Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3302▲ 384 respecto a la semana anterior
Críticas / altas1464▲ 142 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)591▲ 117 respecto a la semana anterior
123 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.4) | 0.32% | — | ZammadAI | 30/9/2026 | 30/9/2026 | All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root. | |
| Aplazada | Crítica (9.4) | 0.71% | — | ZammadAI | 30/9/2026 | 30/9/2026 | Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions. | |
| Aplazada | Alta (7.1) | 0.12% | — | ZammadAI | 25/9/2026 | 29/9/2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when Zammad checks the digital signature on an incoming S/MIME-signed email, it does not verify that the signing certificate is genuinely trusted, it only checks whether a certificate with a matching name is already stored in the… | |
| Aplazada | Alta (7.1) | 0.29% | — | ZammadAI | 25/9/2026 | 28/9/2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, zammad's External Data Source feature, used to look up records from an external system, did not properly verify whether a user was allowed to see a specific ticket, user, group, or organization before including its details in a request… | |
| Aplazada | Media (6.3) | 0.15% | — | ZammadAI | 25/9/2026 | 29/9/2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a user with Knowledge Base editing rights for a category can embed a video widget in a published answer with a specially crafted value. When the answer is rendered, that value is inserted into the page's HTML without being escaped for… | |
| Aplazada | Media (6.9) | 0.32% | — | ZammadAI | 25/9/2026 | 28/9/2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the two-factor login step let an attacker try unlimited password guesses for any account without triggering Zammad's normal lockout or rate limiting. The response also revealed whether a guess was correct, even before two-factor… | |
| Aplazada | Media (5.3) | 0.26% | — | ZammadAI | 25/9/2026 | 29/9/2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, any authenticated user can call the REST endpoint for getting a tag list and receive the tag names for the given ticket, regardless of whether they have access to that ticket. Tags are an internal categorization feature and may contain… | |
| Aplazada | Crítica (9.1) | 0.36% | — | ZammadAI | 25/9/2026 | 28/9/2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when the "Automatic account link on initial logon" setting is enabled, Zammad binds an incoming third-party (SSO) identity to an existing local account by matching the email address the identity provider reports, without verifying that… | |
| Aplazada | Media (5.3) | 0.24% | — | ZammadAI | 25/9/2026 | 29/9/2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, unsanitized option labels are rendered in the configuration dialogs of AI Agents within Zammad's admin UI. When rendering the list of selected options, the option label is output as raw HTML without escaping. An attacker who can… | |
| Aplazada | Media (5.1) | 0.31% | — | ZammadAI | 25/9/2026 | 28/9/2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when a Microsoft Graph request fails, Zammad logs the error including the authentication token used to access the mailbox. The system attempts to hide this token in the log, but the masking is incomplete: for the token format Microsoft… | |
| Aplazada | Media (6.9) | 0.17% | — | ZammadAI | 25/9/2026 | 29/9/2026 | Zammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, an authenticated administrator can obtain stored integration credentials in cleartext through the integration administration API. Certain responses do not consistently mask sensitive fields, so configured secrets can be returned in… | |
| Aplazada | Media (5.3) | 0.28% | — | ZammadAI | 25/9/2026 | 28/9/2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, zammad's HTML sanitizer, which blocks remote images in ticket articles and email views, can be bypassed using a shortened URL format that omits the double slash after the scheme (for example a shortened HTTP URL instead of a shortened… | |
| Aplazada | Media (5.1) | 0.32% | — | ZammadAI | 25/9/2026 | 29/9/2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when creating or updating an email signature, Zammad processes inline images referenced in the signature body. If a signature body contains an HTML img tag pointing to any existing attachment, the system copies that attachment into a… | |
| Aplazada | Baja (2.3) | 0.29% | — | ZammadAI | 25/9/2026 | 28/9/2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, an authenticated user with agent permissions can supply an arbitrary AI analytics run identifier to the ticket summarize endpoint and receive the AI provider error message stored for that run, even if the run belongs to a ticket the… | |
| Aplazada | Media (5.3) | 0.48% | — | ZammadAI | 25/9/2026 | 29/9/2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, attacker-controlled HTML in inbound emails or tickets could bypass the image URL sanitizer using path traversal sequences. When an authenticated agent views the content, the browser resolves the URL to a protected API endpoint and… | |
| Aplazada | Media (5.3) | 0.21% | — | ZammadAI | 25/9/2026 | 28/9/2026 | Zammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, under certain conditions, Zammad's verification of inbound PGP-signed email can mark a message as carrying a valid ("Good") PGP signature from a registered sender key, even though the displayed message content is not actually… | |
| Aplazada | Alta (8.6) | 0.28% | — | ZammadAI | 25/9/2026 | 28/9/2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a security filter that protects Zammad's AI Agent configuration can be bypassed by entering specially crafted text into one of an AI Agent's fields. An administrator with permission to create or edit AI Agents could exploit this to run… | |
| Aplazada | Baja (2.3) | 0.20% | — | ZammadAI | 25/9/2026 | 28/9/2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the legacy destroy_form action on AttachmentsController deletes UploadCache Store records based solely on a user-supplied form_id without verifying that the requesting user owns those records. An authenticated attacker who learns… | |
| Aplazada | Alta (8.8) | 0.36% | — | ZammadAI | 25/9/2026 | 28/9/2026 | Zammad is a web based open source helpdesk/customer support system. In 7.0.2 and 7.1.0, zammad's session management for websocket and long-polling connections is susceptible to a path traversal attack. Session identifiers supplied by the client are insufficiently validated before being used to construct internal file… | |
| Aplazada | Media (5.3) | 0.42% | — | ZammadAI | 25/9/2026 | 28/9/2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2 and 7.1.0, zammad's HTML sanitizer (HtmlSanitizer::Strict) blocks external URLs in to prevent remote content loading, but the srcset attribute, also allowlisted for , is not subject to the same check. This oversight allows an attacker… | |
| Aplazada | Media (5.3) | 0.40% | — | ZammadAI | 25/9/2026 | 29/9/2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, during federated authentication (OAuth/OIDC/SAML), a profile image URL from the external identity provider is fetched without verifying the target address. An actor who controls their profile at a connected provider may cause the… | |
| Aplazada | Alta (8.7) | 0.27% | — | ZammadAI | 25/9/2026 | 28/9/2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2 and 7.1.0, this issue concerns a lack of discursive validation within the authorization cascade. It has been determined that the system-level enforcement of access restrictions during the initialization of new identity objects exhibits… | |
| Aplazada | Media (5.3) | 0.20% | — | ZammadAI | 25/9/2026 | 28/9/2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, vulnerability in Zammad's HTML sanitization allows injection of specific HTML elements into ticket bodies. When another user views the crafted ticket, the injected element can trigger a logout request, terminating the viewer's session.… | |
| Aplazada | Alta (8.4) | 0.24% | — | ZammadAI | 25/9/2026 | 28/9/2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, a low-privilege authenticated user may inject arbitrary HTML markup, including JavaScript event handlers, into a ticket title via the standard ticket creation workflow. The title is persisted without sanitization. This issue is fixed… | |
| Aplazada | Baja (2.1) | 0.35% | — | ZammadAI | 25/9/2026 | 29/9/2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, an authorization bypass vulnerability was found that allows an authenticated agent to read knowledge base answer content they should not be able to access. The vulnerable GraphQL mutation is meant to transform a knowledge base answer… |