Una señal es cualquier evento operacional detectado en las últimas 24h–30d: CVEs en KEV explotados activamente, advisories de vendor, exposición cloud, ransomware y avisos regulatorios. Cada señal se prioriza por severidad, freshness y match con tu Digital Twin.
Para análisis editorial y noticias generales visita Noticias.
Discover muestra 8 señales operativas recientes. Sube a Consultant Pro o Professional Pro para abrir el feed completo, histórico ampliado y el catálogo KEV.
The Netherlands' National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged. [...] CVEs: CVE-2026-65400. CISA KEV/exploitation signal detected. Vendors: Microsoft, Palo Alto Networks, Google, SAP, Adobe, Apple, Docker, Check Point. DORA relevance: medium.
Por qué importa
Filtered for operational relevance. Powered by a curated catalog of vulnerability, CERT, vendor and threat-intelligence sources.View methodology →
Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data. [...] CVEs: CVE-2026-12569. CISA KEV/exploitation signal detected. Vendors: Microsoft, SAP, Adobe, Salesforce, ServiceNow. DORA relevance: medium.
Por qué importa
Explotación activa confirmada. Riesgo material para entornos expuestos.
Acción recomendada
Comprueba la exposición a CVE-2026-12569 en el inventario de activos y las herramientas de vulnerabilidades.
A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat intelligence company Defused. [...] CVEs: CVE-2026-58231, CVE-2026-44761, CVE-2026-22732, CVE-2026-34263. CISA KEV/exploitation signal detected. Vendors: Microsoft, Cisco, VMware, SAP, Adobe, Node.js. DORA relevance: medium.
Por qué importa
Explotación activa confirmada. Riesgo material para entornos expuestos.
Acción recomendada
Comprueba la exposición a CVE-2026-58231, CVE-2026-44761, CVE-2026-22732 en el inventario de activos y las herramientas de vulnerabilidades.
Cybersecurity teams should be responsible for risk oversight, rather than for executing every corrective action. Assigning security teams the tasks of finding, prioritizing, assigning, implementing, tracking and validating every remediation does not foster accountability. Instead, it results in an organizational repository for unresolved issues. A more effective model distinguishes roles clearly: security functions as the overseer, while technology and business operations execute remediation. Security should maintain the authoritative risk inventory, determine priorities, establish remediation standards, escalate missed commitments and verify closure. Owners of the affected infrastructure, cloud environment, application, identity platform or business process are responsible for implementing fixes. Executives are tasked with resolving resource conflicts and explicitly accepting risks that the organization elects not to remediate. This distinction is substantive, as it determines whether a vulnerability management program effectively reduces risk or simply generates remediation tickets. An increasing backlog indicates a failure in the operating model Security teams often become the default owners of any issue labeled as a security concern. For example, when a scanner identifies an outdated package, security is expected to patch the server. If a cloud security platform detects an exposed storage bucket, security is tasked with redesigning the deployment. Similarly, when an audit reveals excessive privileges in a business application, security is expected to negotiate access changes with the department responsible for the workflow. This dynamic arises because discovery is highly visible, while remediation is often inconvenient. When the security team produces a report, the organization may assume that the team is also responsible for implementing the solutions. Over time, infrastructure, engineering and business owners come to expect that security will initiate tickets, CISA KEV/exploitation signal detected. Vendors: Microsoft. DORA relevance: high.
Por qué importa
Explotación activa confirmada. Riesgo material para entornos expuestos.
Acción recomendada
Prioriza la remediación por explotación in-the-wild; no esperes al ciclo mensual de parcheo.
View CSAF Summary Hitachi Energy is aware of Dirty Frag vulnerabilities that affect APM Edge product versions listed in this document. Successful exploitation of these vulnerabilities could result in impact on confidentiality, integrity and availability of the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. The following versions of Hitachi Energy APM Edge Product are affected: APM Edge vers:APM_Edge/<=6.10 (CVE-2026-43284, CVE-2026-43500) CVSS Vendor Equipment Vulnerabilities v3 8.8 Hitachi Energy Hitachi Energy APM Edge Product Write-what-where Condition, Out-of-bounds Write Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2026-43284 CWE-123: Write-what-where Condition A vulnerability exists in the IPsec ESP subsystem (esp4, esp6) of the Linux kernel used in APM Edge that allows a local unprivileged user to escalate privileges to root. The flaw exists in how the kernel handles memory pages when processing ESP encrypted network packets. An attacker can craft a packet that causes the kernel to decrypt data directly into memory pages it does not own, including the cached copies of privileged operating system binaries. When one of those binaries is executed, the attacker's injected code runs with root privileges. In APM Edge, the vulnerable kernel modules (esp4, esp6) can be loaded by any local user and exploited. View CVE Details Affected Products Hitachi Energy APM Edge Product Vendor: Hitachi Energy Product Version: APM Edge versions 6.10 and prior Product Status: known_affected Remediations Mitigation Disable the esp4 and esp6 modules [2] Relevant CWE: CWE-123 Write-what-where Condition Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVE-2026-43500 CWE-787: Out-of-bounds Write A vulnerability exists in the RxRPC protocol im CVEs: CVE-2026-43284, CVE-2026-43500. CISA KEV/exploitation signal detected. Vendors: Hitachi Energy Product Version: APM Edge versions 6, GitHub, Linux, Siemens. DORA relevance: medium.
Por qué importa
Explotación activa confirmada. Riesgo material para entornos expuestos.
Acción recomendada
Comprueba la exposición a CVE-2026-43284, CVE-2026-43500 en el inventario de activos y las herramientas de vulnerabilidades.
