Una señal es cualquier evento operacional detectado en las últimas 24h–30d: CVEs en KEV explotados activamente, advisories de vendor, exposición cloud, ransomware y avisos regulatorios. Cada señal se prioriza por severidad, freshness y match con tu Digital Twin.
Para análisis editorial y noticias generales visita Noticias.
Discover muestra 8 señales operativas recientes. Sube a Consultant Pro o Professional Studio para abrir el feed completo, histórico ampliado y el catálogo KEV.
Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software. [...] CVEs: CVE-2026-92370, CVE-2026-19743, CVE-2026-92368, CVE-2026-92369, CVE-2026-92371. CISA KEV/exploitation signal detected. Vendors: Microsoft, Cisco, Oracle, Apple, Citrix, Atlassian, GitLab, ServiceNow, Zimbra, MikroTik, Cloudflare. DORA relevance: medium.
Filtered for operational relevance. Powered by a curated catalog of vulnerability, CERT, vendor and threat-intelligence sources.View methodology →
8signals
Explotados & KEV
Vulns Críticas
Sin CVEs críticas frescas en la ventana actual.
Advisories de Vendor
Sin nuevos advisories PSIRT de vendor en la ventana.
TeamViewer ha advertido de vulnerabilidades de severidad alta con señal de explotación y presencia en CISA KEV, por lo que los activos afectados requieren remediación inmediata.
Acción recomendada
Identifica inmediatamente las instalaciones afectadas de TeamViewer, aplica las actualizaciones disponibles sin esperar al ciclo mensual y valida la exposición o explotación de los activos vulnerables.
Citrix NetScaler ADC and NetScaler Gateway users should take their systems offline and patch them immediately, they were told over the weekend, as news emerged of two critical unauthenticated remote code execution zero-day vulnerabilities in the products under active attack. “Monday will be too late,” watchtower CEO Benjamin Harris wrote in a LinkedIn post on Sunday. Citrix subsequently confirmed the two remotely exploitable vulnerabilities were under attack, and released fixes for both. Affected customers should install the patched versions “as soon as possible,” Citrix wrote in an advisory issued later on Sunday. NetScaler appliances are an important part of many enterprise networks, providing VPN and remote access, load balancing and other application delivery services. Citrix is tracking the two exploited vulnerabilities as CVE-2026-88771 and CVE-2026-88772. It has released fixes in NetScaler ADC and Gateway 14.1-73.37 and later, 13.1-64.23 and later, with corresponding FIPS and NDcPP builds also available. CVE-2026-88771 is a critical remote code execution (RCE) vulnerability in Netscaler ADC and Netscaler Gateway caused by improper input validation. With a CVSS rating of 9.5, it enables unauthenticated attackers to execute arbitrary commands on the appliance. Citrix said all NetScaler ADC and NetScaler Gateway deployments are affected, including default configurations, with no additional feature required to meet the vulnerability’s precondition. It’s barely a month since Citrix patched two other critical security holes in the appliances CVE-2026-88772 also has a CVSS score of 9.5; it involves a memory overflow that can result in remote code execution or denial of service. It requires Datagram Transport Layer Security (DTLS) to be enabled, but Citrix notes that is the case by default on VPN virtual servers, making the condition relevant to many NetScaler Gateway deployments. Citrix said exploitation of both vulnerabilities had been observed on unmitigated deplo CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775. CISA KEV/exploitation signal detected. Vendors: Microsoft, Google, Citrix, GitLab, GitHub. DORA relevance: high.
Por qué importa
Dos vulnerabilidades críticas de ejecución remota de código en NetScaler ADC y Gateway están siendo explotadas activamente, afectan configuraciones predeterminadas y pueden comprometer infraestructura VPN y de acceso remoto expuesta a Internet.
Acción recomendada
Activa el procedimiento de emergencia, identifica inmediatamente los dispositivos NetScaler expuestos, aíslalos cuando sea posible, aplica las versiones corregidas 14.1-73.37 o posteriores y 13.1-64.23 o posteriores, y busca indicios de compromiso.
The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability. [...] CVEs: CVE-2026-42608. Vendors: Microsoft, Oracle, Adobe, SonicWall, Atlassian, GitLab, WordPress. DORA relevance: high.
Por qué importa
Una vulnerabilidad crítica de path traversal no autenticada fue explotada para comprometer y desfigurar el sitio de filtraciones de una banda de ransomware, lo que exige validar exposición y posibles compromisos de activos públicos.
Acción recomendada
Comprueba hoy la exposición a CVE-2026-42608, aplica la corrección o mitigación disponible, revisa indicadores de compromiso y escala el resultado al CISO.
