Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2838▼ 146 respecto a la semana anterior
Críticas / altas1377▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 268 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.3) | 0.27% | — | IBM I Access FamilyAIIBM I Access Client SolutionsAI | 14/9/2026 | 17/9/2026 | IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a malicious emulator macro RunProgram action. | |
| Pendiente de análisis | Media (6.3) | 0.27% | — | IBM I Access FamilyAIIBM I Access Client SolutionsAI | 14/9/2026 | 17/9/2026 | IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a STRPCCMD CL command. | |
| Analizada | Alta (7.8) | 0.17% | — | IBM I Access Client Solutions | 13/8/2026 | 17/8/2026 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publicly writeable directory. | |
| Analizada | Alta (7.8) | 0.21% | — | IBM I Access Client Solutions | 12/8/2026 | 18/8/2026 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 could allow a local attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. | |
| Analizada | Alta (7.1) | 0.11% | — | IBM I Access Client Solutions | 12/8/2026 | 18/8/2026 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to injection of rogue certificate authority due to publicly writeable truststore. | |
| Analizada | Crítica (9.6) | 0.17% | — | IBM I Access Client Solutions | 12/8/2026 | 18/8/2026 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unverified product code when configured to update from an IBM i. A bad actor could use this vulnerablity to run compromised code on the ACS user's workstation. | |
| Analizada | Alta (8.8) | 0.50% | — | IBM I Access Client Solutions | 12/8/2026 | 18/8/2026 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to zip slip path traversal exploit when importing a configuration. | |
| Analizada | Alta (7.8) | 0.20% | — | IBM I Access Client Solutions | 12/8/2026 | 18/8/2026 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publicly writeable configuration file. | |
| Analizada | Alta (8.8) | 0.81% | — | IBM I Access Client Solutions | 1/6/2026 | 26/8/2026 | IBM i Access Family 1.1.5.0 through 1.1.9.12 IBM i Access Client Solutions (ACS) is vulnerable to remote code execution when configured to listen for requests from IBM i Navigator. | |
| Modificada | Media (5.5) | 0.57% | — | IBM I Access Client Solutions | 9/2/2024 | 17/6/2026 | IBM i Access Client Solutions (ACS) 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.4 is vulnerable to NT LAN Manager (NTLM) hash disclosure by an attacker modifying UNC capable paths within ACS configuration files to point to a hostile server. If NTLM is enabled, the Windows operating system will try to authenticate… | |
| Modificada | Alta (8.8) | 0.99% | — | IBM I Access Client Solutions | 14/12/2023 | 17/6/2026 | IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to execute remote code. Due to improper authority checks the attacker could perform operations on the PC under the user's authority. IBM X-Force ID: 268273. | |
| Modificada | Media (6.5) | 0.63% | — | IBM I Access Client Solutions | 14/12/2023 | 17/6/2026 | IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 is vulnerable to having its key for an encrypted password decoded. By somehow gaining access to the encrypted password, a local attacker could exploit this vulnerability to obtain the password to other systems. IBM X-Force ID: 268265. | |
| Modificada | Alta (7.5) | 1.6% | — | IBM I Access Client Solutions | 14/12/2023 | 17/6/2026 | IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to obtain a decryption key due to improper authority checks. IBM X-Force ID: 268270. | |
| Modificada | Media (6.7) | 0.35% | — | IBM I Access Client Solutions | 21/11/2022 | 17/6/2026 | IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability. By placing a specially crafted file in a compromised folder, an attacker could exploit this vulnerability to… |