Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.8) | 0.22% | — | Paloaltonetworks Cortex XDR Broker VMAI | 10/9/2026 | 11/9/2026 | A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an authenticated low privileged user with man-in-the-middle (MitM) access to execute code with root privileges on the Broker VM. | |
| En análisis | Baja (1.1) | 0.14% | — | Paloaltonetworks Cortex XDR Broker VM | 9/7/2026 | 16/7/2026 | A privilege escalation vulnerability in Palo Alto Networks Cortex® XDR Broker VM enables a locally authenticated user to perform actions as the root user. | |
| Analizada | Baja (1.1) | 0.10% | — | Paloaltonetworks Broker VM | 13/5/2026 | 13/7/2026 | A vulnerability in Palo Alto Networks Broker VM allows an authenticated administrator to inject arbitrary content into certain Broker VM fields. | |
| Aplazada | Media (5.3) | 0.17% | — | Paloaltonetworks Cortex XDR Broker VMAI | 13/8/2025 | 17/6/2026 | A credential management flaw in Palo Alto Networks Cortex XDR® Broker VM causes different Broker VM images to share identical default credentials for internal services. Users knowing these default credentials could access internal services on other Broker VM installations. The attacker must have network access to the… | |
| Aplazada | Media (6.5) | 0.49% | — | Paloaltonetworks Cortex XDR Broker VMAI | 14/5/2025 | 17/6/2026 | A code injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute arbitrary code with root privileges on the host operating system running Broker VM. | |
| Aplazada | Media (6.9) | 0.44% | — | Paloaltonetworks Cortex XDR Broker VMAI | 14/5/2025 | 17/6/2026 | A missing authentication vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an unauthenticated user to disable certain internal services on the Broker VM. The attacker must have network access to the Broker VM to exploit this issue. | |
| Aplazada | Media (6.3) | 0.56% | — | Paloaltonetworks Cortex XDR Broker VMAI | 11/4/2025 | 17/6/2026 | A command injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute arbitrary OS commands with root privileges on the host operating system running Broker VM. | |
| Aplazada | Media (5.3) | 0.26% | — | Paloaltonetworks Cortex XDR Broker VMAI | 12/2/2025 | 17/6/2026 | A problem with the network isolation mechanism of the Palo Alto Networks Cortex XDR Broker VM allows attackers unauthorized access to Docker containers from the host network used by Broker VM. This may allow access to read files sent for analysis and logs transmitted by the Cortex XDR Agent to the Cortex XDR server. |