Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-78253

Publication date:
23/09/2026
Uncontrolled recursion in QXmlStreamReader::readElementText() in Qt Group Qt allows attackers to cause a denial of service (application crash via stack exhaustion) via a crafted XML document.
Severity CVSS v4.0: LOW
Last modification:
23/09/2026

CVE-2026-80444

Publication date:
23/09/2026
URL redirection to untrusted site (&amp;#39;open redirect&amp;#39;) vulnerability in Abis Technology Ltd. Co. AVESİS allows Input Data Manipulation.<br /> <br /> This issue affects AVESİS: from 202608201331 before 202608240351.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2026

CVE-2026-84787

Publication date:
23/09/2026
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Privilege Escalation vulnerability that allowed an authenticated low-privilege user to gain Administrator privileges through Report Profile import.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2026

CVE-2026-84789

Publication date:
23/09/2026
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to create alert notifications for firewalls outside their assigned scope.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2026

CVE-2026-78383

Publication date:
23/09/2026
Allocation of resources without limits or throttling vulnerability in Apache Tomcat allows an unauthenticated AJP request to pin an AJP processing thread leading to denial of service.<br /> <br /> <br /> <br /> This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M1 through 9.0.121.<br /> <br /> <br /> <br /> The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected.<br /> <br /> <br /> <br /> Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2026

CVE-2026-78437

Publication date:
23/09/2026
Incomplete cleanup vulnerability in Apache Tomcat allows a malformed request to potentially (depends on timing) cause one request from another user to fail.<br /> <br /> <br /> <br /> This issue affects Apache Tomcat: from 11.0.19 through 11.0.25, from 10.1.53 through 10.1.59, from 9.0.116 through 9.0.121.<br /> <br /> <br /> <br /> Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2026

CVE-2026-79677

Publication date:
23/09/2026
Missing release of resource after effective lifetime, Comparison using wrong factors vulnerability in Apache Tomcat allows a denial of service as a result of lost time outs for asynchronous WebSocket writes.<br /> <br /> <br /> <br /> This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M1 through 9.0.121.<br /> <br /> <br /> <br /> The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected.<br /> <br /> <br /> <br /> Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2026

CVE-2026-73581

Publication date:
23/09/2026
Improper Check for Certificate Revocation vulnerability in Apache Tomcat. Both the OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore.<br /> <br /> <br /> <br /> This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.58, from 9.0.0-M1 through 9.0.121.<br /> <br /> <br /> <br /> The following versions were EOL at the time the CVE was created but are <br /> known to be affected: from 8.5.0 through 8.5.100. Other unsupported versions may also be affected.<br /> <br /> <br /> <br /> Users are recommended to upgrade to version 11.0.26, 10.1.59, 9.0.122, which fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2026

CVE-2026-75973

Publication date:
23/09/2026
Improper Authentication vulnerability in Apache Tomcat. When Jakarta Authentication was configured with SimpleAuthConfigProvider as the default provider and multiple web application used that provider, the realm for the first web application to authenticate a request would be used for all web applications.<br /> <br /> <br /> <br /> This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M4 through 9.0.121.<br /> <br /> <br /> <br /> The following versions were EOL at the time the CVE was created but are <br /> known to be affected: from 8.5.0 through 8.5.100. Other unsupported versions may also be affected.<br /> <br /> <br /> <br /> <br /> Users are recommended to upgrade to version 11.0.26, 10.1.60, 9.0.122, which fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2026

CVE-2026-76183

Publication date:
23/09/2026
Authentication Bypass by Alternate Name vulnerability in Apache Tomcat allowed the security constraints for any WebSocket endpoint to be bypassed.<br /> <br /> <br /> <br /> This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M1 through 9.0.121.<br /> <br /> <br /> <br /> The following versions were EOS at the time the CVE was created but are <br /> known to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected.<br /> <br /> <br /> <br /> <br /> Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2026

CVE-2026-77756

Publication date:
23/09/2026
Inconsistent Interpretation of HTTP Requests (&amp;#39;HTTP Request/Response Smuggling&amp;#39;) vulnerability in Apache Tomcat caused by processing the transfer-encoding header for an HTTP/1.0 request may allow an attacker to cause one request from another user to fail when Tomcat is located behind a reverse proxy.<br /> <br /> <br /> <br /> This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.47 through 9.0.121.<br /> <br /> <br /> <br /> The following versions were EOL at the time the CVE was created but are <br /> known to be affected: from 8.5.67 through 8.5.100. Other unsupported versions may also be affected.<br /> <br /> <br /> <br /> Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2026

CVE-2026-77762

Publication date:
23/09/2026
Concurrent Execution using Shared Resource with Improper Synchronization (&amp;#39;Race Condition&amp;#39;) vulnerability in Apache Tomcat allows an attacker to inject trailer fields into another HTTP/2 request.<br /> <br /> <br /> <br /> This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.39 through 9.0.121.<br /> <br /> <br /> <br /> The following versions were EOL at the time the CVE was created but are <br /> known to be affected: from 8.5.59 through 8.5.100. Other unsupported versions may also be affected.<br /> <br /> <br /> <br /> <br /> Users are recommended to upgrade to version 11.0.26, 10.1.60, 9.0.122, which fix the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2026