Bolsa Ética
Radar de amenazas · ETECHAL

Lo que se está explotando ahora mismo

Vulnerabilidades con explotación activa confirmada (catálogo CISA KEV) · actualizado 25 Jun 2026
Vulnerabilidades activas
1,629
Usadas en ransomware
327
Añadidas (este mes)
22

Nuevas amenazas catalogadas por mes

CVEFabricante / productoVulnerabilidadDetectada
CVE-2026-12569 PTC
Windchill and FlexPLM
PTC Windchill and FlexPLM Improper Input Validation Vulnerability 2026-06-25
CVE-2026-20230 Cisco
Unified Communications Manager
Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability 2026-06-25
CVE-2025-67038 Lantronix
EDS5000
Lantronix EDS5000 Code Injection Vulnerability 2026-06-23
CVE-2026-34910 Ubiquiti
UniFi OS
Ubiquiti UniFi OS Improper Input Validation Vulnerability 2026-06-23
CVE-2026-34909 Ubiquiti
UniFi OS
Ubiquiti UniFi OS Path Traversal Vulnerability 2026-06-23
CVE-2026-34908 Ubiquiti
UniFi OS
Ubiquiti UniFi OS Improper Access Control Vulnerability 2026-06-23
CVE-2026-20253 Splunk
Enterprise
Splunk Enterprise Missing Authentication for Critical Function Vulnerability 2026-06-18
CVE-2026-48907 Widget Factory
Joomla Content Editor
Widget Factory Joomla Content Editor Improper Access Control Vulnerability 2026-06-16
CVE-2026-54420 LiteSpeed
cPanel Plugin
LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability 2026-06-15
CVE-2026-20262 Cisco
Catalyst SD-WAN Manager
Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability 2026-06-15
CVE-2026-35273
Ransomware
Oracle
PeopleSoft Enterprise PeopleTools
Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability 2026-06-12
CVE-2026-10520 Ivanti
Sentry
Ivanti Sentry OS Command Injection Vulnerability 2026-06-11
CVE-2026-11645 Google
Chromium V8
Google Chromium V8 Out-of-Bounds Read and Write Vulnerability 2026-06-09
CVE-2026-7473 Arista
Extensible Operating System
Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability 2026-06-09
CVE-2026-20245 Cisco
Catalyst SD-WAN Manager
Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability 2026-06-09
CVE-2026-42271 BerriAI
LiteLLM
BerriAI LiteLLM Command Injection Vulnerability 2026-06-08
CVE-2026-50751
Ransomware
Check Point
Security Gateway
Check Point Security Gateway Improper Authentication Vulnerability 2026-06-08
CVE-2026-28318 SolarWinds
Serv-U
SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability 2026-06-05
CVE-2026-45247 Mirasvit
Mirasvit Full Page Cache Warmer
Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability 2026-06-03
CVE-2022-0492 Linux
Kernel
Linux Kernel Improper Authentication Vulnerability 2026-06-02
CVE-2025-48595 Android
Framework
Android Framework Integer Overflow Vulnerability 2026-06-02
CVE-2024-21182 Oracle
WebLogic Server
Oracle WebLogic Server Unspecified Vulnerability 2026-06-01
CVE-2026-0257 Palo Alto Networks
PAN-OS
Palo Alto Networks PAN-OS Authentication Bypass Vulnerability 2026-05-29
CVE-2026-48027
Ransomware
Nx
Nx Console
Nx Console Embedded Malicious Code Vulnerability 2026-05-27
CVE-2026-45321
Ransomware
TanStack
TanStack
TanStack Unspecified Vulnerability 2026-05-27
CVE-2026-8398 Daemon
Daemon Tools Lite
Daemon Tools Lite Embedded Malicious Code Vulnerability 2026-05-27
CVE-2026-48172 LiteSpeed
cPanel Plugin
LiteSpeed cPanel Plugin Privilege Escalation Vulnerability 2026-05-26
CVE-2026-9082 Drupal
Core
Drupal Core SQL Injection Vulnerability 2026-05-22
CVE-2025-34291 Langflow
Langflow
Langflow Origin Validation Error Vulnerability 2026-05-21
CVE-2026-34926 Trend Micro
Apex One
Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability 2026-05-21
CVE-2008-4250 Microsoft
Windows
Microsoft Windows Buffer Overflow Vulnerability 2026-05-20
CVE-2009-1537 Microsoft
DirectX
Microsoft DirectX NULL Byte Overwrite Vulnerability 2026-05-20
CVE-2009-3459 Adobe
Acrobat and Reader
Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability 2026-05-20
CVE-2010-0249 Microsoft
Internet Explorer
Microsoft Internet Explorer Use-After-Free Vulnerability 2026-05-20
CVE-2010-0806 Microsoft
Internet Explorer
Microsoft Internet Explorer Use-After-Free Vulnerability 2026-05-20
CVE-2026-41091 Microsoft
Defender
Microsoft Defender Link Following Vulnerability 2026-05-20
CVE-2026-45498 Microsoft
Defender
Microsoft Defender Denial of Service Vulnerability 2026-05-20
CVE-2026-42897 Microsoft
Microsoft
Microsoft Exchange Server Cross-Site Scripting Vulnerability 2026-05-15
CVE-2026-20182 Cisco
Catalyst SD-WAN
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability 2026-05-14
CVE-2026-42208 BerriAI
LiteLLM
BerriAI LiteLLM SQL Injection Vulnerability 2026-05-08

Fuente: CISA Known Exploited Vulnerabilities Catalog (dominio público). Cada CVE enlaza a su ficha en NVD.

PORTADA DEL DÍA