/2026 | An improper authorization vulnerability in WatchGuard Fireware OS's SAML login process allows a remote, authenticated SAML user with access only to the Access Portal to obtain unauthorized Mobile VPN with SSL access through a specially crafted request. | |
| Aplazada | Alta (8.7) | 0.20% | — | Watchguard FirewareAI | 29/9/2026 | 1/10/2026 | A stack-based buffer overflow vulnerability in WatchGuard Fireware OS's DHCP fingerprinting daemon (fingerd) allows an unauthenticated attacker with adjacent network access to execute arbitrary code or crash the process by sending a specially crafted DHCP packet. | |
| En análisis | Alta (8.6) | 0.34% | — | Watchguard FirewareAI | 29/9/2026 | 1/10/2026 | A stack-based buffer overflow vulnerability in the spamBlocker (spamd) service of WatchGuard Fireware OS allows an authenticated attacker with administrator privileges to crash the service or potentially execute arbitrary code by sending a specially crafted management request. | |
| En análisis | Alta (7.1) | 0.23% | — | Watchguard Fireware OSAI | 29/9/2026 | 30/9/2026 | An uncontrolled resource consumption vulnerability in Fireware OS's diagnostic tasks feature allows a low-privileged, authenticated user to cause a denial of service of the system's diagnostic tools by repeatedly starting and aborting a specially crafted diagnostic task through the web UI. | |
| En análisis | Alta (8.2) | 0.36% | — | Watchguard Fireware OSAI | 29/9/2026 | 30/9/2026 | A path traversal vulnerability in the Fireware OS WebUI management agent allows an authenticated administrator to read or list arbitrary files on the local filesystem by sending a specially crafted management request. | |
| En análisis | Alta (7.5) | 0.32% | — | Watchguard Fireware OSAI | 29/9/2026 | 1/10/2026 | A deserialization of untrusted data vulnerability in WatchGuard Fireware OS's SAML single sign-on session handling (samld) allows an attacker who has already obtained the ability to write files on the appliance to execute arbitrary code in the context of the samld service by causing samld to load a maliciously crafted… | |
| Aplazada | Alta (8.7) | 0.54% | — | Watchguard Fireware OSAI | 28/8/2026 | 3/9/2026 | An integer underflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic. | |
| Aplazada | Alta (8.7) | 0.54% | — | Watchguard Fireware OSAI | 28/8/2026 | 3/9/2026 | A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process iallows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic. | |
| Aplazada | Alta (8.7) | 0.54% | — | Watchguard Fireware OSAI | 28/8/2026 | 3/9/2026 | An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic. | |
| Aplazada | Alta (8.6) | 0.61% | — | Watchguard Fireware OSAI | 28/8/2026 | 3/9/2026 | A buffer overflow vulnerability in the WatchGuard Fireware OS Management Web UI allows an authenticated administrator with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic. | |
| Aplazada | Crítica (9.3) | 0.47% | — | Watchguard Fireware OSAI | 28/8/2026 | 3/9/2026 | A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic. | |
| Aplazada | Alta (8.7) | 0.32% | — | Watchguard Fireware OSAI | 28/8/2026 | 3/9/2026 | An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic. | |
| Aplazada | Alta (8.7) | 0.32% | — | Watchguard Fireware OSAI | 28/8/2026 | 3/9/2026 | A double-free vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic. | |
| Aplazada | Crítica (9.3) | 0.46% | — | Watchguard Fireware OSAI | 28/8/2026 | 3/9/2026 | A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic. | |
| Aplazada | Alta (8.7) | 0.32% | — | Watchguard Fireware OSAI | 28/8/2026 | 3/9/2026 | An integer underflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic. | |
| Aplazada | Crítica (9.3) | 0.47% | — | Watchguard FirewareAI | 28/8/2026 | 3/9/2026 | An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic. |