Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-77112

Publication date:
23/09/2026
Server-Side request forgery (SSRF) vulnerability in Global IT Informatics Technology Services Inc. Weoll allows Server Side Request Forgery.<br /> <br /> This issue affects Weoll: before 3.2.45.44.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2026

CVE-2026-76978

Publication date:
23/09/2026
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Command Injection vulnerability in the Diagnose Settings feature.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2026

CVE-2026-76979

Publication date:
23/09/2026
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to an XML Injection vulnerability in the Rule Tracking Compare Policies feature.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2026

CVE-2026-76980

Publication date:
23/09/2026
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Data Exposure vulnerability in the Firewall Analyzer syslog collector.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2026

CVE-2026-75825

Publication date:
23/09/2026
ZohoCorp ManageEngine OpManager versions 12.8.710 and below with the Application Manager Plugin enabled were vulnerable to an Authentication Bypass vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2026

CVE-2026-19599

Publication date:
23/09/2026
ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable to a Remote Code Execution vulnerability in the Notification Profile module.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2026

CVE-2026-96446

Publication date:
23/09/2026
A flaw was found in the Pushed Authorization Request PAR implementation of Keycloak. The issue occurs when the silent authentication path prompt=none is used, which allows the authorization process to skip certain steps if a user is already logged in. Due to this bypass, the security rule that ensures a pushed request URI is used only once is not enforced. An attacker could potentially reuse a request URI to obtain multiple authorization codes for a user who is already signed in, violating security standards like FAPI-2.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2026

CVE-2026-86248

Publication date:
23/09/2026
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat.<br /> <br /> <br /> <br /> This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.25, from 10.1.22 through 10.1.59, from 9.0.92 through 9.0.121.<br /> <br /> <br /> <br /> Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2026

CVE-2026-86350

Publication date:
23/09/2026
Inconsistent interpretation of HTTP/2 requests (&amp;#39;HTTP Request/Response smuggling&amp;#39;) vulnerability in Apache Tomcat caused by a regression in fix for CVE-2026-41293 can trigger request header mix-up.<br /> <br /> <br /> <br /> This issue affects Apache Tomcat: from 11.0.22 through 11.0.25, from 10.1.55 through 10.1.59, from 9.0.118 through 9.0.121.<br /> <br /> <br /> <br /> Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2026

CVE-2026-84791

Publication date:
23/09/2026
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to modify Change Management report schedule configurations for firewalls outside their assigned scope.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2026

CVE-2026-87022

Publication date:
23/09/2026
Improper handling of length parameter inconsistency vulnerability in Apache Tomcat allows WebSocket message smuggling when per-message-deflate is used.<br /> <br /> <br /> <br /> This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M1 through 9.0.121.<br /> <br /> <br /> <br /> The following versions were EOS at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.56 through 7.0.109. Other unsupported versions may also be affected.<br /> <br /> <br /> <br /> Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.1.22, which fix the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2026

CVE-2026-96445

Publication date:
23/09/2026
A flaw was found in the Conditional OTP authenticator of Keycloak, an identity and access management solution. The issue occurs when the system evaluates specific HTTP headers to determine if a one-time password (OTP) should be skipped, but fails to verify if those headers came from a trusted source. This could allow an attacker who already has a user&amp;#39;s password to bypass the second-factor authentication by providing a specially crafted header in their request.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2026