Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
–

15 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
En análisisAlta (8.1)0.29%—Paloaltonetworks Cortex Xsiam Commvaultsecurityiq MarketplacePaloaltonetworks Cortex Xsoar Commvaultsecurityiq Marketplace10/6/202623/7/2026
An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resources.
AnalizadaMedia (4.8)0.20%—Paloaltonetworks Cortex Xsoar10/6/202623/7/2026
A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenticated attacker on an adjacent network, with the ability to intercept and manipulate network response traffic via a man-in-the-middle (MITM) attack, to write arbitrary files to the host.
En análisisAlta (7.2)0.23%—Paloaltonetworks Cortex XsiamPaloaltonetworks Cortex Xsoar13/4/20267/7/2026
An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams that enables an unauthenticated user to access and modify protected resources.
AplazadaMedia (5.3)0.38%—Paloaltonetworks Cortex XsoarAI9/10/202417/6/2026
A vulnerability in Cortex XSOAR allows the disclosure of incident data to users who do not have the privilege to view the data.
AplazadaMedia (6)0.22%—Paloaltonetworks Cortex XsoarAIPaloaltonetworks Cortex XsiamAIApache ActivemqAI11/9/202417/6/2026
A problem with the ActiveMQ integration for both Cortex XSOAR and Cortex XSIAM can result in the cleartext exposure of the configured ActiveMQ credentials in log bundles.
AnalizadaAlta (7)1.2%—Paloaltonetworks Cortex Xsoar Commonscripts14/8/202417/6/2026
A command injection issue in Palo Alto Networks Cortex XSOAR CommonScripts Pack allows an unauthenticated attacker to execute arbitrary commands within the context of an integration container.
ModificadaMedia (6.7)0.17%—Paloaltonetworks Cortex Xsoar8/11/202317/6/2026
A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system enables a local attacker to execute programs with elevated privileges if the attacker has shell access to the engine.
ModificadaMedia (6.5)1.3%—Paloaltonetworks Cortex XsoarFedoraproject Fedora8/2/202317/6/2026
A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user with access to the web interface to read local files from the server.
ModificadaMedia (6.7)0.12%—Paloaltonetworks Cortex Xsoar9/11/202217/6/2026
A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system allows a local attacker with shell access to the engine to execute programs with elevated privileges.
ModificadaMedia (4.3)0.55%—Paloaltonetworks Cortex Xsoar11/5/202217/6/2026
An improper authorization vulnerability in Palo Alto Network Cortex XSOAR software enables authenticated users in non-Read-Only groups to generate an email report that contains summary information about all incidents in the Cortex XSOAR instance, including incidents to which the user does not have access. This issue…
ModificadaMedia (5.4)1.7%—Paloaltonetworks Cortex Xsoar10/2/202217/6/2026
A stored cross-site scripting (XSS) vulnerability in Palo Alto Network Cortex XSOAR web interface enables an authenticated network-based attacker to store a persistent javascript payload that will perform arbitrary actions in the Cortex XSOAR web interface on behalf of authenticated administrators who encounter the…
ModificadaAlta (8.1)0.58%—Paloaltonetworks Cortex Xsoar8/9/202117/6/2026
An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR SAML authentication that enables an unauthenticated network-based attacker with specific knowledge of the Cortex XSOAR instance to access protected resources and perform unauthorized actions on the Cortex XSOAR server. This issue…
ModificadaMedia (4.3)0.49%—Paloaltonetworks Cortex Xsoar8/9/202117/6/2026
An improper authorization vulnerability in the Palo Alto Networks Cortex XSOAR server enables an authenticated network-based attacker with investigation read permissions to download files from incident investigations of which they are aware but are not a part of. This issue impacts: All Cortex XSOAR 5.5.0 builds;…
ModificadaCrítica (9.8)1.4%—Paloaltonetworks Cortex Xsoar22/6/202117/6/2026
An improper authorization vulnerability in Palo Alto Networks Cortex XSOAR enables a remote unauthenticated attacker with network access to the Cortex XSOAR server to perform unauthorized actions through the REST API. This issue impacts: Cortex XSOAR 6.1.0 builds later than 1016923 and earlier than 1271064; Cortex…
ModificadaMedia (5.1)0.17%—Paloaltonetworks Cortex Xsoar10/3/202117/6/2026
An information exposure through log file vulnerability exists in Cortex XSOAR software where the secrets configured for the SAML single sign-on (SSO) integration can be logged to the '/var/log/demisto/' server logs when testing the integration during setup. This logged information includes the private key and identity…