Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
4 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.48% | — | LokkaAIMicrosoft 365AIMicrosoft GraphAIMicrosoft Azure Resource ManagerAI | 15/9/2026 | 30/9/2026 | Lokka is a Model Context Protocol server for Microsoft 365, including Microsoft Graph and other services. Prior to 2.1.2, the Lokka-Microsoft tool in src/mcp/src/main.ts uses direct URL string concatenation to append the user-controlled path value to the management.azure.com base URL. A specially crafted path can… | |
| Analizada | Crítica (9.8) | 0.90% | — | Microsoft Azure Resource Manager | 22/5/2026 | 23/7/2026 | Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (10) | 0.90% | — | Microsoft Azure LocalMicrosoft Azure Resource Manager | 18/5/2026 | 17/6/2026 | Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network. | |
| Modificada | Alta (8.8) | 0.68% | — | Microsoft Azure Resource Manager | 23/1/2026 | 30/7/2026 | Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network. |