Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-59919

Fecha de publicación:
29/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Final, Netty's HAProxy encoder ( HAProxyMessageEncoder ) writes AF_UNIX source and destination socket addresses into the HAProxy V1 text protocol without validating them for CRLF characters, so an attacker who controls an AF_UNIX address can inject  \r\n  sequences and split the single PROXY header into multiple lines. This is possible because the V1 protocol uses CRLF as its line terminator and, unlike IPv4/IPv6 addresses whose format checks implicitly reject CRLF, AF_UNIX addresses are only validated for length (up to 108 bytes), allowing a forged second PROXY header line that spoofs the client source/destination IP to a downstream server or load balancer. The issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
Gravedad CVSS v3.1: MEDIA
Última modificación:
29/07/2026

CVE-2026-54705

Fecha de publicación:
29/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** MathLive provides web components for math display and input. Prior to 0.110.0, MathLive fails to escape text-mode content in \text{} and \mbox{} commands in Box.toMarkup at src/core/box.ts, in xmlEscape, scanText, and text-mode output in src/formats/atom-to-math-ml.ts, and through convertLatexToMarkup, convertLatexToMathMl, , , and the default identity MathfieldElement.createHTML, allowing malicious input to run arbitrary JavaScript when rendered. This issue is fixed in version 0.110.0.
Gravedad CVSS v3.1: MEDIA
Última modificación:
29/07/2026

CVE-2026-41939

Fecha de publicación:
29/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attackers to gain administrative access by using default credentials identical across all installations. Attackers can authenticate to the exposed WildFly management console on port 20990 and deploy a malicious Web Application Archive file through the Deployments interface to achieve remote code execution as the Windows machine account. Version 14.x.x was declared end-of-life (EOL) in 2017 and future releases have addressed the vulnerable finding.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
29/07/2026

CVE-2026-40272

Fecha de publicación:
29/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Input Validation in the decode() function of the traceparser library could allow an attacker with a corrupted kernel trace event log (.kev) file, to execute arbitrary code or cause a crash in processes that use libtraceparser in QNX hosts or targets.
Gravedad CVSS v3.1: ALTA
Última modificación:
29/07/2026

CVE-2026-18236

Fecha de publicación:
29/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker who is able to manipulate or inject events into the session history can execute unauthorized tools by forging a tool confirmation response. This is possible because the framework did not verify if the target tool was registered to the executing agent, did not validate if the tool actually required confirmation, and did not match the confirmation arguments against the original tool call event in the history.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
29/07/2026

CVE-2026-13723

Fecha de publicación:
29/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability in the `zipx.Unzip` extraction routine of Develar&amp;#39;s app-builder allows an attacker to overwrite arbitrary files on macOS APFS by exploiting a Unicode Normalization Collision combined with symlink following behavior. APFS treats certain Unicode equivalent filenames as identical (e.g., ß ↔ ss), while app builder performs no canonical normalization before validating or writing paths. As a result, a crafted ZIP archive containing:<br /> • a symlink entry named ss pointing to a target file, and<br /> • a regular file named ß containing attacker controlled data,<br /> will cause the second write to follow the symlink and overwrite the target file.
Gravedad CVSS v3.1: MEDIA
Última modificación:
29/07/2026

CVE-2026-14266

Fecha de publicación:
29/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** 7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.<br /> <br /> The specific flaw exists within the processing of XZ chunked data. Crafted XZ-compressed data can trigger an overflow of a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-30169.
Gravedad CVSS v3.1: ALTA
Última modificación:
29/07/2026

CVE-2026-8339

Fecha de publicación:
29/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A SQL injection vulnerability exists in the Coverity Connect SOAP API for versions between 2024.6.0 and 2026.3.0 (inclusive). A malicious, authenticated threat actor who sends a specially crafted payload can achieve full read access to database contents and other unauthorized commands.
Gravedad CVSS v4.0: ALTA
Última modificación:
29/07/2026

CVE-2026-67194

Fecha de publicación:
29/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Courier IMAP before 6.0.1 and Courier Mail Server before 2.0.2 allow authenticated IMAP users to crash the imapd process via deeply nested parenthesized SEARCH queries. The SEARCH command parser (alloc_search_key in searchinfo.C) recursively descends on nested parenthesized groups through a mutual recursion chain with alloc_search_andlist() and alloc_search_notkey(), with no depth limit. Courier IMAP has no overall command line length limit, making exploitation trivial. A single IMAP command with ~2500 nested parentheses overflows the 8MB default stack, causing SIGSEGV.
Gravedad CVSS v4.0: ALTA
Última modificación:
29/07/2026

CVE-2026-8338

Fecha de publicación:
29/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026.3.0. An unauthenticated malicious threat actor that can send a specially crafted HTTP request is able to bypass authentication and authorization controls on certain API endpoints to access data within Coverity.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
29/07/2026

CVE-2026-64558

Fecha de publicación:
29/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> s390/pkey: Check length in pkey_pckmo handler implementation<br /> <br /> Explicitly check the length of the target buffer in the pkey_pckmo<br /> implementation of the key_to_protkey() handler function. The handler<br /> function fails, if the generated output data exceeds the length of the<br /> provided target buffer.
Gravedad: Pendiente de análisis
Última modificación:
29/07/2026

CVE-2026-64559

Fecha de publicación:
29/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> s390/pkey: Check length in PKEY_VERIFYPROTK ioctl<br /> <br /> Explicitly check the buffer length request structure provided by<br /> user-space and fail, if it exceeds the buffer size.
Gravedad: Pendiente de análisis
Última modificación:
29/07/2026