Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-81674

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The endpoint ‘/ws/apiprensa/getVideoNextPrev’ is vulnerable to SQL injection via the id_ambito parameter. Unsanitized input is directly incorporated into a MariaDB query, allowing attackers to inject SQL syntax that interrupts the query's execution. The vulnerability results in detailed database error messages and exposes the internal structure of the queries, which could facilitate further exploitation.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
27/08/2026

CVE-2026-81560

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability was identified in blackms aistack up to 1.6.1. Affected by this issue is some unknown functionality of the file src/web/server.ts of the component Static File Handler. Such manipulation of the argument req.url leads to path traversal. The attack can be executed remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Gravedad CVSS v4.0: MEDIA
Última modificación:
27/08/2026

CVE-2026-81562

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A security flaw has been discovered in AlexGladkov claude-in-mobile 3.10.2. This affects the function execSync of the file src/adb/client.ts. Performing a manipulation results in os command injection. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. Upgrading to version 3.10.3 is able to mitigate this issue. The patch is named a86d9e55694c98a122943eeff859461d0b9aa6d6. It is suggested to upgrade the affected component.
Gravedad CVSS v4.0: BAJA
Última modificación:
27/08/2026

CVE-2026-74233

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, and MT7620N firmware 19.1101, and WRC1 firmware 20.0622 contain an unauthenticated command injection in the infosrvd service (UDP/9992). A remote unauthenticated attacker can send a crafted UDP packet to execute arbitrary commands as root. The service's authentication uses a hardcoded salt and an all-zero wildcard MAC bypass, rendering it ineffective.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
27/08/2026

CVE-2026-74232

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2.000, AP522 firmware 1.0.0.2.014, AP7628 and HC5661A firmware 3.0.0.4.380, APG721B firmware 19.0809, HK300 firmware 1.0.0.2.032, and MAP-N10 firmware 1.0.0.2.044 ship a backdoor command-and-control implant (yunmgrd) reachable over an unauthenticated cleartext UDP channel to a hardcoded C2 server. A remote unauthenticated attacker on the network path can hijack the channel and execute arbitrary commands as root. The attacker can also modify DNS entries, exfiltrate PPPoE credentials, and open reverse SSH tunnels.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
27/08/2026

CVE-2026-66155

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability has been identified in Element maps-ng V47 (All versions
Gravedad CVSS v4.0: ALTA
Última modificación:
27/08/2026

CVE-2026-5218

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Softtr Informatics Technology Trading Limited Company E-Commerce Pack allows Cross-Site Scripting (XSS).<br /> <br /> This issue affects E-Commerce Pack: before 5.03.01.49.
Gravedad CVSS v3.1: MEDIA
Última modificación:
27/08/2026

CVE-2026-17562

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Authorization bypass through User-Controlled key vulnerability in Summit Security Systems AdisyonPro allows Accessing Functionality Not Properly Constrained by ACLs.<br /> <br /> This issue affects AdisyonPro: before v5.21.0.
Gravedad CVSS v3.1: MEDIA
Última modificación:
27/08/2026

CVE-2026-81625

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A remote attacker with user privileges may use a malicious or compromised NASL vulnerability test (VT) on the affected products to trigger a stack buffer overflow and gain full access on the compromised system.
Gravedad CVSS v4.0: ALTA
Última modificación:
27/08/2026

CVE-2026-81574

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format<br /> specifiers. This can be used to reliably crash CodeMeter and disclose sensitive information such as process memory<br /> and stack canaries. The attack works locally, for example by using cmu --set-proxy to set the proxy value, and<br /> remotely when combined with CVE-2026-81573 by setting General.ProxyServer and then triggering this<br /> vulnerability.
Gravedad CVSS v3.1: ALTA
Última modificación:
27/08/2026

CVE-2026-81575

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 accepts requests with opcode 0x5e, which contain the data length and<br /> the data itself. Missing bounds checking on the data length value can lead to out of bounds reads, causing a<br /> segmentation fault that ultimately crashes the CodeMeter Runtime.
Gravedad CVSS v3.1: ALTA
Última modificación:
27/08/2026

CVE-2026-81576

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak<br /> SID as sole authenticator. An attacker can brute-force the SID, recover another session&amp;#39;s handle number, and read<br /> license information belonging to another handle.
Gravedad CVSS v3.1: ALTA
Última modificación:
27/08/2026