| CVE-2026-82232 |
Apache Software Foundation |
Apache Syncope |
CRITICAL (9.8) |
3.0.0-M0 hasta 3.0.16, 4.0.0-M0 hasta 4.0.7, 4.1.0-M0 hasta 4.1.2 |
Sí |
| CVE-2026-86460 |
Apache Software Foundation |
Apache Syncope |
CRÍTICA (9.8) |
3.0.0-M0 a 3.0.16, 4.0.0-M0 a 4.0.7, 4.1.0-M0 a 4.1.2 |
Sí |
| CVE-2026-87785 |
Apache Software Foundation |
Apache Syncope |
CRITICAL (9.1) |
3.0.0-M0 a 3.0.16, 4.0.0-M0 a 4.0.7, 4.1.0-M0 a 4.1.2 |
Sí |
| CVE-2026-87802 |
Apache Software Foundation |
AfectadoApache Syncope |
CRÍTICA (9.1) |
3.0.0-M0 a 3.0.16, 4.0.0-M0 a 4.0.7, 4.1.0-M0 a 4.1.2 |
Sí |
| CVE-2026-90898 |
maximhq |
Bifrost |
CRITICAL (9.8) |
transports |
Sí |
| CVE-2026-21391 |
Ping Identity |
PingAM |
CRITICAL (9.5) |
No especificadas; afecta configuraciones específicas del producto |
Sí |
| CVE-2026-90919 |
LightLLM |
LightLLM Config Server |
CRITICAL (9.3) |
versiones hasta 1.2.0 incluidas |
Sí |
| CVE-2026-12258 |
Hiperdino |
REST API v1.0 |
CRITICAL (9.2) |
REST v1.0 |
Sí |
| CVE-2026-73470 |
Apache Software Foundation |
Apache Syncope |
CRITICAL (9.8) |
Desde 3.0.0-M0 a 3.0.16, 4.0.0-M0 a 4.0.7 y 4.1.0-M0 a 4.1.2 |
Sí |
| CVE-2026-73579 |
Apache Software Foundation |
Apache Syncope |
CRÍTICA (9.8) |
3.0.0-M0 a 3.0.16, 4.0.0-M0 a 4.0.7, 4.1.0-M0 a 4.1.2 |
Sí |
| CVE-2026-73668 |
Apache Software Foundation |
Apache Syncope |
CRÍTICA (9.8) |
3.0.0-M0 a 3.0.16, 4.0.0-M0 a 4.0.7, 4.1.0-M0 a 4.1.2 |
Sí |
| CVE-2026-75030 |
Apache Software Foundation |
Apache Syncope |
CRÍTICA (9.8) |
3.0.0-M0 a 3.0.16, 4.0.0-M0 a 4.0.7, 4.1.0-M0 a 4.1.2 |
Sí |
| CVE-2026-77051 |
Apache |
Apache Syncope |
CRÍTICO (9.8) |
de 3.0.0-M0 a 3.0.16, de 4.0.0-M0 a 4.0.7, de 4.1.0-M0 a 4.1.2 |
Sí |
| CVE-2026-77181 |
Apache Software Foundation |
Apache Syncope |
CRITICAL (9.8) |
3.0.0-M0 a 3.0.16, 4.0.0-M0 a 4.0.7, 4.1.0-M0 a 4.1.2 |
Sí |
| CVE-2026-78299 |
Eclipse Foundation |
Eclipse Embedded CDT |
CRÍTICA (9.1) |
6.0 a 6.7 |
Sí |
| CVE-2026-78330 |
Apache |
Apache Syncope |
CRÍTICO (9.8) |
3.0.0-M0 a 3.0.16, 4.0.0-M0 a 4.0.7, 4.1.0-M0 a 4.1.2 |
Sí |
| CVE-2026-90937 |
Froxlor |
Froxlor |
CRITICAL (9.4) |
anteriores a 2.2.5 |
Sí |
| CVE-2026-73370 |
Apache Software Foundation |
Apache Syncope |
CRÍTICA (9.8) |
3.0.0-M0 hasta 3.0.16, 4.0.0-M0 hasta 4.0.7, 4.1.0-M0 hasta 4.1.2 |
Sí |
| CVE-2026-82439 |
Apache Software Foundation (ASF) |
Apache Storm DRPC server |
CRITICAL (9.8) |
Versiones anteriores a 3.1.0 |
Sí |
| CVE-2026-82441 |
Apache |
Apache Storm – Nimbus |
CRÍTICA (9.1) |
Versiones anteriores a 3.1.0 |
Sí |
| CVE-2026-90961 |
MISP Project |
MISP (plugins LdapAuth y LinOTPAuth) |
CRÍTICA (9.3) |
Versiones iguales o anteriores a 2.5.45 |
Sí |
| CVE-2026-57123 |
PraisonAI |
PraisonAI multi-agent teams system |
CRITICAL (9.8) |
Anteriores a la versión 1.6.59 |
Sí |
| CVE-2026-57125 |
PraisonAI |
AfectadoPraisonAI multi-agent teams system |
CRÍTICA (9.8) |
versiones anteriores a 4.6.59 y praisonaiagents anteriores a 1.6.59 |
Sí |
| CVE-2026-82431 |
Apache Software Foundation |
Apache Storm (componente Nimbus) |
CRÍTICA (9.8) |
Versiones anteriores a 3.1.0 |
Sí |
| CVE-2026-82434 |
Apache Software Foundation |
Apache Storm |
CRÍTICA (10.0) |
versiones anteriores a 3.1.0 |
Sí |
| CVE-2026-82435 |
Apache Software Foundation |
Apache Storm |
CRÍTICA (9.8) |
anteriores a la versión 3.1.0 |
Sí |
| CVE-2026-57124 |
PraisonAI |