[CISA KEV actively exploited] Vendor: GitLab | Product: Community Edition and Enterprise Edition | GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API. | Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. | Due date: 2026-09-14 | Ransomware use: Unknown | Added: 2026-09-11 CVEs: CVE-2026-85706. CISA KEV/exploitation signal detected. Vendors: GitLab. DORA relevance: medium.
Por qué importa
Explotación activa confirmada. Riesgo material para entornos expuestos.
Acción recomendada
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
On September 23, 2026, we released versions 19.0.9 and 18.11.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). These versions backport the fixes for two critical vulnerabilities, CVE-2026-85706 and CVE-2026-87719, that were originally patched in 19.3.2, 19.2.6, and 19.1.8 on September 10, 2026. These backports were made available outside of our standard maintenance policy so that self-managed administrators running 18.11 and 19.0 can apply the fixes without first completing a version upgrade. These versions contain no other changes. We strongly recommend that all self-managed GitLab installations still running 18.11 or 19.0 be upgraded to one of these versions immediately. Installations running 19.1, 19.2, or 19.3 should upgrade to 19.1.8, 19.2.6, or 19.3.2 or later instead. GitLab.com is already running the patched version. GitLab Dedicated customers do not need to take action. GitLab releases fixes for vulnerabilities in patch releases. There are two types of patch releases: scheduled releases and ad-hoc critical patches for high-severity vulnerabilities. Scheduled releases are released twice a month on the second and fourth Wednesdays. For more information, please visit our releases handbook and security FAQ. You can see all GitLab release blog posts. For security fixes, the issues detailing each vulnerability are made public on our issue tracker 90 days after the release in which they were patched. We are committed to ensuring that all aspects of GitLab that are exposed to customers or that host customer data are held to the highest security standards. To maintain good security hygiene, it is highly recommended that all customers upgrade to the latest patch release for their supported version. You can read more best practices in securing your GitLab instance in our blog post. Recommended Action We strongly recommend that all installations running a version affected by the issues described below are upgraded to the latest version as soon as possib CVEs: CVE-2026-85706, CVE-2026-87719. CISA KEV/exploitation signal detected. Vendors: GitLab. DORA relevance: medium.
Por qué importa
GitLab identifica dos vulnerabilidades críticas con señal de explotación y recomienda actualizar inmediatamente las instalaciones self-managed afectadas.
Acción recomendada
Identifica las instancias afectadas y actualízalas inmediatamente a GitLab 18.11.12, 19.0.9, 19.1.8, 19.2.6, 19.3.2 o posteriores según la rama instalada.
La vulnerabilidad crítica con señal de explotación puede comprometer la seguridad de los datos personales alojados en GitLab y exige aplicar medidas técnicas y organizativas adecuadas, incluida la corrección inmediata.
[CISA KEV actively exploited] Vendor: GitLab | Product: GitLab | GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the internal network for webhooks are enabled. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Due date: 2026-03-11 | Ransomware use: Unknown | Added: 2026-02-18 CVEs: CVE-2021-22175. CISA KEV/exploitation signal detected. Vendors: GitLab. DORA relevance: medium.
Por qué importa
Explotación activa confirmada. Riesgo material para entornos expuestos.
Acción recomendada
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
[CISA KEV actively exploited] Vendor: GitLab | Product: Community and Enterprise Editions | GitLab Community and Enterprise Editions contain a server-side request forgery vulnerability which could allow unauthorized external users to perform Server Side Requests via the CI Lint API. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Due date: 2026-02-24 | Ransomware use: Unknown | Added: 2026-02-03 CVEs: CVE-2021-39935. CISA KEV/exploitation signal detected. Vendors: GitLab. DORA relevance: medium.
Por qué importa
Explotación activa confirmada. Riesgo material para entornos expuestos.
Acción recomendada
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
HTML source discovery from thehackernews.com CVEs: CVE-2026-104286, CVE-2026-85102, CVE-2026-93616, CVE-2026-93952, CVE-2026-94127. CISA KEV/exploitation signal detected. Vendors: Microsoft, Cisco, Google, Fortinet, Citrix, F5, Zyxel, GitLab, Linux, WordPress, Veeam, MikroTik, Cloudflare, Check Point. DORA relevance: medium.
Por qué importa
La vulnerabilidad CVE-2026-104286 en FortiMail está siendo explotada activamente in-the-wild y ha sido incluida en el catálogo KEV de CISA, permitiendo ejecución de escritura de archivos no autenticada.
Acción recomendada
Identificar y parchear inmediatamente los dispositivos FortiMail afectados; no esperar al ciclo de mantenimiento regular y realizar triage de seguridad hoy mismo.