Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-76268

Publication date:
07/10/2026
In Splunk Enterprise versions below 10.4.3 and 10.2.7, an unauthenticated user with network access to the Patroni Representational State Transfer (REST) Application Programming Interface (API) on a search head cluster member could execute attacker-controlled operating-system commands. The vulnerability is possible because this interface does not require authentication for critical configuration operations. For more information see Sidecar configuration settings (https://help.splunk.com/en/data-management/splunk-enterprise-admin-manual/10.2/splunk-sidecars/sidecar-configuration-settings) in the Splunk documentation.<br /> <br /> Splunk Enterprise versions 10.0.x and 9.4.x are not affected.
Severity CVSS v4.0: Pending analysis
Last modification:
07/10/2026

CVE-2026-76269

Publication date:
07/10/2026
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could use a user-controlled job identifier to access substantially all search job information from jobs that belong to other users, including search query text, job metadata, results, and preview results, through an Application Programming Interface (API) implemented as a Representational State Transfer (REST) API. The vulnerability is possible because the REST API does not fully validate job ownership before returning search job information.
Severity CVSS v4.0: Pending analysis
Last modification:
07/10/2026

CVE-2026-76270

Publication date:
07/10/2026
In Splunk Enterprise versions below 10.4.3, a user that holds a role with the list_spl2_modules capability could use SQL injection in SPL2 module filtering to access all relevant data available through the affected Representational State Transfer (REST) API, including private SPL2 module definitions belonging to other users. The vulnerability is possible because Splunk Enterprise and Splunk Cloud Platform do not parameterize user-supplied values before using them in database queries for SPL2 module filtering. For more information see Manage SPL2 modules (https://help.splunk.com/en/splunk-enterprise/search/spl2-search-manual/multiple-searches-in-an-spl2-module/manage-spl2-modules) and Module permissions (https://help.splunk.com/en/splunk-enterprise/search/spl2-search-manual/modules-statements-and-views/module-permissions) in the Splunk documentation.<br /> <br /> Splunk Enterprise versions 10.2.x, 10.0.x, and 9.4.x are not affected.
Severity CVSS v4.0: Pending analysis
Last modification:
07/10/2026

CVE-2026-107352

Publication date:
07/10/2026
Missing authorization checks in Amazon Athena engine version 3 request handling could have allowed an authenticated user to read limited query metadata (AWS account identifiers and SQL statement text) from other AWS accounts. Query results, credentials, and Amazon S3 data were not affected. AWS remediated the issue on September 1, 2026, and has confirmed no customer metadata was accessed. No customer action is required.
Severity CVSS v4.0: MEDIUM
Last modification:
07/10/2026

CVE-2026-1403

Publication date:
07/10/2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.7 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that when importing CSV files could have allowed an authenticated user to cause denial of service to Sidekiq workers due to improper validation of CSV file structure.
Severity CVSS v4.0: Pending analysis
Last modification:
07/10/2026

CVE-2026-107227

Publication date:
07/10/2026
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.2.0 until 3.0.14, WebSocket permessage-deflate decompression is unbounded when compression is enabled. The inbound pipeline aggregates compressed frames before WebSocketClientCompressionHandler inflates them, so webSocketMaxFrameSize and webSocketMaxBufferSize do not bound decompressed output. A malicious WebSocket peer can send a small compressed message that expands to a very large Netty buffer and exhausts JVM heap. This issue is fixed in version 3.0.14.
Severity CVSS v4.0: Pending analysis
Last modification:
07/10/2026

CVE-2026-107228

Publication date:
07/10/2026
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 3.0.14, the enabled-by-default cookie store replaces a Cookie header explicitly supplied through setHeader or addHeader whenever the store contributes any cookie for the origin. In a shared client, stored cookies originating from one user can replace a different user&amp;#39;s request cookie, causing the request to execute under the wrong session. This bypasses the earlier CVE-2024-53990 remediation, which covered cookies supplied through addCookie but not a directly supplied header. This issue is fixed in version 3.0.14.
Severity CVSS v4.0: Pending analysis
Last modification:
07/10/2026

CVE-2026-107229

Publication date:
07/10/2026
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.16.0 until 3.0.14, ThreadSafeCookieStore incompletely validates cookie Domain attributes. Missing private-section and default public-suffix rules, absent A-label normalization, locale-sensitive lowercasing, public-suffix host-only handling, and numeric or IP host checks allow one origin to store a cookie later sent to another origin. Applications sharing one client across trust domains can therefore receive attacker-injected cookies and may be exposed to session fixation. This issue is fixed in version 3.0.14.
Severity CVSS v4.0: Pending analysis
Last modification:
07/10/2026

CVE-2026-97715

Publication date:
07/10/2026
CVE-2026-97715 is<br /> a vulnerability in the client registration process of Secure Access servers<br /> prior to version 14.60. Authenticated attackers can pass malformed data to the<br /> server and cause a persistent denial of service.
Severity CVSS v4.0: HIGH
Last modification:
07/10/2026

CVE-2026-97716

Publication date:
07/10/2026
CVE-2026-97716<br /> is a vulnerability in the connection set up sub-system of Secure Access servers<br /> prior to version 14.60. Unauthenticated attackers can send specially crafted<br /> traffic to the server and cause a persistent denial of service.
Severity CVSS v4.0: HIGH
Last modification:
07/10/2026

CVE-2026-97717

Publication date:
07/10/2026
CVE-2026-97717<br /> is a vulnerability in the proxy sub-system of Secure Access servers prior to<br /> 14.60. Authenticated attackers can send malformed data to the server and cause<br /> a persistent denial of service.
Severity CVSS v4.0: MEDIUM
Last modification:
07/10/2026

CVE-2026-97714

Publication date:
07/10/2026
CVE-2026-97714<br /> is a is a vulnerability in the authentication sub-system of Secure Access<br /> servers prior to version 14.60. Attackers can send a malformed response during<br /> authentication and cause a persistent denial of service.
Severity CVSS v4.0: HIGH
Last modification:
07/10/2026