Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
8415 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.1) | 1.4% | — | Cisco ISEAICisco Ise-picAI | 16/9/2026 | 17/9/2026 | A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have valid administrative credentials. This… | |
| Pendiente de análisis | Alta (7) | 0.12% | — | Projectdiscovery NucleiAI | 16/9/2026 | 24/9/2026 | Nuclei versions before 3.11.1 cache template signature verification based only on file modification time without content checksums. Attackers can replace verified templates with unsigned malicious content and restore the original modification time to bypass signature checks and execute arbitrary operating system… | |
| Pendiente de análisis | Alta (7.5) | 0.57% | — | ISC BindAI | 16/9/2026 | 17/9/2026 | If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC at the same owner name, it will trigger an unexpected program exit. This issue affects BIND 9 versions 9.11.0 through 9.18.50,… | |
| Pendiente de análisis | Media (5.9) | 0.23% | — | ISC BindAI | 16/9/2026 | 17/9/2026 | A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned answer through. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and… | |
| Pendiente de análisis | Alta (7.5) | 0.57% | — | ISC BindAI | 16/9/2026 | 17/9/2026 | If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of QTYPE TKEY which may cause an assertion failure and subsequent unexpected program exit. This issue affects BIND 9 versions 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, and 9.20.9-S1 through… | |
| Pendiente de análisis | Media (5.3) | 0.48% | — | ISC BindAI | 16/9/2026 | 17/9/2026 | In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOA record). If the RDATA is the same on all the copies, the record is appended to the in-memory RDATA set, which can cause increased memory usage of the negative cache and possibly lead to other… | |
| Pendiente de análisis | Media (5.3) | 0.48% | — | ISC BindAI | 16/9/2026 | 17/9/2026 | A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid DNSSEC record. Default limits on "max-records-per-type" and "max-types-per-name" help mitigate the exposure. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through… | |
| Pendiente de análisis | Alta (7.5) | 0.57% | — | ISC BindAI | 16/9/2026 | 17/9/2026 | On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1,… | |
| Pendiente de análisis | Media (6.5) | 0.24% | — | ISC BindAI | 16/9/2026 | 17/9/2026 | For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message with the TSIG signature arrives. This could allow an attacker that does not actually possess a valid TSIG signature to send unauthorized zone contents to a secondary server.… | |
| Pendiente de análisis | Crítica (9.6) | 0.23% | — | Cisco Secure Adaptive Security Appliance SoftwareAICisco Secure Firewall Threat Defense SoftwareAICisco Secure Firewall Management Center SoftwareAI | 16/9/2026 | 18/9/2026 | The vulnerabilities tracked by CVE-2026-20331 are related to the failure of protection mechanisms issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-693. | |
| Analizada | Crítica (9.9) | 0.37% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 16/9/2026 | 28/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses… | |
| Pendiente de análisis | Alta (7.5) | 0.57% | — | ISC BindAI | 16/9/2026 | 17/9/2026 | If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the resolver will spend disproportionate CPU time constructing the response. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.18.11-S1 through… | |
| Pendiente de análisis | Alta (7.5) | 0.57% | — | ISC BindAI | 16/9/2026 | 17/9/2026 | A BIND resolver encountering an SVCB/HTTPS AliasMode record referencing 14 or more SVCB/HTTPS ServiceMode records may fail to properly deallocate internal resources. If this happens repeatedly, resource exhaustion will eventually prevent the resolver from performing new recursive lookups. This issue affects BIND 9… | |
| Pendiente de análisis | Media (5.8) | 0.21% | — | ISC BindAI | 16/9/2026 | 17/9/2026 | A malformed zone may contain an NS or DNAME node above its origin, which `named` treats as a zone cut. If an attacker inserts a malformed zone into a BIND authoritative server (e.g., via zone transfer), queries for names inside the configured zone then lose authoritative status and return an out-of-zone delegation. On… | |
| Pendiente de análisis | Alta (7.5) | 6.6% | — | ISC BindAI | 16/9/2026 | 17/9/2026 | An attacker can cause `named` to abort by sending a crafted DNS-over-HTTPS request with a cryptographically invalid SIG(0) record, and then closing the transport connection prematurely. This issue affects BIND 9 versions 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, and 9.20.9-S1 through 9.20.27-S1. | |
| Pendiente de análisis | Media (5.9) | 0.23% | — | ISC BindAI | 16/9/2026 | 17/9/2026 | An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an attacker at the same or an upstream level of the zone name to mask the existence of a victim's wildcard record. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27,… | |
| Pendiente de análisis | Alta (7.5) | 0.57% | — | ISC BindAI | 16/9/2026 | 17/9/2026 | If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in `named` results in a negative cache entry of 0 bytes. When this entry is subsequently read, `named` aborts. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0… | |
| Pendiente de análisis | Media (5.9) | 0.46% | — | ISC BindAI | 16/9/2026 | 17/9/2026 | An attacker may be able to cause a `named` resolver to abort. The attack requires inducing the victim resolver to send multiple queries for a DNSSEC-signed zone hosted by an authoritative server under the control of the attacker. If the auth responds with a particular sequence of crafted answers, and those answers… | |
| Pendiente de análisis | Baja (2.1) | 0.20% | — | Cisco IOS XEAI | 14/9/2026 | 16/9/2026 | A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed, either via the clear dot1x host all CLI command or due to a supplicant timeout. During this window, the supplicant's traffic may pass without ACL enforcement. | |
| Analizada | Crítica (9.8) | 28% | ⚠ Explotación activa💥 PoC | Cisco Asyncos | 14/9/2026 | 15/9/2026 | A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An… | |
| Pendiente de análisis | Crítica (9.8) | 0.53% | — | Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI | 14/9/2026 | 15/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered… | |
| Pendiente de análisis | Alta (7.5) | 0.47% | — | Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI | 14/9/2026 | 16/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered… | |
| Pendiente de análisis | Crítica (9.8) | 0.53% | — | Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI | 14/9/2026 | 15/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered… | |
| Pendiente de análisis | Crítica (9.8) | 0.62% | — | Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI | 14/9/2026 | 15/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered… | |
| Pendiente de análisis | Crítica (9.8) | 0.40% | — | Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI | 14/9/2026 | 15/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered… |