Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Crítica (9.8) | — | — | Cisco NX OSAICisco Nexus 3000AICisco Nexus 9000AICisco Application Policy Infrastructure ControllerAI+4 | 7/10/2026 | 7/10/2026 | A vulnerability in the Segment Routing over IPv6 (SRv6) Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) on an affected device. This… | |
| Recibida | Crítica (9.8) | — | — | Cisco NX OSAICisco Nexus 3000AICisco Nexus 9000AICisco Application Policy Infrastructure ControllerAI+3 | 7/10/2026 | 7/10/2026 | A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a Denial-of-Service (DoS) on an affected device. This vulnerability is due to improper… | |
| Recibida | Crítica (9.8) | — | — | Cisco NX OSAICisco Nexus 3000AICisco Nexus 9000AICisco Application Policy Infrastructure ControllerAI+4 | 7/10/2026 | 7/10/2026 | The vulnerability is due to insufficient input validation of data that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP request to the NX-API of an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges and could cause… | |
| Recibida | Alta (8.6) | — | — | Cisco NX OSAICisco Nexus 3000AICisco Nexus 9000AICisco Application Policy Infrastructure ControllerAI+4 | 7/10/2026 | 7/10/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by… | |
| Recibida | Alta (8.8) | — | — | Cisco NX OSAICisco Nexus 3000AICisco Nexus 9000AICisco Application Policy Infrastructure ControllerAI+4 | 7/10/2026 | 7/10/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by… | |
| Recibida | Media (5.8) | — | — | Cisco NX OSAICisco Nexus 3000AICisco Nexus 9000AICisco Application Policy Infrastructure ControllerAI+4 | 7/10/2026 | 7/10/2026 | A vulnerability in Cisco NX-OS Software could allow an unauthenticated, remote attacker to exhaust system resources, causing a denial of service (DoS) condition. This vulnerability exists because rate limiting was improperly applied to some protocols. An attacker could exploit this vulnerability by sending a high rate… | |
| Recibida | Media (5.8) | — | — | Cisco NX OSAICisco Nexus 3000AICisco Nexus 9000AICisco Application Policy Infrastructure ControllerAI+3 | 7/10/2026 | 7/10/2026 | A vulnerability in the endpoint group (EPG) contract functionality of Cisco Nexus 9000 Series Fabric Switches in ACI Mode could allow an unauthenticated, remote attacker to bypass configured EPG contracts. This vulnerability is due to an improper control with EPG contracts. An attacker could exploit this vulnerability… | |
| Recibida | Media (4.4) | — | — | Cisco NX OSAICisco Nexus 3000AICisco Nexus 9000AICisco Application Policy Infrastructure ControllerAI+4 | 7/10/2026 | 7/10/2026 | A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, local attacker with low privileges to escape the Python sandbox and gain unauthorized access to the underlying operating system of an affected device. This vulnerability is due to insufficient validation of… | |
| Analizada | Alta (7.5) | 52% | 💥 Exploit | Cisco Smart License Utility | 4/9/2024 | 17/6/2026 | A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to excessive verbosity in a debug log file. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful… | |
| Analizada | Crítica (9.8) | 97% | ⚠ Explotación activa💥 Exploit | Cisco Smart License Utility | 4/9/2024 | 17/6/2026 | A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a static administrative credential. This vulnerability is due to an undocumented static user credential for an administrative account. An attacker could exploit this… |