PraisonAI UI host applications |
CRITICAL (9.8) |
versiones anteriores a 4.6.59 |
Sí |
| CVE-2026-57127 |
PraisonAI |
PraisonAI Multi-agent Teams System |
CRITICAL (9.8) |
versiones anteriores a 4.6.58 |
Sí |
| CVE-2026-57131 |
PraisonAI |
PraisonAI multi-agent teams system |
CRÍTICA (9.8) |
versiones anteriores a 4.6.58 |
Sí |
| CVE-2026-57145 |
PraisonAI |
PraisonAI multi-agent teams system |
CRÍTICA (9.1) |
versiones anteriores a 4.6.62 |
Sí |
| CVE-2026-61534 |
Confetti |
Yayson (librería JavaScript para serialización y lectura de datos JSON API) |
CRÍTICA (9.1) |
versiones anteriores a 4.3.0 |
Sí |
| CVE-2026-90943 |
parallax |
filament-comments |
CRÍTICA (9.3) |
hasta la 3.0.0 incluida |
Sí |
| CVE-2026-20353 |
Cisco |
Cisco Secure Email Gateway y Cisco Secure Email and Web Manager |
CRITICAL (9.8) |
No especificadas concretamente, afecta a versiones previas a los parches publicados en septiembre 2026 |
Sí |
| CVE-2026-76440 |
Cisco |
Cisco Secure Email Gateway y Cisco Secure Email and Web Manager |
CRITICAL (9.8) |
Versiones anteriores a las actualizaciones de endurecimiento publicadas en septiembre de 2026 |
Sí |
| CVE-2026-76441 |
Cisco |
Cisco Secure Email Gateway y Cisco Secure Email and Web Manager |
CRÍTICO (9.8) |
Versiones previas a los lanzamientos de endurecimiento publicados en septiembre 2026 |
Sí |
| CVE-2026-76443 |
Cisco |
Cisco Secure Email Gateway y Cisco Secure Email and Web Manager |
CRÍTICA (9.8) |
Versiones afectadas no especificadas, se recomienda aplicar releases con hardening publicados |
Sí |
| CVE-2026-76461 |
Cisco |
Cisco AsyncOS Software para Cisco Secure Email Gateway |
CRITICAL (9.8) |
Versiones afectadas no especificadas (vulnerabilidad en la lógica de análisis de correo) |
Sí |
| CVE-2026-57578 |
DotVVM |
DotVVM MVVM Framework |
CRÍTICA (9.2) |
anteriores a 4.2.11, 4.3.15 y 5.0.0-preview09-final |
Sí |
| CVE-2026-90942 |
Casdoor |
Casdoor |
CRITICAL (9.3) |
Versiones hasta 4.4.0 incluidas |
Sí |
| CVE-2026-90945 |
Crawlab Team |
Crawlab |
CRITICAL (9.3) |
versiones hasta la 0.6.3 incluidas |
Sí |
| CVE-2026-59178 |
ESPHome |
ESPHome Device Builder Dashboard |
CRITICAL (9.8) |
versiones anteriores a 1.0.12 |
Sí |
| CVE-2026-16338 |
IBM |
IBM DataStage on Cloud Pak for Data 5.4.0.0 |
CRITICAL (9.9) |
Versión 5.4.0.0 |
Sí |
| CVE-2026-50006 |
Anyquery |
Anyquery SQL Engine |
CRÍTICA (9.1) |
Versiones previas a 0.4.5 |
Sí |
| CVE-2026-54333 |
Proyecto UEFI Firmware Parser (comunitario) |
UEFI Firmware Parser |
CRITICAL (9.8) |
Versiones anteriores a 1.14 |
Sí |
| CVE-2026-54334 |
UEFI Firmware Parser |
UEFI Firmware Parser |
CRÍTICA (9.8) |
versiones anteriores a 1.14 |
Sí |
| CVE-2026-55209 |
Equinor |
resdata (software para archivos de resultados del simulador de depósitos Eclipse) |
CRITICAL (9.8) |
anteriores a la 6.2.9 |
Sí |
| CVE-2026-53713 |
Envoy Gateway Project |
Envoy Gateway |
CRÍTICO (9.1) |
Versiones anteriores a 1.7.4 y 1.8.1 |
Sí |
| CVE-2026-65414 |
Apple Inc. |
iOS, iPadOS, macOS, tvOS, visionOS, watchOS |
CRITICAL (9.8) |
iOS 26.7 y superior, iPadOS 26.7 y superior, macOS Golden Gate 27, Sequoia 15.8, Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27 |
Sí |
| CVE-2026-67399 |
WHMCS |
WHMCS |
CRÍTICA (9.3) |
versiones 8.0.0 a antes de 8.13.7 y 9.0.0 a antes de 9.0.8 |
Sí |
| CVE-2026-12944 |
IBM |
Langflow OSS |
CRÍTICA (9.6) |
1.0.0 hasta 1.10.0 |
Sí |