Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
9523 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.4) | 0.18% | — | IBM Cloud PAK FOR Business AutomationAI | 14/9/2026 | 16/9/2026 | IBM Cloud Pak for Business Automation could allow a remote attacker to bypass authorization and invoke restricted endpoints due to improper validation of HTTP headers. | |
| Pendiente de análisis | Alta (7.1) | 0.29% | — | IBM Business Automation WorkflowAI | 14/9/2026 | 16/9/2026 | IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | |
| Pendiente de análisis | Media (5.4) | 0.23% | — | IBM Cognos AnalyticsAI | 14/9/2026 | 16/9/2026 | IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 allows a non-privileged user to edit their given name and surname to include malicious JavaScript code. When an administrator later accesses the user account management panel and views that user's permissions, the malicious JavaScript code… | |
| Pendiente de análisis | Media (5.4) | 0.31% | — | IBM Sterling Secure ProxyAI | 14/9/2026 | 16/9/2026 | IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2 could allow a remote authenticated attacker to perform UI spoofing and phishing attacks due to improper neutralization of user-supplied HTML markup. | |
| Pendiente de análisis | Media (4.3) | 0.36% | — | IBM Sterling Secure ProxyAI | 14/9/2026 | 16/9/2026 | IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2 could allow a remote authenticated attacker to view administrative user interface components due to client-side authorization bypass. | |
| Pendiente de análisis | Alta (7.5) | 0.40% | — | IBM Sterling File GatewayAI | 14/9/2026 | 16/9/2026 | IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6_1, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 could allow a remote attacker to obtain sensitive information due to improper access control. | |
| Pendiente de análisis | Media (5.2) | 0.12% | — | IBM IAI | 14/9/2026 | 16/9/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An authenticated attacker could leverage this to terminate their own process. | |
| Pendiente de análisis | Media (5.4) | 0.30% | — | IBM Sterling B2B IntegratorAIIBM Sterling File GatewayAI | 14/9/2026 | 16/9/2026 | IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6_2, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6_2, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 Standard Edition could allow a remote authenticated attacker to bypass security restrictions due to improper authentication. | |
| Pendiente de análisis | Baja (3.3) | 0.12% | — | IBM IAI | 14/9/2026 | 16/9/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An authenticated attacker could leverage this to terminate their own process. | |
| Pendiente de análisis | Media (6) | 0.13% | — | IBM IAI | 14/9/2026 | 16/9/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain ownership of arbitrary file system objects due to a time-of-check to time-of-use (TOCTOU) race condition. | |
| Pendiente de análisis | Media (6.3) | 0.50% | — | IBM I Access FamilyAI | 14/9/2026 | 17/9/2026 | IBM i Access Family 1.1.2.0 through 1.1.9.15 could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a session file. | |
| Pendiente de análisis | Media (6.3) | 0.27% | — | IBM I Access FamilyAIIBM I Access Client SolutionsAI | 14/9/2026 | 17/9/2026 | IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a malicious emulator macro RunProgram action. | |
| Pendiente de análisis | Media (6.3) | 0.27% | — | IBM I Access FamilyAIIBM I Access Client SolutionsAI | 14/9/2026 | 17/9/2026 | IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a STRPCCMD CL command. | |
| Pendiente de análisis | Alta (8.8) | 0.65% | — | IBM MQAI | 14/9/2026 | 16/9/2026 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote authenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted… | |
| Pendiente de análisis | Alta (7.1) | 0.39% | — | IBM MQAI | 14/9/2026 | 16/9/2026 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit… | |
| Pendiente de análisis | Media (4.7) | 0.28% | — | IBM Verify Identity AccessAI | 14/9/2026 | 16/9/2026 | IBM Verify Identity Access could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear… | |
| Pendiente de análisis | Media (6.1) | 0.24% | — | IBM Verify Identity AccessAIIBM Security Verify AccessAIIBM Verify Identity Access ContainerAIIBM Security Verify Access ContainerAI | 14/9/2026 | 16/9/2026 | IBM Verify Identity Access 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access 10.0.0 through 10.0.9.2 Interim Fix 001 and IBM Verify Identity Access Container 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access Container 10.0.0 through 10.0.9.2 Interim Fix 001. | |
| Pendiente de análisis | Alta (7.1) | 0.25% | — | IBM MQAIIBM Managed File TransferAI | 14/9/2026 | 16/9/2026 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 Managed File Transfer could allow an authenticated attacker to read arbitrary files or perform server-side request forgery… | |
| Pendiente de análisis | Alta (7.5) | 0.43% | — | IBM Verify Identity AccessAI | 14/9/2026 | 16/9/2026 | IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources. | |
| Pendiente de análisis | Alta (7.1) | 0.28% | — | IBM Business Automation WorkflowAI | 14/9/2026 | 16/9/2026 | IBM Business Automation Workflow containers and traditional may use programming model artifacts that are vulnerable to XML Entity Injection attacks by default. | |
| Pendiente de análisis | Media (6.5) | 0.22% | — | IBM LangflowAI | 14/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.5 is vulnerable to server-side request forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |
| Pendiente de análisis | Media (5.4) | 0.18% | — | IBM Langflow OSSAI | 14/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |
| Pendiente de análisis | Media (6.5) | 0.22% | — | IBM Langflow OSSAI | 14/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.10.2 is vulnerable to server-side request forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |
| Pendiente de análisis | Media (4.2) | 0.15% | — | IBM LangflowAIIBM Langflow OSSAI | 14/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context due to improper cache key isolation in the MCP Tools component. | |
| Pendiente de análisis | Media (4.3) | 0.14% | — | IBM IAI | 14/9/2026 | 16/9/2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to improper validation of the WebSocket origin. |