Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2546▼ 402 respecto a la semana anterior
Críticas / altas1312▲ 29 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
58 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Baja (2.4) | 0.19% | — | Paloaltonetworks Checkov BY Prisma CloudAI | 10/9/2026 | 10/9/2026 | A code execution vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can allow arbitrary code execution when Checkov scans a directory that contains an attacker-controlled configuration file. | |
| Pendiente de análisis | Baja (1.1) | 0.82% | — | Paloaltonetworks Checkov BY Prisma CloudAI | 10/9/2026 | 10/9/2026 | An OS command injection vulnerability in Palo Alto Networks Checkov by Prisma® Cloud enables a local user to execute arbitrary commands in the processes running Checkov. | |
| Pendiente de análisis | Media (5.8) | 0.10% | — | Paloaltonetworks Prisma Access AgentAI | 10/9/2026 | 10/9/2026 | A vulnerability in the EndPoint Data Loss Prevention (DLP) enforcement of Palo Alto Networks Prisma® Access Agent enables a local user to bypass configured DLP policy enforcement controls and exfiltrate sensitive data. This Prisma Access Agent on macOS, Linux, iOS, Android and Chrome OS is not affected. | |
| Pendiente de análisis | Media (4.3) | 0.10% | — | Paloaltonetworks Prisma Access AgentAI | 10/9/2026 | 10/9/2026 | An information disclosure vulnerability in the Palo Alto Networks Prisma® Access Agent on Linux enables a local user to access sensitive configuration data and credentials. The Prisma Access Agent on macOS, Windows, iOS, Android and Chrome OS is not affected. | |
| Analizada | Baja (1.7) | 0.32% | — | Paloaltonetworks Cloud NgfwPaloaltonetworks Prisma AccessPaloaltonetworks Pan-os | 13/8/2026 | 28/8/2026 | An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information. Panorama is not impacted by this vulnerability. | |
| Analizada | Media (6) | 0.11% | — | Paloaltonetworks Prisma Access Agent | 13/8/2026 | 9/9/2026 | A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Windows and macOS devices enables a local user to execute code with elevated privileges. The Prisma Access Agent on Linux, iOS, Android, and ChromeOS is not affected. | |
| Analizada | Media (5.6) | 0.11% | — | Paloaltonetworks Prisma Access Agent | 13/8/2026 | 9/9/2026 | A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tamper protection, enabling unauthorized access to protected processes and files. The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected. | |
| Analizada | Baja (2.1) | 0.13% | — | Paloaltonetworks Prisma Access Agent | 13/8/2026 | 9/9/2026 | An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to inject and intercept arbitrary network traffic. The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome… | |
| Analizada | Baja (1.1) | 0.11% | — | Paloaltonetworks Prisma Access Agent | 13/8/2026 | 9/9/2026 | An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Linux platforms that enables a local low privileged user to delete system files in a limited scope and disable Prisma Access Agent. The Prisma Access Agent on macOS, Windows, iOS, Android, and Chrome… | |
| Analizada | Baja (0.5) | 0.13% | — | Paloaltonetworks Prisma Browser | 13/8/2026 | 9/9/2026 | An information disclosure vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a local attacker to view sensitive data. | |
| Analizada | Baja (0.5) | 0.22% | — | Paloaltonetworks Prisma Browser | 13/8/2026 | 9/9/2026 | A security bypass vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a user to bypass intended security controls. | |
| Pendiente de análisis | Alta (7.7) | 0.71% | — | PrismaporductionAI | 3/8/2026 | 3/9/2026 | A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution. | |
| Analizada | Media (5.8) | 0.15% | — | Paloaltonetworks Prisma Access Agent | 9/7/2026 | 16/7/2026 | Multiple protection mechanism failures in the Prisma Access Agent Data Loss Prevention (DLP) component for Windows allow a local user to bypass DLP policy enforcement controls. The Prisma Access Agent on macOS is not affected. | |
| Analizada | Media (5.7) | 0.20% | — | Paloaltonetworks Prisma Access Agent | 9/7/2026 | 16/7/2026 | An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. The Prisma Access Agent on Windows, macOS, Linux, Android and ChromeOS are not affected. | |
| Analizada | Baja (2) | 0.17% | — | Paloaltonetworks Prisma Browser | 9/7/2026 | 14/7/2026 | A local privilege escalation vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated administrator with access to the macOS local filesystem to perform actions on the device with root privileges. This issue only affects Prisma® Browser on macOS. | |
| Analizada | Media (5.9) | 0.11% | — | Paloaltonetworks Prisma Access Agent | 10/6/2026 | 23/7/2026 | A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices enables a local user to execute code with elevated privileges. This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS. | |
| Analizada | Media (4.4) | 0.10% | — | Paloaltonetworks Prisma Access Agent | 10/6/2026 | 23/7/2026 | A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffic outside the VPN tunnel. This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS. | |
| Analizada | Media (4.9) | 0.17% | — | Paloaltonetworks Prisma Sd-wan | 13/5/2026 | 14/7/2026 | A denial of service (DoS) vulnerability in Palo Alto Networks Prisma SD-WAN ION devices enables an unauthenticated attacker in a network adjacent to a Prisma SD-WAN ION device to cause a system disruption by sending a specially crafted IPv6 packet. | |
| Analizada | Alta (7.8) | 96% | ⚠ Explotación activa | Paloaltonetworks Pan-osPaloaltonetworks Prisma AccessSiemens Ruggedcom Ape1808 Firmware | 13/5/2026 | 17/6/2026 | Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues. | |
| Analizada | Media (6.2) | 0.19% | — | Paloaltonetworks Prisma Access Agent | 13/5/2026 | 14/7/2026 | An improper certificate validation vulnerability in the Prisma Access Agent® for Android and Chrome OS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. By presenting a certificate for any domain issued by a trusted Certificate Authority, the attacker can capture sensitive… | |
| Analizada | Media (5.9) | 0.15% | — | Paloaltonetworks Prisma Access Agent | 13/5/2026 | 14/7/2026 | Multiple authorization bypass vulnerabilities in the Endpoint DLP component of Prisma Access Agent® allow a local attacker to bypass authentication controls and execute privileged operations. | |
| Analizada | Media (5.9) | 0.15% | — | Paloaltonetworks Prisma Access Agent | 13/5/2026 | 14/7/2026 | A vulnerability with a privilege management mechanism in the Palo Alto Networks Prisma Access Agent® enables a locally authenticated non-administrative user to escalate their privileges to root on macOS and Linux or NT AUTHORITY\SYSTEM on Windows. This allows the user to execute arbitrary code and read sensitive… | |
| Analizada | Media (4.3) | 0.14% | — | Paloaltonetworks Prisma Access Agent | 13/5/2026 | 14/7/2026 | Multiple information disclosure vulnerabilities in Prisma Access Agent® allow a local user to access sensitive configuration data and credentials. The Prisma Access Agent on Linux, ChromeOS, Android, and iOS are not affected. | |
| Analizada | Media (5.2) | 0.22% | — | Paloaltonetworks Prisma Sd-wan | 13/5/2026 | 14/7/2026 | An improper certificate validation vulnerability in the Palo Alto Networks Prisma SD-WAN ION enables man-in-the-middle (MitM) attacker to impersonate the controller. | |
| Analizada | Alta (7.3) | 0.16% | — | Paloaltonetworks Prisma Browser | 13/5/2026 | 13/7/2026 | A code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its AppleScript interface allowing a locally authenticated non-admin user to leverage this exposed Apple Event handler to send unauthorized commands to the browser. |