Skip to content
LEARN

Recursos de Aprendizaje

Expande tu conocimiento con nuestro contenido curado.

Vulnerabilidades (CVE)

Vulnerabilidades activamente explotadas o de severidad máxima.

Activamente explotadaCVSS 10.0EPSS 0.43

CVE-2026-21962Compromiso remoto en Oracle HTTP Server y WebLogic Proxy

oracle:http_serveroracle:weblogic_server_proxy_plug-in
BackendciberseguridadCloudJavaLinuxWindows

Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data as well as unauthori…

Análisis

Oracle HTTP Server y el plug-in de proxy para WebLogic presentan una falla crítica de control de acceso que permite a atacantes no autenticados comprometer el servidor y manipular datos de forma remota. Esta vulnerabilidad está siendo explotada activamente en entornos que utilizan Apache o IIS como front-end para servidores WebLogic. Es vital actualizar las instalaciones de Fusion Middleware para evitar el acceso no autorizado a sistemas internos y bases de datos conectadas.

Agregada al KEV: 2026-08-24Ver detalle
Activamente explotadaCVSS 8.9

CVE-2026-73570RCE por inyección de comandos en Zimbra Collaboration

synacor:zimbra_collaboration_suite
BackendciberseguridadCloudLinux

Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating sy…

Análisis

Zimbra Collaboration Suite es vulnerable a la ejecución remota de comandos (RCE) sin autenticación debido a una sanitización insuficiente en las notificaciones SNMP. Los atacantes pueden ejecutar código arbitrario en el servidor mediante peticiones SMTP especialmente diseñadas. Esta vulnerabilidad está confirmada como activamente explotada en ataques reales.

Agregada al KEV: 2026-08-21Ver detalle
Activamente explotadaCVSS 9.0

CVE-2026-72530RCE sin autenticación en TrueConf Server

trueconf:trueconf_server
CyberSecurityBackendWindowsLinuxDocker

TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment an…

Análisis

TrueConf Server is vulnerable to unauthenticated remote code execution (RCE). An attacker can escape the isolated environment via port 4307/TCP and execute arbitrary code on the underlying host system.

Agregada al KEV: 2026-08-20Ver detalle
Activamente explotadaCVSS 9.8

CVE-2026-72529RCE sin autenticación en TrueConf Server

trueconf:trueconf_server
BackendCyberSecurityWindowsLinuxCloud

TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script.

Análisis

TrueConf Server versions up to 5.5.5 are vulnerable to unauthenticated remote script execution via port 4307/TCP. An attacker can execute arbitrary commands by calling an undocumented function without valid credentials.

Agregada al KEV: 2026-08-20Ver detalle
Activamente explotadaCVSS 9.3EPSS 0.16

CVE-2026-64849SSRF sin autenticación en MLflow

lfprojects:mlflow
PythonIADataScienceMachineLearningCloudBackend

MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body.

Análisis

MLflow is vulnerable to an unauthenticated Server-Side Request Forgery (SSRF) via its webhook testing endpoint. Attackers can exploit this to reach internal services or cloud metadata endpoints (IMDS) and view response bodies, potentially leading to credential theft.

Agregada al KEV: 2026-08-19Ver detalle
Activamente explotadaCVSS 9.8EPSS 0.10

CVE-2026-65400Bypass de autenticación en Apple Screen Sharing para macOS

apple:macos
MacosCyberSecurity

Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.

Análisis

A critical authentication bypass in macOS Screen Sharing allows an attacker on the same network to gain control of a machine without valid credentials. Users should update to macOS Sequoia 15.7.9, Sonoma 14.8.9, or Tahoe 26.6.1 immediately.

Agregada al KEV: 2026-08-18Ver detalle

Documentos

Talleres, presentaciones y demos.

Taller

DNS

Pasos para controlar tu propio dns

Ver Presentación

Cursos

Libros de curso completos y cursos externos recomendados.

InicioEventosBlogRecursos
CursosEquipo