Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
567 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.9) | 0.17% | — | Paloaltonetworks Chronosphere Collector | 13/5/2026 | 13/7/2026 | An information disclosure vulnerability in the Chronosphere Chronocollector enables an unauthenticated attacker with network access to the collector service to retrieve sensitive information. | |
| Analizada | Baja (1.1) | 0.10% | — | Paloaltonetworks Broker VM | 13/5/2026 | 13/7/2026 | A vulnerability in Palo Alto Networks Broker VM allows an authenticated administrator to inject arbitrary content into certain Broker VM fields. | |
| Analizada | Alta (7.3) | 0.16% | — | Paloaltonetworks Prisma Browser | 13/5/2026 | 13/7/2026 | A code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its AppleScript interface allowing a locally authenticated non-admin user to leverage this exposed Apple Event handler to send unauthorized commands to the browser. | |
| Analizada | Media (5.8) | 0.11% | — | Paloaltonetworks Prisma Browser | 13/5/2026 | 14/7/2026 | A race condition vulnerability in Palo Alto Networks Prisma® Browser enables a locally authenticated non-admin user to bypass certain access and data control policies. | |
| Analizada | Alta (7.2) | 1.1% | 💥 PoC | Paloaltonetworks Pan-osSiemens Ruggedcom Ape1808 Firmware | 13/5/2026 | 14/7/2026 | An authentication bypass vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to bypass authentication controls when Cloud Authentication Service (CAS) is enabled. The risk is higher if CAS is enabled on the management interface and lower when any other login… | |
| Analizada | Alta (7.2) | 0.47% | — | Paloaltonetworks Pan-osSiemens Ruggedcom Ape1808 Firmware | 13/5/2026 | 14/7/2026 | A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo Alto Networks PAN-OS® Software allows an unauthenticated attacker with network access to cause a denial of service (DoS) condition (all PAN-OS platforms except Cloud NGFW and Prisma Access) or potentially execute arbitrary code by sending… | |
| Analizada | Alta (7.2) | 0.37% | — | Paloaltonetworks Pan-os | 13/5/2026 | 14/7/2026 | A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PAN-OS® software allows an unauthenticated network-based attacker to execute arbitrary code with elevated privileges on the firewall, or cause a denial of service (DoS) condition. Panorama, Cloud NGFW, and Prisma® Access are not impacted by… | |
| Analizada | Alta (7.3) | 0.15% | — | Paloaltonetworks Prisma Browser | 13/5/2026 | 14/7/2026 | An improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to an internal automation bridge. This allows a locally authenticated non-admin user to leverage an exposed communication channel to send unauthorized commands to the browser,… | |
| Analizada | Crítica (9.3) | 32% | ⚠ Explotación activa💥 PoC | Paloaltonetworks Pan-osSiemens Ruggedcom Ape1808 Firmware | 6/5/2026 | 17/6/2026 | A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this… | |
| En análisis | Alta (7.2) | 0.23% | — | Paloaltonetworks Cortex XsiamPaloaltonetworks Cortex Xsoar | 13/4/2026 | 7/7/2026 | An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams that enables an unauthenticated user to access and modify protected resources. | |
| Analizada | Baja (2) | 0.18% | — | Paloaltonetworks Autonomous Digital Experience Manager | 13/4/2026 | 7/7/2026 | A certificate validation vulnerability in Palo Alto Networks Autonomous Digital Experience Manager on Windows allows an unauthenticated attacker with adjacent network access to execute arbitrary code with NT AUTHORITY\SYSTEM privileges. | |
| Analizada | Media (4) | 0.15% | — | Paloaltonetworks Cortex XDR Agent | 13/4/2026 | 7/7/2026 | A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows administrator to disable the agent. This issue may be leveraged by malware to perform malicious activity without detection. | |
