Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
468 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (6.9) | — | — | Brocade Fabric OSAI | 8/10/2026 | 8/10/2026 | A buffer overflow vulnerability exists in the WebTools administrative interface handling configuration download or file transfer operations of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An authenticated user with permissions to perform configuration downloads using remote server profiles can… | |
| Recibida | Alta (8.5) | — | — | Brocade Fabric OSAI | 8/10/2026 | 8/10/2026 | A command injection vulnerability exists in the WebTools administrative interface handling configuration download or file transfer operations of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An authenticated user with permissions to perform configuration downloads using remote server profiles… | |
| Recibida | Alta (7.7) | — | — | Brocade Fabric OSAI | 8/10/2026 | 8/10/2026 | An authentication bypass vulnerability exists in the web management interface of Brocade Fabric OS versions before 9.2.2d running on the MXG610 platform. An unauthenticated, network-adjacent attacker can exploit an unauthenticated endpoint within the Single Sign-On (SSO) workflow to gain administrative access to the… | |
| Recibida | Alta (8.5) | — | — | Brocade Fabric OSAI | 8/10/2026 | 8/10/2026 | An OS command injection vulnerability exists in the REST API management interface of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1 allows an authenticated, high-privileged remote attacker to execute arbitrary system commands with root permissions. An attacker with administrative privileges to… | |
| Recibida | Media (5.4) | — | — | Brocade Fabric OSAI | 8/10/2026 | 8/10/2026 | An OS command injection vulnerability exists in the PAM (Pluggable Authentication Module) session cleanup routines during SSH session termination on Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An authenticated user authenticating via an external directory or AAA service whose username or… | |
| Recibida | Alta (7.3) | — | — | Brocade Fabric OSAI | 8/10/2026 | 8/10/2026 | A privilege escalation vulnerability exists in the internal Command-Line Interface (CLI) authorization handling mechanism of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An authenticated user or local process that can manipulate the process execution environment can bypass Role-Based Access… | |
| Recibida | Media (5.9) | — | — | Brocade Fabric OSAI | 8/10/2026 | 8/10/2026 | An authentication logic and privilege escalation vulnerability exists in the account management interface of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. Under specific conditions, an authenticated user can bypass authorization restrictions intended to prevent modifying another account's… | |
| Recibida | Media (5.4) | — | — | Brocade Fabric OSAI | 8/10/2026 | 8/10/2026 | An OS command injection vulnerability exists in the account management subsystem of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When an administrator initiates an account deletion, the system invokes an internal maintenance routine to clean up cryptographic keys associated with the target… | |
| Recibida | Alta (8.5) | — | — | Brocade Fabric OSAI | 8/10/2026 | 8/10/2026 | A session context forgery vulnerability exists in the web management daemon of Brocade Fabric OS versions 9.2.2d and 10.0.0 through 10.0.0a1. When processing local inter-process communication (IPC) storage callbacks, the service accepts and registers session structures including administrative role permissions, user… | |
| Recibida | Alta (7.1) | — | — | Brocade Fabric OSAI | 8/10/2026 | 8/10/2026 | An authentication bypass and command injection vulnerability exists in the inter-switch remote execution service of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When processing remote command execution IPC frames across the fabric, the receiving switch processes these commands at an elevated… | |
| Recibida | Alta (7) | — | — | Brocade FabricAI | 8/10/2026 | 8/10/2026 | Brocade Fabric versions before 9.2.2d and 10.0.0 through 10.0.0a1 handling of specific download protocols utilizes unsanitized parameter strings. When processing upgrade requests, parameters are converted into system command strings and executed through a system shell interface. Because control characters and shell… | |
| Recibida | Media (6.8) | — | — | Brocade Fabric OSAI | 8/10/2026 | 8/10/2026 | Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1 directly accepts Apache configuration file data during service setup or re-initialization. An attacker capable of corrupting the configuration structure will prevent the web management service from starting or recovering during service bring-up,… | |
