Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
34 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.8) | 0.22% | — | Paloaltonetworks Cortex XDR Broker VMAI | 10/9/2026 | 11/9/2026 | A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an authenticated low privileged user with man-in-the-middle (MitM) access to execute code with root privileges on the Broker VM. | |
| En análisis | Baja (1.1) | 0.14% | — | Paloaltonetworks Cortex XDR Broker VM | 9/7/2026 | 16/7/2026 | A privilege escalation vulnerability in Palo Alto Networks Cortex® XDR Broker VM enables a locally authenticated user to perform actions as the root user. | |
| Analizada | Media (4) | 0.15% | — | Paloaltonetworks Cortex XDR Agent | 13/4/2026 | 7/7/2026 | A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows administrator to disable the agent. This issue may be leveraged by malware to perform malicious activity without detection. | |
| Pendiente de análisis | Media (5.7) | 0.17% | — | Paloaltonetworks Cortex XDRAI | 11/3/2026 | 17/6/2026 | An information disclosure vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to obtain and modify sensitive information by triggering live terminal session via Cortex UI and modifying any configuration setting. The attacker must have network access to the Broker VM to exploit this… | |
| Pendiente de análisis | Media (4) | 0.14% | — | Paloaltonetworks Cortex XDRAI | 11/3/2026 | 17/6/2026 | A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on macOS allows a local administrator to disable the agent. This issue could be leveraged by malware to perform malicious activity without detection. | |
| Aplazada | Baja (2.4) | 0.14% | — | Microsoft 365 DefenderAIPaloaltonetworks Cortex XDRAI | 12/9/2025 | 17/6/2026 | A problem with the Palo Alto Networks Cortex XDR Microsoft 365 Defender Pack can result in exposure of user credentials in application logs. Normally, these application logs are only viewable by local users and are included when generating logs for troubleshooting purposes. This means that these credentials are… | |
| Aplazada | Media (5.3) | 0.17% | — | Paloaltonetworks Cortex XDR Broker VMAI | 13/8/2025 | 17/6/2026 | A credential management flaw in Palo Alto Networks Cortex XDR® Broker VM causes different Broker VM images to share identical default credentials for internal services. Users knowing these default credentials could access internal services on other Broker VM installations. The attacker must have network access to the… | |
| Aplazada | Media (4.6) | 0.19% | — | Paloaltonetworks Cortex XDR BrokerAI | 13/6/2025 | 17/6/2026 | An incorrect privilege assignment vulnerability in Palo Alto Networks Cortex® XDR Broker VM allows an authenticated administrative user to execute certain files available within the Broker VM and escalate their privileges to root. | |
| Aplazada | Media (6.5) | 0.49% | — | Paloaltonetworks Cortex XDR Broker VMAI | 14/5/2025 | 17/6/2026 | A code injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute arbitrary code with root privileges on the host operating system running Broker VM. | |
| Aplazada | Media (6.9) | 0.44% | — | Paloaltonetworks Cortex XDR Broker VMAI | 14/5/2025 | 17/6/2026 | A missing authentication vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an unauthenticated user to disable certain internal services on the Broker VM. The attacker must have network access to the Broker VM to exploit this issue. | |
| Aplazada | Media (6.3) | 0.56% | — | Paloaltonetworks Cortex XDR Broker VMAI | 11/4/2025 | 17/6/2026 | A command injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute arbitrary OS commands with root privileges on the host operating system running Broker VM. | |
| Aplazada | Media (6.8) | 0.17% | — | Paloaltonetworks Cortex XDRAI | 11/4/2025 | 17/6/2026 | A null pointer dereference vulnerability in the Palo Alto Networks Cortex® XDR agent on Windows devices allows a low-privileged local Windows user to crash the agent. Additionally, malware can use this vulnerability to perform malicious activity without Cortex XDR being able to detect it. | |
| Aplazada | Media (6.8) | 0.20% | — | Paloaltonetworks Cortex XDRAI | 20/2/2025 | 17/6/2026 | A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to disable the agent. This vulnerability can also be leveraged by malware to disable the Cortex XDR agent and then perform malicious activity. | |
| Aplazada | Media (5.3) | 0.26% | — | Paloaltonetworks Cortex XDR Broker VMAI | 12/2/2025 | 17/6/2026 | A problem with the network isolation mechanism of the Palo Alto Networks Cortex XDR Broker VM allows attackers unauthorized access to Docker containers from the host network used by Broker VM. This may allow access to read files sent for analysis and logs transmitted by the Cortex XDR Agent to the Cortex XDR server. | |
| Analizada | Media (5.7) | 0.21% | — | Paloaltonetworks Cortex XDR Agent | 9/10/2024 | 17/6/2026 | A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity. | |
| Analizada | Media (5.6) | 0.19% | — | Paloaltonetworks Cortex XDR Agent | 11/9/2024 | 17/6/2026 | A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows administrator privileges to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity. | |
| Aplazada | Media (6.8) | 0.13% | — | Paloaltonetworks Cortex XDR AgentAI | 10/7/2024 | 17/6/2026 | An improper file signature check in Palo Alto Networks Cortex XDR agent may allow an attacker to bypass the Cortex XDR agent's executable blocking capabilities and run untrusted executables on the device. This issue can be leveraged to execute untrusted software without being detected or blocked. | |
| Modificada | Media (6.8) | 0.41% | — | Paloaltonetworks Cortex XDR Agent | 12/6/2024 | 17/6/2026 | A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privileged local Windows user to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity. | |
| Modificada | Media (5.2) | 0.13% | — | Paloaltonetworks Cortex XDR Agent | 12/6/2024 | 17/6/2026 | A privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices enables a local user to execute programs with elevated privileges. However, execution does require the local user to successfully exploit a race condition, which makes this vulnerability difficult to exploit. | |
| Modificada | Baja (2) | 0.09% | — | Paloaltonetworks Cortex XDR Agent | 12/6/2024 | 17/6/2026 | A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local low privileged Windows user to disrupt some functionality of the agent. However, they are not able to disrupt Cortex XDR agent protection mechanisms using this vulnerability. | |
| Modificada | Media (5.5) | 0.32% | — | Paloaltonetworks Cortex XDR Agent | 13/9/2023 | 17/6/2026 | A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user to disable the agent. | |
| Modificada | Alta (7.8) | 0.29% | — | Paloaltonetworks Cortex XDR Agent | 8/2/2023 | 17/6/2026 | A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user to execute privileged cytool commands that disable or uninstall the agent. | |
| Modificada | Media (6.7) | 0.21% | — | Paloaltonetworks Cortex XDR Agent | 8/2/2023 | 17/6/2026 | An information exposure vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local system administrator to disclose the admin password for the agent in cleartext, which bad actors can then use to execute privileged cytool commands that disable or uninstall the agent. | |
| Modificada | Media (5.5) | 0.22% | — | Paloaltonetworks Cortex XDR Agent | 14/9/2022 | 17/6/2026 | An improper link resolution vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local attacker to read files on the system with elevated privileges when generating a tech support file. | |
| Modificada | Media (6.7) | 0.23% | — | Paloaltonetworks Cortex XDR Agent | 11/5/2022 | 17/6/2026 | A local privilege escalation (PE) vulnerability exists in Palo Alto Networks Cortex XDR agent software on Windows that enables an authenticated local user with file creation privilege in the Windows root directory (such as C:\) to execute a program with elevated privileges. This issue impacts all versions of Cortex… |