Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
24 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Entra ID | 8/9/2026 | 16/9/2026 | Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 0.86% | — | Microsoft Entra ID | 3/9/2026 | 8/9/2026 | Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network. | |
| Pendiente de análisis | Alta (8.8) | 0.42% | — | Jenkins Microsoft Entra ID PluginAI | 2/9/2026 | 3/9/2026 | Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 and earlier grants Entra group permissions using both the group's unique object ID and its display name, allowing attackers who can create an Entra group with a colliding display name to gain the permissions configured for a privileged group. | |
| Analizada | Crítica (9.9) | 0.78% | — | Microsoft Entra ID | 20/8/2026 | 25/8/2026 | Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (10) | 1.5% | — | Microsoft Entra ID | 20/8/2026 | 25/8/2026 | Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.44% | — | Microsoft Entra ID | 11/8/2026 | 13/8/2026 | Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network. | |
| Pendiente de análisis | Crítica (9.3) | 0.88% | — | Moodle Microsoft 365 AND Microsoft Entra ID PluginsAIMoodle Local O365AI | 16/7/2026 | 16/7/2026 | The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration for Moodle. Prior to 4.5.6, 5.0.5, and 5.1.1, the Microsoft Office 365 Integration plugin local_o365 Teams SSO endpoint sso_login.php base64-decodes a JWT payload and authenticates users from the upn… | |
| Analizada | Alta (8.6) | 0.14% | — | Gallagher Active Directory SyncGallagher Cardholder Sync UtilityGallagher Command CentreGallagher Diagnostics Service+11 | 25/5/2026 | 17/8/2026 | Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure. Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted.… | |
| Analizada | Crítica (10) | 0.46% | — | Microsoft Entra ID | 22/5/2026 | 23/7/2026 | Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 0.86% | — | Microsoft Entra ID | 22/5/2026 | 23/7/2026 | Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network. | |
| Aplazada | Media (5.3) | 0.31% | — | Linux-entra-ssoAIGoogle ChromeAIMozilla FirefoxAIMicrosoft Entra IDAI | 12/5/2026 | 17/6/2026 | linux-entra-sso is a browser plugin for Linux to SSO on Microsoft Entra ID. Prior to 1.8.1, platform/chrome/js/platform-chrome.js:69-88 registers a single declarativeNetRequest rule whose urlFilter is Platform.SSO_URL + "/*", i.e. "https://login.microsoftonline.com/*". Chrome's urlFilter without a | or || anchor is… | |
| Analizada | Alta (7.5) | 0.95% | — | Microsoft Entra ID | 12/5/2026 | 17/6/2026 | Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Crítica (10) | 0.90% | — | Microsoft Entra ID | 23/4/2026 | 17/6/2026 | Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network. | |
| Aplazada | Crítica (9.8) | 0.73% | — | Miniorange ALL IN ONE Microsoft 365 Entra ID Azure AD SSO LoginAI | 3/3/2026 | 17/6/2026 | The All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.2.5. This makes it possible for unauthenticated attackers to bypass authentication and log in as other users, including administrators. | |
| Analizada | Media (6.5) | 0.23% | — | Jaseerkinangattil Microsoft Entra ID SSO Login | 4/2/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Microsoft Entra ID SSO Login allows Privilege Escalation.This issue affects Microsoft Entra ID SSO Login: from 0.0.0 before 1.0.4. | |
| Analizada | Crítica (9.8) | 0.55% | — | Microsoft Entra ID | 22/1/2026 | 17/6/2026 | Azure Entra ID Elevation of Privilege Vulnerability | |
| Analizada | Crítica (9.8) | 7.7% | — | Microsoft Entra ID | 9/10/2025 | 17/6/2026 | Azure Entra ID Elevation of Privilege Vulnerability | |
| Analizada | Crítica (9.6) | 0.66% | — | Microsoft Entra ID | 9/10/2025 | 17/6/2026 | Azure Entra ID Elevation of Privilege Vulnerability | |
| Aplazada | Media (4.4) | 0.14% | — | Microsoft Azure Entra IDAIMicrosoft IntuneAIHimmelblau-idm HimmelblauAI | 9/9/2025 | 17/6/2026 | Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Himmelblau 0.9.x derives numeric GIDs for Entra ID groups from the group display name when himmelblau.conf `id_attr_map = name` (the default configuration). Because Microsoft Entra ID allows multiple groups with the same `displayName`… | |
| Modificada | Crítica (9.8) | 1.6% | — | Microsoft Entra ID | 4/9/2025 | 17/6/2026 | Azure Entra ID Elevation of Privilege Vulnerability | |
| Aplazada | Baja (2.8) | 0.14% | — | Microsoft Azure Entra IDAIMicrosoft IntuneAIHimmelblau-idm HimmelblauAI | 2/8/2025 | 17/6/2026 | Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. When debugging is enabled for Himmelblau in version 1.0.0, the himmelblaud_tasks service leaks an Intune service access token to the system journal. This short-lived token can be used to detect the host's Intune compliance status, and may… | |
| Aplazada | Media (5.2) | 0.23% | — | Microsoft Azure Entra IDAIMicrosoft IntuneAIHimmelblau-idm HimmelblauAI | 26/6/2025 | 17/6/2026 | Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. A vulnerability present in versions 0.9.10 through 0.9.16 allows a user to authenticate to a Linux host via Himmelblau using an *invalid* Linux Hello PIN, provided the host is offline. While the user gains access to the local system,… | |
| Aplazada | Media (5.4) | 0.34% | — | Microsoft Azure Entra IDAIMicrosoft IntuneAIHimmelblau-idm HimmelblauAI | 5/6/2025 | 17/6/2026 | Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Himmelblau versions 0.9.0 through 0.9.14 and 1.00-alpha are vulnerable to a privilege escalation issue when Entra ID group-based access restrictions are configured using group display names instead of object IDs. Starting in version… | |
| Analizada | Alta (7.5) | 1.0% | — | Microsoft Entra ID | 23/8/2024 | 17/6/2026 | Improper access control in Decentralized Identity Services resulted in a vulnerability that allows an unauthenticated attacker to disable Verifiable ID's on another tenant. |