Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-48911

Publication date:
05/08/2026
Insufficient Verification of Data Authenticity vulnerability in Apache Answer.<br /> <br /> This issue affects Apache Answer: through 2.0.1.<br /> <br /> A missing authorization check in the external-login email binding flow allows unauthenticated attackers to take over arbitrary user accounts by tricking victims into clicking a crafted confirmation link.<br /> Users are recommended to upgrade to version 2.0.2, which fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
06/08/2026

CVE-2026-49331

Publication date:
05/08/2026
A flaw was found in openshift/oauth-proxy. On paths configured to bypass authentication (skip-auth-regex), the proxy forwards client-supplied identity headers (X-Forwarded-User, X-Forwarded-Email, X-Forwarded-Access-Token) to the upstream application without stripping them. An unauthenticated attacker can inject forged identity headers on whitelisted paths.
Severity CVSS v4.0: Pending analysis
Last modification:
06/08/2026

CVE-2026-39924

Publication date:
05/08/2026
Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers who hold a valid session token to retain full account access after a victim changes their password, because the access_tokens table is never cleared on password change events. The TokensClearer::clearPasswordTokens() function only removes rows from the password_tokens table while leaving all active session cookies and API bearer tokens intact, including long-lived RememberAccessToken entries, and administrator-forced password resets via the user update endpoint are equally ineffective at revoking attacker-held sessions.
Severity CVSS v4.0: HIGH
Last modification:
05/08/2026

CVE-2026-48834

Publication date:
05/08/2026
Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer.<br /> <br /> This issue affects Apache Answer: through 2.0.1.<br /> <br /> Unauthenticated attackers can cause a denial of service via a specially crafted Accept-Language header that triggers excessive CPU consumption during parsing.<br /> Users are recommended to upgrade to version 2.0.2, which fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
06/08/2026

CVE-2026-39923

Publication date:
05/08/2026
Flarum before 1.8.16 contains a password reset token expiry bypass vulnerability that allows unauthenticated attackers to reuse expired password reset tokens by submitting them directly to the reset processing endpoint. The SavePasswordController::handle() method calls PasswordToken::findOrFail() without performing any expiry validation, allowing attackers to bypass the 24-hour token lifetime enforced only during form rendering and change any account&amp;#39;s password to gain an authenticated session.
Severity CVSS v4.0: CRITICAL
Last modification:
05/08/2026

CVE-2026-32835

Publication date:
05/08/2026
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Severity CVSS v4.0: Pending analysis
Last modification:
05/08/2026

CVE-2026-18531

Publication date:
05/08/2026
IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use of a weak HMAC session signing secret.
Severity CVSS v4.0: Pending analysis
Last modification:
10/08/2026

CVE-2026-16442

Publication date:
05/08/2026
A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a provider is restricted to account linking only. This allows an attacker with control over a linked upstream identity to bypass login restrictions and gain full access to a local user account.
Severity CVSS v4.0: Pending analysis
Last modification:
10/08/2026

CVE-2026-15587

Publication date:
05/08/2026
Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to escalate privileges to system-level administrative access using a crafted internal authentication header.<br /> <br /> <br /> <br /> <br /> This vulnerability was patched with version 6.3.85, and no customer action is needed.
Severity CVSS v4.0: CRITICAL
Last modification:
05/08/2026

CVE-2026-15656

Publication date:
05/08/2026
IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.
Severity CVSS v4.0: Pending analysis
Last modification:
10/08/2026

CVE-2026-15572

Publication date:
05/08/2026
A flaw was found in Keycloak&amp;#39;s Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Types" policy, which restricts which types of data mappers a client can use, fails to re-validate the mapper type during a client update if the mapper&amp;#39;s configuration remains unchanged. An attacker with client registration privileges can exploit this by first registering an allowed mapper type with a malicious configuration and then swapping it for a restricted, high-privilege mapper type (such as one that hardcodes administrative roles). This allows the attacker to gain full administrative access to the Keycloak realm.
Severity CVSS v4.0: Pending analysis
Last modification:
10/08/2026

CVE-2026-13477

Publication date:
05/08/2026
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input.
Severity CVSS v4.0: Pending analysis
Last modification:
10/08/2026