Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-10031

Fecha de publicación:
30/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** SFTPGo prior to 2.7.4 contains a permission bypass vulnerability that allows authenticated users to circumvent per-directory access controls by creating symbolic links in a permitted directory that point to files in directories where download, upload, or overwrite permissions are denied. Attackers can exploit the create_symlinks permission combined with read and write access in one directory to read or modify files in restricted directories, as operations are authorized against the link's directory permissions rather than the dereferenced target's directory permissions.
Gravedad CVSS v4.0: BAJA
Última modificación:
30/07/2026

CVE-2026-68562

Fecha de publicación:
30/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a managed node's Leapp report content can manipulate it. When an operator runs a specific remediation task, this manipulated report can cause the Ansible controller to read its own local files and copy them to the managed node. This vulnerability leads to information disclosure, potentially exposing sensitive controller-side data such as private keys or credentials.
Gravedad CVSS v3.1: MEDIA
Última modificación:
30/07/2026

CVE-2026-68563

Fecha de publicación:
30/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with elevated privileges and the `leapp_old_postgresql_data` option is selected, a PostgreSQL data backup archive is created with insecure permissions. This allows a local non-root user on the managed node to read sensitive archived PostgreSQL data, leading to information disclosure.
Gravedad CVSS v3.1: MEDIA
Última modificación:
30/07/2026

CVE-2026-5846

Fecha de publicación:
30/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS connections to the controller's built-in web management interface. These keys are embedded in plaintext within the application patch binaries in the firmware directly from Watchfire's Remote Support filestore.
Gravedad CVSS v4.0: ALTA
Última modificación:
30/07/2026

CVE-2026-62246

Fecha de publicación:
30/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datastore schema, database user, and etcd key prefix from a lossy namespace-and-name normalization in GetDefaultDatastoreSchema() and GetDefaultDatastoreUsername(), allowing distinct tenants with colliding normalized identifiers to share control-plane state and read, modify, or destroy another tenant's Kubernetes data. This issue is fixed in version 26.7.4-edge.
Gravedad CVSS v3.1: ALTA
Última modificación:
30/07/2026

CVE-2026-62845

Fecha de publicación:
30/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, the PostgreSQL and MySQL datastore drivers build DDL statements by interpolating the user-supplied DataStoreUsername/DataStoreSchema directly into SQL via fmt.Sprintf, without escaping identifiers. These fields have no format validation, so a value containing a quote character breaks out of the quoted identifier — SQL injection executed over Kamaji's root connection to the shared datastore. etcd driver is not affected.This issue is fixed in version 26.7.4-edge.
Gravedad CVSS v3.1: MEDIA
Última modificación:
30/07/2026

CVE-2026-63559

Fecha de publicación:
30/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An integer overflow in the UA_Variant arrayDimensions product <br /> computation in open62541 may allow a remote attacker to read <br /> out-of-bounds heap memory, potentially disclosing sensitive information.
Gravedad CVSS v4.0: ALTA
Última modificación:
30/07/2026

CVE-2026-64816

Fecha de publicación:
30/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** RapidRAW before 1.6.0 does not validate the lutPath field in preset files before passing it to File::open() in lut_processing.rs. On Windows, a UNC path in lutPath causes an outbound SMB connection to an attacker-controlled host, leaking the victim&amp;#39;s NTLMv2 credentials. The vulnerable code path is reachable through two vectors: community presets fetched automatically from the remote preset repository when the victim opens the Community tab, and individual preset files imported directly by the victim via the preset import feature (handle_import_presets_from_file in file_management.rs). The second vector does not require control of the community preset repository and is triggered when a user imports a preset file shared through Discord, forums, or similar channels.
Gravedad CVSS v4.0: ALTA
Última modificación:
30/07/2026

CVE-2026-18064

Fecha de publicación:
30/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An incomplete fix for CVE-2026-15352 in the NASA core Flight System <br /> (cFS) Health and Safety (HS) application leaves a separate NULL pointer <br /> dereference reachable in versions through 7.0.1. An attacker who can <br /> trigger the affected command under specific conditions could cause the <br /> HS application to crash, resulting in a denial-of-service condition and <br /> processor reset.
Gravedad CVSS v4.0: ALTA
Última modificación:
30/07/2026

CVE-2026-38709

Fecha de publicación:
30/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the net.set_wan interface. This vulnerability allows attackers to execute arbitrary commands as root via a crafted input.
Gravedad: Pendiente de análisis
Última modificación:
30/07/2026

CVE-2026-12562

Fecha de publicación:
30/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The RCU II+ and Multiload II+ are vulnerable to an unauthenticated <br /> service that exposes a debug interface granting full root-level access <br /> to the embedded system. This vulnerability stems from a <br /> network-accessible port running a Target Communications Framework (TCF) <br /> service that does not require any authentication, allowing an attacker <br /> to directly interact with the Linux environment that powers the device. <br /> Once connected, an attacker can freely view and modify the filesystem, <br /> manipulate running processes, and control network interfaces, enabling <br /> deep alteration of system behavior.
Gravedad CVSS v4.0: ALTA
Última modificación:
30/07/2026

CVE-2026-68500

Fecha de publicación:
30/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin&amp;#39;s POST /{_locale}/update-payment payment webhook accepts attacker-controlled id and orderId parameters but does not verify that the Mollie payment belongs to the referenced Sylius order, allowing an unauthenticated attacker with any valid paid Mollie payment ID to mark a victim order as paid without transferring funds for that order. This issue is fixed in 2.2.8, 3.2.4, and 3.3.1.
Gravedad CVSS v3.1: ALTA
Última modificación:
30/07/2026