9 vulnerabilidades · General · 🔥 KEV Orden: CVSS EPSS Año ID
CVE-2026-1731
🔥 KEV Remote Support(RS) & Privileged Remote Access(PRA) General
9.9
CRITICAL
EPSS
81.5%
2026 CWE-78 2 PoCs

BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.

CVE-2026-24061
🔥 KEV Inetutils General
9.8
CRITICAL
EPSS
92.3%
2026 CWE-88 2 PoCs

telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.

CVE-2026-33634
🔥 KEV setup-trivy General
9.4
CRITICAL
EPSS
16.8%
2026 CWE-506 1 PoC

Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credential-stealing malware, and replace all 7 tags in `aquasecurity/setup-trivy` with malicious commits. This incident is a continuation of the supply chain attack that began in late February 2026. Following the initial disclosure on March 1, credential rotation was performed but was not atomic (not all credentials were revoked simultaneously). The attacker could have use a valid token to ex

CVE-2026-41940
🔥 KEV cPanel General ⚡ nuclei
9.3
CRITICAL
EPSS
67.0%
2026 CWE-306 1 PoC

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

CVE-2026-39987
🔥 KEV marimo General
9.3
CRITICAL
EPSS
78.7%
2026 CWE-306 1 PoC

marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks authentication validation, allowing an unauthenticated attacker to obtain a full PTY shell and execute arbitrary system commands. Unlike other WebSocket endpoints (e.g., /ws) that correctly call validate_auth() for authentication, the /terminal/ws endpoint only checks the running mode and platform support before accepting connections, completely skipping authentication verification. This vulnerability is fixed in 0.23.0.

CVE-2026-2441
🔥 KEV Chrome General
8.8
HIGH
EPSS
9.5%
2026 CWE-416 1 PoC

Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-31431
🔥 KEV Linux General
7.8
HIGH
EPSS
2.6%
2026 22 PoCs

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.

CVE-2026-33825
🔥 KEV Microsoft Defender Antimalware Platform General
7.8
HIGH
EPSS
4.9%
2026 CWE-1220 1 PoC

Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.

CVE-2026-21509
🔥 KEV Microsoft 365 Apps for Enterprise General
7.8
HIGH
EPSS
12.5%
2026 CWE-807 2 PoCs

Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.