Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3059▲ 556 respecto a la semana anterior
Críticas / altas1460▲ 282 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.3) | 0.21% | — | Netx SecureAI | 29/9/2026 | 29/9/2026 | When NetX Secure is built with `NX_SECURE_KEY_CLEAR`, every TLS record sent on an active session is wiped after it has been handed to TCP. By then the TCP layer owns the packet chain and may already have released it to the packet pool. The wipe therefore writes zeros into packets that are free or in use by another… | |
| Pendiente de análisis | Media (6.3) | 0.16% | — | Expresslogic Netx Secure TLSAI | 29/9/2026 | 29/9/2026 | NetX Secure TLS accepts an empty application-data record without verifying its message authentication code. In `_nx_secure_verify_mac`, a decrypted application record whose length equals the negotiated MAC size is treated as valid and returns success after advancing the receive sequence number. The received MAC is… | |
| Pendiente de análisis | Alta (7.5) | 0.17% | — | Microsoft Netx SecureAI | 29/9/2026 | 30/9/2026 | The `_nx_secure_x509_asn1_tlv_block_parse()` function parses ASN.1 TLV (tag-length-value) blocks out of DER-encoded data. It is the primitive underneath all X.509 certificate parsing in NetX Secure, and therefore runs on certificates supplied by a remote peer during the TLS handshake. The function reads the one-byte… | |
| Pendiente de análisis | Alta (7.5) | 0.24% | — | Azure Netx SecureAI | 29/9/2026 | 30/9/2026 | Two client-side TLS/DTLS handshake parsers in NetX Secure read fields from a server-supplied message before validating that the message is long enough to contain them. Both are bounded out-of-bounds reads on a remotely reachable path, both are reached from a TLS or DTLS client connecting to a malicious or malformed… | |
| Pendiente de análisis | Media (6.3) | 0.21% | — | Netx SecureAI | 29/9/2026 | 29/9/2026 | Predictable DTLS HelloVerifyRequest Cookie in NetX Secure |