Una señal es cualquier evento operacional detectado en las últimas 24h–30d: CVEs en KEV explotados activamente, advisories de vendor, exposición cloud, ransomware y avisos regulatorios. Cada señal se prioriza por severidad, freshness y match con tu Digital Twin.
Para análisis editorial y noticias generales visita Noticias.
Discover muestra 8 señales operativas recientes. Sube a Consultant Pro o Professional Pro para abrir el feed completo, histórico ampliado y el catálogo KEV.
The security defect is described as an SQL injection that could allow attackers to achieve remote code execution. The post Hackers Exploiting Unpatched GeoServer Zero-Day appeared first on SecurityWeek. CISA KEV/exploitation signal detected. Vendors: Microsoft, Fortinet, VMware, Oracle, Adobe, Apple, Ivanti, SonicWall, WordPress. DORA relevance: medium.
Por qué importa
Explotación activa confirmada. Riesgo material para entornos expuestos.
Filtered for operational relevance. Powered by a curated catalog of vulnerability, CERT, vendor and threat-intelligence sources.View methodology →
3signals
Explotados & KEV
Vulns Críticas
Sin CVEs críticas frescas en la ventana actual.
Advisories de Vendor
Sin nuevos advisories PSIRT de vendor en la ventana.
A currently exploited zero-day elevation of privilege vulnerability that needs to be patched in a Windows driver for WinSock is the highlight of the 398 fixes issued today in Microsoft’s August Patch Tuesday releases. The hole is in Windows’ Ancillary Function Driver for WinSock (CVE-2026-68820), which, according to Todd Schell, principal product manager at Ivanti, has been a recurring target for local privilege-escalation bugs throughout 2026. Past vulnerabilities in this component have let an authorized attacker win a race condition to gain SYSTEM privileges. “Exploitation has already been detected,” noted Jack Bicer, director of vulnerability research at Action1, “making this the highest priority vulnerability in this month’s release.” Separately, SAP issued 29 new and updated security patches, the most severe of which is CVE-2026-58231, with a CVSS score of 10. This is an improper authorization issue in SAP Commerce Cloud’s Data Hub Adapter. 42 critical Microsoft vulnerabilities In total, Microsoft addressed 398 CVEs. Of them, 42 were rated critical, while 355 were rated Important. However, Tyler Reguly, associate director of security R&D at Fortra, noted that 236 CVEs affect Windows and are covered by a cumulative update. Another 98 are Office CVEs that are covered by separate Office cumulative updates, unless you happen to still run Office 2016 In addition to the actively exploited zero-day, Microsoft also warned of two other zero-days. CVE-2026-62832 is an elevation of privilege vulnerability in the Windows User Profile Service, rated Important. Action1 pointed out this has been publicly disclosed, so exploitation is likely; Ivanti noted that it is the flaw behind “LegacyHive,” the unpatched proof-of-concept released by researcher Nightmare-Eclipse just hours after July’s Patch Tuesday. This vulnerability lets a standard user coerce the User Profile Service into loading another user’s registry hive, even an administrator’s, to gain unauthorized access to that CVEs: CVE-2026-68820, CVE-2026-58231, CVE-2026-62832, CVE-2026-72971, CVE-2024-38193. CISA KEV/exploitation signal detected. Vendors: Microsoft, Tenable, Oracle, SAP, Adobe, Ivanti, GitHub. DORA relevance: high.
Por qué importa
Explotación activa confirmada. Riesgo material para entornos expuestos.
Acción recomendada
Comprueba la exposición a CVE-2026-68820, CVE-2026-58231, CVE-2026-62832 en el inventario de activos y las herramientas de vulnerabilidades.
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today. CVEs: CVE-2026-68820, CVE-2026-62832, CVE-2026-72971. CISA KEV/exploitation signal detected. Vendors: Microsoft, Cisco, Google, Oracle, Adobe, Mozilla. DORA relevance: medium.
Por qué importa
Explotación activa confirmada. Riesgo material para entornos expuestos.
Acción recomendada
Comprueba la exposición a CVE-2026-68820, CVE-2026-62832, CVE-2026-72971 en el inventario de activos y las herramientas de vulnerabilidades.
The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors. [...] CVEs: CVE-2026-3502. CISA KEV/exploitation signal detected. Vendors: Microsoft, Cisco, Oracle, Apache, Zoom, PHP, Check Point, Kaspersky. DORA relevance: medium.
Por qué importa
Explotación activa confirmada. Riesgo material para entornos expuestos.
Acción recomendada
Comprueba la exposición a CVE-2026-3502 en el inventario de activos y las herramientas de vulnerabilidades.
[CISA KEV actively exploited] Vendor: Oracle | Product: E-Business Suite | Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. | Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. | Due date: 2026-07-18 | Ransomware use: Unknown | Added: 2026-07-15 CVEs: CVE-2026-46817. CISA KEV/exploitation signal detected. Vendors: Oracle. DORA relevance: high.
Por qué importa
Explotación activa confirmada. Riesgo material para entornos expuestos.
Acción recomendada
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
[CISA KEV actively exploited ransomware] Vendor: Oracle | Product: PeopleSoft Enterprise PeopleTools | Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools. | Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. | Due date: 2026-06-15 | Ransomware use: Known | Added: 2026-06-12 CVEs: CVE-2026-35273. CISA KEV/exploitation signal detected. Vendors: Oracle. DORA relevance: medium.
Por qué importa
Explotación activa confirmada. Riesgo material para entornos expuestos.
Acción recomendada
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
[CISA KEV actively exploited] Vendor: Oracle | Product: WebLogic Server | Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Due date: 2026-06-04 | Ransomware use: Unknown | Added: 2026-06-01 CVEs: CVE-2024-21182. CISA KEV/exploitation signal detected. Vendors: Oracle. DORA relevance: medium.
Por qué importa
Explotación activa confirmada. Riesgo material para entornos expuestos.
Acción recomendada
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
[CISA KEV actively exploited] Vendor: Oracle | Product: Fusion Middleware | Oracle Fusion Middleware contains a missing authentication for critical function vulnerability, allowing unauthenticated remote attackers to take over Identity Manager. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Due date: 2025-12-12 | Ransomware use: Unknown | Added: 2025-11-21 CVEs: CVE-2025-61757. CISA KEV/exploitation signal detected. Vendors: Oracle. DORA relevance: medium.
Por qué importa
Explotación activa confirmada. Riesgo material para entornos expuestos.
Acción recomendada
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.