Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
567 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.7) | 0.20% | — | Paloaltonetworks Prisma Access Agent | 9/7/2026 | 16/7/2026 | An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. The Prisma Access Agent on Windows, macOS, Linux, Android and ChromeOS are not affected. | |
| En análisis | Baja (1.1) | 0.14% | — | Paloaltonetworks Cortex XDR Broker VM | 9/7/2026 | 16/7/2026 | A privilege escalation vulnerability in Palo Alto Networks Cortex® XDR Broker VM enables a locally authenticated user to perform actions as the root user. | |
| Analizada | Baja (2) | 0.17% | — | Paloaltonetworks Prisma Browser | 9/7/2026 | 14/7/2026 | A local privilege escalation vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated administrator with access to the macOS local filesystem to perform actions on the device with root privileges. This issue only affects Prisma® Browser on macOS. | |
| Modificada | Media (6.6) | 0.62% | — | Paloaltonetworks Cloud NgfwPaloaltonetworks Pan-os | 9/7/2026 | 11/8/2026 | Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic to or through a dataplane interface. Repeated attempts to trigger this condition result in… | |
| Modificada | Media (6) | 1.7% | — | Paloaltonetworks Pan-os | 9/7/2026 | 11/8/2026 | A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authenticated administrator to execute arbitrary OS commands as root. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators. This… | |
| Modificada | Media (4.7) | 0.43% | — | Paloaltonetworks Pan-os | 9/7/2026 | 11/8/2026 | A server-side request forgery (SSRF) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator with network access to the management web interface to make unauthorized requests from the firewall to internal services. The security risk posed by this issue is minimized when the… | |
| Modificada | Media (4.7) | 0.46% | — | Paloaltonetworks Pan-os | 9/7/2026 | 11/8/2026 | An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corruption of internal LSVPN satellite data. Panorama, Cloud NGFW,… | |
| Modificada | Media (4.5) | 0.38% | — | Paloaltonetworks Pan-os | 9/7/2026 | 11/8/2026 | An authentication bypass vulnerability in Large Scale VPN ( LSVPN) functionality of Palo Alto Networks PAN-OS software allows an attacker with network access to bypass security restrictions and establish an unauthorized site-to-site VPN connection. Panorama, Cloud NGFW, and Prisma® Access are not impacted by this… | |
| Modificada | Baja (2.7) | 0.29% | — | Paloaltonetworks Pan-os | 9/7/2026 | 11/8/2026 | A file deletion vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web interface to delete files from a temporary directory. The security risk posed by this issue is minimized by restricting access to the management web interface to only… | |
| Modificada | Baja (2.1) | 0.28% | — | Paloaltonetworks Pan-os | 9/7/2026 | 11/8/2026 | An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web interface to obtain web session tokens. This requires a legitimate user to first click on a malicious link provided by the attacker. The security risk posed by… | |
| Modificada | Baja (1.7) | 0.34% | — | Paloaltonetworks Pan-os | 9/7/2026 | 11/8/2026 | An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to bypass firewall security policy enforcement, allowing network traffic that should be blocked to reach protected services. Cloud NGFW and Panorama are not impacted by this vulnerability. | |
| Modificada | Baja (1.3) | 0.75% | — | Paloaltonetworks Pan-os | 9/7/2026 | 11/8/2026 | Multiple cross site scripting vulnerabilities in the User-ID™ Authentication Portal (aka Captive Portal) service, GlobalProtect™ gateway/portal features and Clientless VPN of Palo Alto Networks PAN-OS® software enables a malicious unauthenticated user to store or execute malicious JavaScript payload. The security risk… | |
| Modificada | Alta (7.2) | 0.83% | — | Paloaltonetworks Pan-os | 8/7/2026 | 11/8/2026 | Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic. The… | |
