Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 211 respecto a la semana anterior
Críticas / altas1376▲ 147 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
2304 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.3) | 0.13% | — | Watchguard Kernel Memory Access DriverAI | 1/10/2026 | 2/10/2026 | A missing authentication vulnerability in the Kernel Memory Access Driver (PSKMAD) used by WatchGuard endpoint security products allows a local, authenticated attacker to bypass the driver's access-control handshake and issue arbitrary privileged commands to the driver, resulting in disclosure of kernel and process… | |
| Pendiente de análisis | Alta (8.7) | 0.42% | — | Watchguard FirewareAI | 30/9/2026 | 30/9/2026 | A NULL pointer dereference vulnerability in the WatchGuard Fireware OS authentication process allows a remote, unauthenticated attacker to crash the management daemon by sending a specially request to the login interface, resulting in a denial of service. | |
| Pendiente de análisis | Alta (7.1) | 0.21% | — | Watchguard WgagentAI | 29/9/2026 | 30/9/2026 | A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted… | |
| Pendiente de análisis | Alta (7.1) | 0.27% | — | Watchguard WgagentAI | 29/9/2026 | 30/9/2026 | A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted… | |
| Pendiente de análisis | Alta (8.2) | 0.34% | — | Watchguard FirewareAI | 29/9/2026 | 30/9/2026 | An integer underflow vulnerability in the WatchGuard Fireware OS IKE daemon (iked) allows a remote attacker who has completed the initial IKEv2 handshake to crash the iked process by sending a specially crafted encrypted IKEv2 message, resulting in a denial of service. | |
| Pendiente de análisis | Alta (8.2) | 0.36% | — | Watchguard Fireware OSAI | 29/9/2026 | 30/9/2026 | An integer underflow vulnerability in the WatchGuard Fireware OS IKEv2 daemon (iked) allows a remote, unauthenticated attacker to crash the process by sending a specially crafted encrypted IKEv2 message negotiated with an AES-GCM cipher suite. | |
| Pendiente de análisis | Crítica (9.2) | 0.33% | — | Watchguard FirewareAI | 29/9/2026 | 1/10/2026 | A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox. | |
| Pendiente de análisis | Alta (8.2) | 0.36% | — | Watchguard Fireware OSAI | 29/9/2026 | 30/9/2026 | A NULL pointer dereference vulnerability in Fireware OS's NetFlow packet-processing feature allows a remote, unauthenticated attacker to cause a denial of service by sending a specially crafted IPv6 packet. | |
| Pendiente de análisis | Media (6) | 0.36% | — | Watchguard Fireware OSAI | 29/9/2026 | 30/9/2026 | An improper authorization vulnerability in Fireware OS's Access Portal reverse proxy allows an authenticated, low-privileged Access Portal user to access other web applications they are not authorized for by sending a specially crafted request for a different resource which they are authorized to access. | |
| Pendiente de análisis | Alta (8.7) | 0.36% | — | Watchguard Fireware OSAI | 29/9/2026 | 30/9/2026 | An uncontrolled resource consumption vulnerability in the Fireware OS login process (wgagent) allows a remote, unauthenticated attacker to cause a denial of service by sending a specially crafted request. | |
| Pendiente de análisis | Alta (7.2) | 0.21% | — | Watchguard FirewareAI | 29/9/2026 | 30/9/2026 | An improper authorization vulnerability in WatchGuard Fireware OS's SAML login process allows a remote, authenticated SAML user with access only to the Access Portal to obtain unauthorized Mobile VPN with SSL access through a specially crafted request. | |
| Aplazada | Alta (8.7) | 0.20% | — | Watchguard FirewareAI | 29/9/2026 | 1/10/2026 | A stack-based buffer overflow vulnerability in WatchGuard Fireware OS's DHCP fingerprinting daemon (fingerd) allows an unauthenticated attacker with adjacent network access to execute arbitrary code or crash the process by sending a specially crafted DHCP packet. | |
| Pendiente de análisis | Alta (8.6) | 0.34% | — | Watchguard FirewareAI | 29/9/2026 | 1/10/2026 | A stack-based buffer overflow vulnerability in the spamBlocker (spamd) service of WatchGuard Fireware OS allows an authenticated attacker with administrator privileges to crash the service or potentially execute arbitrary code by sending a specially crafted management request. | |