View CSAF Summary Simcenter Femap contains two file parsing vulnerabilities that could be triggered when the application reads files in BMP file format. If a user is tricked to open a malicious file with the affected application, this could lead the application to crash or potentially lead to arbitrary code execution. Siemens has released a new version for Simcenter Femap and recommends to update to the latest version. The following versions of Siemens Simcenter Femap are affected: Simcenter Femap vers:intdot/<2606.0001 (CVE-2026-59700, CVE-2026-59701) CVSS Vendor Equipment Vulnerabilities v3 7.8 Siemens Siemens Simcenter Femap Out-of-bounds Read Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-59700 The affected applications contains an out of bounds read vulnerability while parsing specially crafted BMP files. This could allow an attacker to execute code in the context of the current process. View CVE Details Affected Products Siemens Simcenter Femap Vendor: Siemens Product Version: Simcenter Femap < V2606.0001 Product Status: known_affected Remediations Vendor fix Update to V2606.0001 or later version https://support.sw.siemens.com/product/275652363/ Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2026-59701 The affected applications contains an out of bounds read vulnerability while parsing specially crafted BMP files. This could allow an attacker to execute code in the context of the current process. View CVE Details Affected Products Siemens Simcenter Femap Vendor: Siemens Product Version: Simcenter Femap < V2606.0001 Product Status: known_affected Remediations Vendor fix Update to V2606.0001 or later version https://support.sw.siemens.com/product/275652363/ Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version CVEs: CVE-2026-59700, CVE-2026-59701. CISA KEV/exploitation signal detected. Vendors: Siemens Product Version: Simcenter Femap < V2606, GitHub, Siemens. DORA relevance: medium.
Por qué importa
Explotación activa confirmada. Riesgo material para entornos expuestos.
Acción recomendada
Comprueba la exposición a CVE-2026-59700, CVE-2026-59701 en el inventario de activos y las herramientas de vulnerabilidades.
View CSAF Summary Successful exploitation of this vulnerability may allow an attacker to inject and execute arbitrary OS commands with root privileges. The following versions of Haiwell IoT Cloud HMI Gateway are affected: Haiwell IoT Cloud HMI Gateway 3.40.1.12 (CVE-2026-19188) CVSS Vendor Equipment Vulnerabilities v3 10 Haiwell Haiwell IoT Cloud HMI Gateway Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Background Critical Infrastructure Sectors: Energy, Critical Manufacturing, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: China Vulnerabilities Expand All + CVE-2026-19188 A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails to properly sanitize user-supplied input before passing it to the underlying operating system, allowing an attacker to inject and execute arbitrary OS commands with root privileges View CVE Details Affected Products Haiwell IoT Cloud HMI Gateway Vendor: Haiwell Product Version: Haiwell Haiwell IoT Cloud HMI Gateway: 3.40.1.12 Product Status: known_affected Remediations Mitigation Haiwell has addressed the issue in patch version number Scada-v3.50.1.19, which is available for download on their website: https://en.haiwell.com/app/system/entrance.php?m=include&c=access&a=dodown&lang=en&id=361 https://en.haiwell.com/app/system/entrance.php?m=include&c=access&a=dodown&lang=en&id=361 Relevant CWE: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 10 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H 4.0 10 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H Acknowledgments Fiqram Akmal reported this vulnerability to CISA Legal Notice and Terms of Use This CVEs: CVE-2026-19188. CISA KEV/exploitation signal detected. Vendors: Haiwell Product Version: Haiwell Haiwell IoT Cloud HMI Gateway: 3, GitHub, Siemens, PHP. DORA relevance: medium.
Por qué importa
Explotación activa confirmada. Riesgo material para entornos expuestos.
Acción recomendada
Comprueba la exposición a CVE-2026-19188 en el inventario de activos y las herramientas de vulnerabilidades.
View CSAF Summary Siveillance Video Management Servers contains a vulnerability that could allow a Remote Code Execution attack. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Siveillance Video are affected: Siveillance Video V2023 R3 vers:intdot/<23.3.27 (CVE-2026-3014) Siveillance Video V2024 R1 vers:intdot/<24.1.16 (CVE-2026-3014) Siveillance Video V2025 vers:intdot/<25.1.15 (CVE-2026-3014) CVSS Vendor Equipment Vulnerabilities v3 9.1 Siemens Siemens Siveillance Video Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Background Critical Infrastructure Sectors: Critical Manufacturing, Communications, Commercial Facilities Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-3014 Milestone has released a new version of XProtect® (and several cumulative patch updates) which fix security vulnerability in Management Server API. The vulnerability causes users with edit permissions to the Management Server to be able to execute arbitrary code in context of the Management Server Service. View CVE Details Affected Products Siemens Siveillance Video Vendor: Siemens Product Version: Siveillance Video V2023 R3 < V23.3.27, Siveillance Video V2024 R1 < V24.1.16, Siveillance Video V2025 < V25.1.15 Product Status: known_affected Remediations Vendor fix Update to V23.3 HotfixRev27 or later version https://support.industry.siemens.com/cs/ww/en/view/109827783/ Vendor fix Update to V24.1 HotfixRev16 or later version https://support.industry.siemens.com/cs/ww/en/view/109976123/ Vendor fix Update to V25.1 HotfixRev15 or later version https://support.industry.siemens.com/cs/ww/en/view/109988670/ Relevant CWE: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.1 CRITICAL CVSS:3.1/AV CVEs: CVE-2026-3014. CISA KEV/exploitation signal detected. Vendors: Siemens Product Version: Siveillance Video V2023 R3 < V23, GitHub, Siemens. DORA relevance: medium.
Por qué importa
Explotación activa confirmada. Riesgo material para entornos expuestos.
Acción recomendada
Comprueba la exposición a CVE-2026-3014 en el inventario de activos y las herramientas de vulnerabilidades.