| Analizada | Alta (8.7) | 0.63% | — | Paloaltonetworks Idira Privileged Access Manager Vault | 12/6/2026 | 7/7/2026 | Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, processing unexpected input could potentially lead to an unexpected service termination, resulting in a localized… | |
| Modificada | Alta (7.5) | 0.17% | — | Paloaltonetworks Idira Privilege Cloud Connector | 12/6/2026 | 23/6/2026 | Idira Vendor PAM - Self-Hosted Connector versions prior 1.1.100504 under specific conditions and configuration scenarios, TLS certificate validation may not be fully enforced. CyberArk Security Bulletin: CA26-17 | |
| Analizada | Alta (8.5) | 0.17% | — | Paloaltonetworks Idira Endpoint Privilege Manager | 11/6/2026 | 22/6/2026 | Idira Endpoint Privilege Manager Linux Agent versions prior to 26.5 allow a local attacker to potentially compromise the agent daemon initialization. CyberArk Security Bulletin: CA26-19 | |
| Analizada | Alta (8.4) | 0.21% | — | Paloaltonetworks Idira Identity Browser Extension | 11/6/2026 | 22/6/2026 | Idira Identity Browser Extension (Chrome, Firefox, and Edge builds) versions prior to 26.8.1 exhibit an origin validation flaw within its internal web-page verification routines. If an authenticated user navigates to a specially crafted webpage, this interaction could potentially allow a remote attacker to trigger… | |
| Analizada | Alta (8.7) | 0.81% | — | Paloaltonetworks Idira Privileged Session Manager FOR SSH | 11/6/2026 | 23/6/2026 | Due to incomplete input validation in Idira Privileged Session Manager for SSH (PSMP) versions prior to 15.0.2, 14.6.3, 14.2.5, and 14.0.6, an authenticated, low-privileged user could potentially execute arbitrary commands on the PSMP host. CyberArk Security Bulletins: CA26-17 and CA26-18 | |
| Analizada | Alta (8.7) | 0.72% | — | Paloaltonetworks Idira Privileged Session Manager | 11/6/2026 | 23/6/2026 | Incomplete input validation and improperly configured folder permissions within Idira Privileged Session Manager (PSM) versions prior to 15.0.3, 14.6.3, 14.2.5, and 14.0.5, an authenticated, low-privileged user could potentially execute arbitrary code. CyberArk Security Bulletin: CA26-17 and CA26-18 | |
| Analizada | Alta (8.5) | 0.17% | — | Paloaltonetworks Idira Endpoint Privilege Manager | 11/6/2026 | 22/6/2026 | Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local attacker could potentially bypass built-in security controls or cryptographic validations. Under specific circumstances, this could allow the attacker to circumvent agent… | |
| Analizada | Alta (8.4) | 0.51% | — | Paloaltonetworks Idira Secrets ManagerPaloaltonetworks Idira Secrets Manager Credential Providers | 11/6/2026 | 22/6/2026 | Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endpoints. A remote, authenticated attacker possessing standard node-level credentials could leverage these endpoints to potentially retrieve unauthorized secrets or cause a denial of service (DoS).… | |
| Analizada | Crítica (9.1) | 0.73% | — | Paloaltonetworks Idira Secrets Manager Edge | 11/6/2026 | 22/6/2026 | Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication components. A remote, unauthenticated attacker could exploit this by submitting a specially crafted request. Under specific circumstances, this could allow the attacker to manipulate internal… | |
| Analizada | Alta (8.9) | 0.17% | — | Paloaltonetworks Idira Endpoint Privilege Manager | 11/6/2026 | 22/6/2026 | Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileged agent components. A local, low-privileged attacker could exploit this by manipulating an internal communication mechanism or file operation. Under specific circumstances, this could potentially allow… | |
| En análisis | Alta (8.1) | 0.29% | — | Paloaltonetworks Cortex Xsiam Commvaultsecurityiq MarketplacePaloaltonetworks Cortex Xsoar Commvaultsecurityiq Marketplace | 10/6/2026 | 23/7/2026 | An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resources. | |
| Modificada | Media (6.1) | 1.3% | 💥 PoC | Paloaltonetworks Pan-os | 10/6/2026 | 23/7/2026 | A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI or Web UI. The security risk posed by this issue is… |