Una señal es cualquier evento operacional detectado en las últimas 24h–30d: CVEs en KEV explotados activamente, advisories de vendor, exposición cloud, ransomware y avisos regulatorios. Cada señal se prioriza por severidad, freshness y match con tu Digital Twin.
Para análisis editorial y noticias generales visita Noticias.
Discover muestra 8 señales operativas recientes. Sube a Consultant Pro o Professional Studio para abrir el feed completo, histórico ampliado y el catálogo KEV.
Google’s analysis found that AI-discovered vulnerabilities are more likely to enable remote code execution. The post Google: AI Is Changing the Pace and Profile of Vulnerability Discovery appeared first on SecurityWeek. CVEs: CVE-2026-1731, CVE-2026-65660. CISA KEV/exploitation signal detected. Vendors: Microsoft, Google, Apple, Citrix, Linux, Mozilla, OpenSSL, WatchGuard. DORA relevance: medium.
Filtered for operational relevance. Powered by a curated catalog of vulnerability, CERT, vendor and threat-intelligence sources.View methodology →
8signals
Explotados & KEV
Vulns Críticas
Sin CVEs críticas frescas en la ventana actual.
Advisories de Vendor
Sin nuevos advisories PSIRT de vendor en la ventana.
Señal crítica con explotación indicada en CISA KEV y posible capacidad de ejecución remota de código, por lo que requiere priorización y triage el mismo día.
Acción recomendada
Verifica inmediatamente la exposición a CVE-2026-1731 y CVE-2026-65660, identifica los activos afectados y aplica las mitigaciones o parches disponibles fuera del ciclo mensual.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a new critical vulnerability in MikroTik RouterOS that could lead to remote code execution or cause a denial-of-service condition. [...] CVEs: CVE-2026-84411, CVE-2026-67276, CVE-2026-86060. CISA KEV/exploitation signal detected. Vendors: Microsoft, Cisco, Oracle, Adobe, Apple, Citrix, SonicWall, Atlassian, Linux, Zimbra, MikroTik, Cloudflare. DORA relevance: medium.
Por qué importa
CISA ha señalado vulnerabilidades críticas en MikroTik RouterOS con posible ejecución remota de código o denegación de servicio y explotación activa.
Acción recomendada
Identifica inmediatamente los activos MikroTik RouterOS afectados, aplica las actualizaciones disponibles, restringe la exposición y realiza una revisión de compromiso el mismo día.
Cybersecurity firms say attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day to deploy custom web shells and tunneling malware, gain root access, steal credentials, and spread into internal networks. [...] CVEs: CVE-2026-88772, CVE-2026-88771. CISA KEV/exploitation signal detected. Vendors: Microsoft, Google, Oracle, Apple, Citrix, Atlassian, Linux, PHP, Python, Cloudflare. DORA relevance: medium.
Por qué importa
Explotación activa de un zero-day en Citrix NetScaler que permite acceso root, robo de credenciales y movimiento lateral en la red interna.
Acción recomendada
Identificar y parchear inmediatamente todos los dispositivos Citrix NetScaler expuestos; buscar indicadores de compromiso (web shells) en los logs del sistema.
Vendors:CitrixSectores:public sectorcloud/SaaSMITRE:T1190 Exploit Public-Facing ApplicationT1505.003 Server Software Component: Web ShellT1078 Valid AccountsCISO · SecOps · Incident Response · Vulnerability Management
The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider WSO2. [...] CVEs: CVE-2026-5430, CVE-2026-71362, CVE-2026-65660, CVE-2026-67279. CISA KEV/exploitation signal detected. Vendors: Microsoft, Cisco, Oracle, Adobe, Atlassian, Linux, WordPress, Zimbra, MikroTik. DORA relevance: high.
Por qué importa
CISA informa de explotación activa de una vulnerabilidad crítica de bypass de autenticación en productos WSO2 y de otras vulnerabilidades en SharePoint y Adobe Commerce, con señal KEV y posible impacto operativo y regulatorio.
Acción recomendada
Comprueba inmediatamente la exposición de todos los CVE afectados, aplica los parches o mitigaciones oficiales fuera del ciclo mensual, revisa indicios de compromiso y escala el estado al CISO.
[CISA KEV actively exploited] Vendor: Linux | Product: Kernel | Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. | Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. | Due date: 2026-09-21 | Ransomware use: Unknown | Added: 2026-09-18 CVEs: CVE-2025-39682. CISA KEV/exploitation signal detected. Vendors: Linux. DORA relevance: medium.
Por qué importa
Explotación activa confirmada. Riesgo material para entornos expuestos.
Acción recomendada
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
[CISA KEV actively exploited] Vendor: Linux | Product: Kernel | Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state. | Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. | Due date: 2026-09-21 | Ransomware use: Unknown | Added: 2026-09-18 CVEs: CVE-2025-39964. CISA KEV/exploitation signal detected. Vendors: Linux. DORA relevance: medium.
Por qué importa
Explotación activa confirmada. Riesgo material para entornos expuestos.
Acción recomendada
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
[CISA KEV actively exploited] Vendor: Linux | Product: Kernel | Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. | Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. | Due date: 2026-09-21 | Ransomware use: Unknown | Added: 2026-09-18 CVEs: CVE-2026-53266. CISA KEV/exploitation signal detected. Vendors: Linux. DORA relevance: medium.
Por qué importa
Explotación activa confirmada. Riesgo material para entornos expuestos.
Acción recomendada
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
[CISA KEV actively exploited] Vendor: Linux | Product: Kernel | Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to Suse, Red Hat, and other products using Linux. | Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. | Due date: 2026-08-30 | Ransomware use: Unknown | Added: 2026-08-27 CVEs: CVE-2026-53362. CISA KEV/exploitation signal detected. Vendors: Linux. DORA relevance: medium.
Por qué importa
Explotación activa confirmada. Riesgo material para entornos expuestos.
Acción recomendada
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.