| Pendiente de análisis | Alta (7.1) | 0.23% | — | Watchguard Fireware OSAI | 29/9/2026 | 30/9/2026 | An uncontrolled resource consumption vulnerability in Fireware OS's diagnostic tasks feature allows a low-privileged, authenticated user to cause a denial of service of the system's diagnostic tools by repeatedly starting and aborting a specially crafted diagnostic task through the web UI. | |
| Pendiente de análisis | Alta (8.2) | 0.32% | — | Watchguard Fireware OSAI | 29/9/2026 | 30/9/2026 | A path traversal vulnerability in the Fireware OS WebUI management agent allows an authenticated administrator to read or list arbitrary files on the local filesystem by sending a specially crafted management request. | |
| Pendiente de análisis | Alta (7.5) | 0.32% | — | Watchguard Fireware OSAI | 29/9/2026 | 1/10/2026 | A deserialization of untrusted data vulnerability in WatchGuard Fireware OS's SAML single sign-on session handling (samld) allows an attacker who has already obtained the ability to write files on the appliance to execute arbitrary code in the context of the samld service by causing samld to load a maliciously crafted… | |
| Aplazada | Alta (8.6) | 1.2% | — | Watchguard APAI | 28/9/2026 | 28/9/2026 | An OS command injection vulnerability in the WatchGuard AP diagnostic CLI allows an authenticated administrator to execute arbitrary operating system commands by supplying crafted input. | |
| Aplazada | Crítica (9.3) | 1.8% | — | Watchguard APAI | 28/9/2026 | 28/9/2026 | An OS command injection vulnerability in the WatchGuard AP internal API service allows an attacker with network access to the AP to execute arbitrary shell commands on the underlying operating system. | |
| Aplazada | Crítica (9.3) | 0.27% | — | Watchguard Access PointAI | 28/9/2026 | 28/9/2026 | An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker with network access to the AP to obtain a valid API session. | |
| Pendiente de análisis | Alta (7.4) | 0.50% | — | Watchguard Authpoint GatewayAI | 23/9/2026 | 24/9/2026 | A missing/improper authentication vulnerability in the WatchGuard AuthPoint Gateway's LDAP Sync first-factor authentication allows a remote attacker to bypass single-factor password verification under non-default operating conditions. Additional authentication factors still apply. | |
| Aplazada | Media (6.9) | 0.14% | — | Watchdog AntivirusAIMicrosoft WindowsAI | 20/9/2026 | 22/9/2026 | Missing Authorization in the IOCTL handlers of the wsdkd.sys kernel drivers in Watchdog WatchDog Antivirus 1.8.640 (driver versions 1.3.0.0 and earlier) on Microsoft Windows allows local, low-privileged attackers to delete arbitrary files with SYSTEM privileges, bypassing NTFS access controls and potentially disabling… | |
| Aplazada | Media (5.2) | 0.18% | — | Watchdog Anti-virusAI | 20/9/2026 | 22/9/2026 | Improper link resolution before file access in the quarantine restoration process of WatchDog Anti-Virus 1.8.640 on Windows allows local, low-privileged attackers to cause a quarantined file to be written to an arbitrary filesystem location by creating a directory junction at the original file path and persuading an… | |
| Aplazada | Media (5.9) | 0.14% | — | Watchdog Anti-virusAI | 20/9/2026 | 22/9/2026 | Incorrect default permissions in the installation directory of WatchDog Anti-Virus on Windows allow local, low-privileged users to modify, replace, or delete antivirus binaries and configuration files, because the installer grants the Users group Full Control over C:\Program Files (x86)\Watchdog Anti-Virus. This may… | |
| Analizada | Alta (7.5) | 0.43% | — | Apple IpadosApple Iphone OSApple Watchos | 14/9/2026 | 16/9/2026 | A privacy issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, watchOS 27. An app may be able to track users across apps and websites without permission. | |
| Analizada | Media (5.5) | 0.16% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 14/9/2026 | 16/9/2026 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to disclose kernel memory. |