| Pendiente de análisis | Media (5.7) | 0.17% | — | Paloaltonetworks Cortex XDRAI | 11/3/2026 | 17/6/2026 | An information disclosure vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to obtain and modify sensitive information by triggering live terminal session via Cortex UI and modifying any configuration setting. The attacker must have network access to the Broker VM to exploit this… | |
| Pendiente de análisis | Media (4) | 0.14% | — | Paloaltonetworks Cortex XDRAI | 11/3/2026 | 17/6/2026 | A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on macOS allows a local administrator to disable the agent. This issue could be leveraged by malware to perform malicious activity without detection. | |
| Aplazada | Media (6.6) | 0.55% | — | Paloaltonetworks Pan-osAI | 11/2/2026 | 17/6/2026 | A denial-of-service (DoS) vulnerability in the Advanced DNS Security (ADNS) feature of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. Cloud NGFW… | |
| Aplazada | Baja (1.3) | 0.19% | — | Paloaltonetworks Pan-osAIMicrosoft WindowsAI | 11/2/2026 | 17/6/2026 | An improper certificate validation vulnerability in PAN-OS allows users to connect Terminal Server Agents on Windows to PAN-OS using expired certificates even if the PAN-OS configuration would not normally permit them to do so. | |
| Analizada | Media (6.6) | 0.75% | — | Paloaltonetworks Pan-osPaloaltonetworks Prisma Access | 15/1/2026 | 17/6/2026 | A vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to cause a denial of service (DoS) to the firewall. Repeated attempts to trigger this issue results in the firewall entering into maintenance mode. | |
| Aplazada | Baja (2.7) | 0.22% | — | Splunk Add-on FOR Palo Alto NetworksAI | 26/11/2025 | 17/6/2026 | In Splunk Add-on for Palo Alto Networks versions below 2.0.2, the add-on exposes client secrets in plain text in the _internal index during the addition of new “Data Security Accounts“. The vulnerability would require either local access to the log files or administrative access to internal indexes, which by default… | |
| Aplazada | Media (4.4) | 0.09% | — | Paloaltonetworks Prisma BrowserAI | 14/11/2025 | 17/6/2026 | A sensitive information disclosure vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated non-admin user to retrieve sensitive data from Prisma Browser. Browser self-protection should be enabled to mitigate this issue. | |
| Aplazada | Baja (1.1) | 0.11% | — | Paloaltonetworks Prisma BrowserAI | 14/11/2025 | 17/6/2026 | An insufficient validation of an untrusted input vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated non-admin user to revert the browser’s security controls. | |
| Aplazada | Baja (1.1) | 0.13% | — | Paloaltonetworks Prisma BrowserAI | 14/11/2025 | 30/9/2026 | An insufficient policy enforcement vulnerability in Palo Alto Networks Prisma® Browser on Windows allows a locally authenticated non-admin user to bypass the screenshot control feature of the browser. Browser self-protection should be enabled to mitigate this issue. | |
| Aplazada | Media (6.6) | 0.56% | — | Paloaltonetworks Pan-osAIPaloaltonetworks Pa-seriesAIPaloaltonetworks Vm-seriesAIPaloaltonetworks Prisma AccessAI | 13/11/2025 | 17/6/2026 | A denial-of-service (DoS) vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to reboot a firewall by sending a specially crafted packet through the dataplane. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. This issue is applicable to the… | |
| Modificada | Media (5.5) | 0.79% | 💥 PoC | Paloaltonetworks Pan-os | 9/10/2025 | 17/6/2026 | An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and execute arbitrary commands. The security risk posed by this issue is significantly minimized when CLI access is restricted… | |
| Analizada | Media (4.8) | 0.26% | — | Paloaltonetworks Pan-os | 9/10/2025 | 17/6/2026 | An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to view session tokens of users authenticated to the firewall web UI. This may allow impersonation of users whose session tokens are leaked. The security risk posed by this issue is significantly… | |
| Aplazada | Alta (7.2) | 0.18% | — | Paloaltonetworks User-id Credential AgentAI | 12/9/2025 | 17/6/2026 | — |