Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▲ 13 respecto a la semana anterior
Críticas / altas1459▲ 323 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
22 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.2) | 0.36% | — | Watchguard Fireware OSAI | 29/9/2026 | 30/9/2026 | An integer underflow vulnerability in the WatchGuard Fireware OS IKEv2 daemon (iked) allows a remote, unauthenticated attacker to crash the process by sending a specially crafted encrypted IKEv2 message negotiated with an AES-GCM cipher suite. | |
| Pendiente de análisis | Alta (8.2) | 0.36% | — | Watchguard Fireware OSAI | 29/9/2026 | 30/9/2026 | A NULL pointer dereference vulnerability in Fireware OS's NetFlow packet-processing feature allows a remote, unauthenticated attacker to cause a denial of service by sending a specially crafted IPv6 packet. | |
| Pendiente de análisis | Media (6) | 0.36% | — | Watchguard Fireware OSAI | 29/9/2026 | 30/9/2026 | An improper authorization vulnerability in Fireware OS's Access Portal reverse proxy allows an authenticated, low-privileged Access Portal user to access other web applications they are not authorized for by sending a specially crafted request for a different resource which they are authorized to access. | |
| Pendiente de análisis | Alta (8.7) | 0.36% | — | Watchguard Fireware OSAI | 29/9/2026 | 30/9/2026 | An uncontrolled resource consumption vulnerability in the Fireware OS login process (wgagent) allows a remote, unauthenticated attacker to cause a denial of service by sending a specially crafted request. | |
| Pendiente de análisis | Alta (7.1) | 0.23% | — | Watchguard Fireware OSAI | 29/9/2026 | 30/9/2026 | An uncontrolled resource consumption vulnerability in Fireware OS's diagnostic tasks feature allows a low-privileged, authenticated user to cause a denial of service of the system's diagnostic tools by repeatedly starting and aborting a specially crafted diagnostic task through the web UI. | |
| Pendiente de análisis | Alta (8.2) | 0.32% | — | Watchguard Fireware OSAI | 29/9/2026 | 30/9/2026 | A path traversal vulnerability in the Fireware OS WebUI management agent allows an authenticated administrator to read or list arbitrary files on the local filesystem by sending a specially crafted management request. | |
| Pendiente de análisis | Alta (7.5) | 0.32% | — | Watchguard Fireware OSAI | 29/9/2026 | 1/10/2026 | A deserialization of untrusted data vulnerability in WatchGuard Fireware OS's SAML single sign-on session handling (samld) allows an attacker who has already obtained the ability to write files on the appliance to execute arbitrary code in the context of the samld service by causing samld to load a maliciously crafted… | |
| Aplazada | Alta (8.7) | 0.54% | — | Watchguard Fireware OSAI | 28/8/2026 | 3/9/2026 | An integer underflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic. | |
| Aplazada | Alta (8.7) | 0.54% | — | Watchguard Fireware OSAI | 28/8/2026 | 3/9/2026 | A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process iallows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic. | |
| Aplazada | Alta (8.7) | 0.54% | — | Watchguard Fireware OSAI | 28/8/2026 | 3/9/2026 | An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic. | |
| Aplazada | Alta (8.6) | 0.61% | — | Watchguard Fireware OSAI | 28/8/2026 | 3/9/2026 | A buffer overflow vulnerability in the WatchGuard Fireware OS Management Web UI allows an authenticated administrator with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic. | |
| Aplazada | Crítica (9.3) | 0.47% | — | Watchguard Fireware OSAI | 28/8/2026 | 3/9/2026 | A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic. | |
| Aplazada | Alta (8.7) | 0.32% | — | Watchguard Fireware OSAI | 28/8/2026 | 3/9/2026 | An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic. | |
| Aplazada | Alta (8.7) | 0.32% | — | Watchguard Fireware OSAI | 28/8/2026 | 3/9/2026 | A double-free vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic. | |
| Aplazada | Crítica (9.3) | 0.46% | — | Watchguard Fireware OSAI | 28/8/2026 | 3/9/2026 | A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic. | |
| Aplazada | Alta (8.7) | 0.32% | — | Watchguard Fireware OSAI | 28/8/2026 | 3/9/2026 | An integer underflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic. | |
| Aplazada | Crítica (9.3) | 0.44% | — | Watchguard Fireware OSAI | 28/8/2026 | 3/9/2026 | A stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the deprecated Mobile Security feature in WatchGuard Fireware OS allows an unauthenticated remote attacker to execute arbitrary code. | |
| Aplazada | Media (6.9) | 0.41% | — | Watchguard Fireware OSAI | 28/8/2026 | 28/8/2026 | A heap-based buffer overflow vulnerability in Fireware OS's iked process allows an authenticated administrator to crash the IKE daemon (iked), resulting in a denial of service, by saving a specially crafted configuration. | |
| Aplazada | Alta (7) | 0.92% | — | Watchguard Fireware OSAI | 30/1/2026 | 10/8/2026 | An LDAP Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensitive information from a connected LDAP authentication server through an exposed authentication or management web interface. This vulnerability may also allow a remote attacker to authenticate as an… | |
| Aplazada | Media (6.9) | 0.45% | — | Watchguard Fireware OSAI | 15/9/2025 | 10/8/2026 | An HTTP Request Smuggling [CWE-444] vulnerability in the Authentication portal of WatchGuard Fireware OS allows a remote attacker to evade request parameter sanitation and perform a reflected self-Cross-Site Scripting (XSS) attack. WatchGuard does not believe there is a practical exploit chain with a meaningful… | |
| Aplazada | Media (4.8) | 0.45% | — | Watchguard Fireware OSAI | 16/5/2025 | 8/8/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS allows Stored XSS via the spamBlocker module. This vulnerability requires an authenticated administrator session to a locally managed Firebox. | |
| Aplazada | Media (6.5) | 1.3% | — | Watchguard Fireware OSAIWatchguard FireboxAIWatchguard XTMAI | 28/1/2025 | 17/6/2026 | An argument injection vulnerability in the diagnose and import pac commands in WatchGuard Fireware OS before 12.8.1, 12.1.4, and 12.5.10 allows an authenticated remote attacker with unprivileged credentials to upload or read files to limited, arbitrary locations on WatchGuard Firebox and XTM appliances |