| Recibida | Baja (2.1) | — | — | Brocade Fabric OSAI | 8/10/2026 | 8/10/2026 | A race condition and thread-safety vulnerability exists in the web management daemon of Brocade Fabric OS versions before 10.0.1. When handling user authentication requests across a multi-threaded execution pool, this race condition causes PAM modules to process stale or incorrect client IP addresses and switch… | |
| Recibida | Media (5.7) | — | — | Brocade Fabric OSAI | 8/10/2026 | 8/10/2026 | An arbitrary file and directory deletion vulnerability exists in the REST API management interface handling USB storage operations on Brocade Fabric OS versions before 10.0.1. An authenticated user possessing USB management privileges can manipulate requested target paths to delete arbitrary files or directories on… | |
| Recibida | Media (6.9) | — | — | Brocade Fabric OSAI | 8/10/2026 | 8/10/2026 | A logic vulnerability in Brocade Fabric OS versions before 10.0.1 web management framework allows an authenticated, low-privileged user to bypass inner Role-Based Access Control (RBAC) checks under specific environmental conditions. Successful exploitation lowers the system authorization mode for the active session… | |
| Recibida | Alta (8.5) | — | — | Brocade Fabric OSAI | 8/10/2026 | 8/10/2026 | An input validation vulnerability exists in the security certificate management component of the Brocade Fabric OS administrative management API. When processing certificate management operations, user-supplied certificate identifiers are handled without adequate sanitization prior to execution in external system… | |
| Recibida | Alta (8.5) | — | — | Brocade Fabric OSAI | 8/10/2026 | 8/10/2026 | An authorization and input validation vulnerability exists in Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An authenticated user with restricted privileges in one Virtual Fabric can exploit this issue by submitting a specially crafted request containing an arbitrary fabric identifier. This… | |
| Recibida | Alta (8.4) | — | — | Brocade Fabric OSAI | 8/10/2026 | 8/10/2026 | An arbitrary file manipulation vulnerability exists in the WebTools management interface of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When processing configuration transfer requests, the application fails to properly validate and sanitize a user-supplied status file path parameter. An… | |
| Recibida | Alta (7.3) | — | — | Brocade Fabric OSAI | 8/10/2026 | 8/10/2026 | An OS command injection vulnerability exists in the configuration management subsystem of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When performing a configuration download operation, the management daemon will relay configuration parameters, user-supplied relay host strings, and filenames… | |
| Recibida | Alta (8.5) | — | — | Brocade Fabric OSAI | 8/10/2026 | 8/10/2026 | A local privilege escalation vulnerability exists in the system logging daemon of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. Insufficient access controls on internal inter-process communication (IPC) channels allow an unprivileged local user to submit malformed logging configurations. Due to… | |
| Recibida | Alta (7) | — | — | Brocade Fabric OSAI | 8/10/2026 | 8/10/2026 | An OS command injection vulnerability exists in maintenance command-line diagnostic utilities on Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. The binary fails to sanitize user-supplied input options when invoking underlying system commands through a shell interpreter. A privileged user with… | |
| Recibida | Alta (8.4) | — | — | Brocade Fabric OSAI | 8/10/2026 | 8/10/2026 | An argument injection vulnerability exists in the configuration management command-line utility of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When executing configuration viewing commands with search pattern filters, the utility fails to sanitize user-supplied search string options before… | |
| Recibida | Alta (8.6) | — | — | Brocade Fabric OSAI | 8/10/2026 | 8/10/2026 | An OS command injection vulnerability exists in the time and zone management subsystem of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When updating system timezone settings via the REST API or configuration download routines, the system fails to sanitize input values before processing them in… | |
| Recibida | Alta (7) | — | — | Brocade Fabric OSAI | 8/10/2026 | 8/10/2026 | An improper file permission and missing authorization vulnerability exists in the diagnostic kernel module subsystem of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An unprivileged local user can invoke privileged hardware tests, force system error conditions, reset hardware blades, or disrupt… | |
| Recibida | Baja (2.1) | — | — | Brocade Fabric OSAI | 8/10/2026 | 8/10/2026 | A race condition vulnerability exists in the request processing logic of the REST management interface on Brocade Fabric OS versions before 10.0.1. When handling concurrent incoming network management FCIP requests, a timing window exists between when a request populates the address variable and when the service… |