Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-4894

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability has been identified regarding insufficient validation in the Frappe Cloud/ERPNext authentication process, which allows multiple email addresses to be accepted by manipulating the email field in the /api/method/press.api.account.signup endpoint. The vulnerability occurs when an unauthenticated remote attacker adds more than one email address.<br /> The service processes the entire value as a valid list of recipients and sends the OTP code to all addresses without proper validation of all added emails (only one of them needs to be valid). Exploiting this vulnerability would allow an attacker to:<br /> <br /> * Obtain the authentication OTP;<br /> * Impersonate someone else in the registration process;<br /> * Register accounts using other people&amp;#39;s email addresses without access to the mailbox;<br /> * Indirectly confirm the existence of already registered email addresses.
Gravedad CVSS v4.0: MEDIA
Última modificación:
08/10/2026

CVE-2026-66084

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to modify task definitions in projects they are not authorized to access through the /dolphinscheduler/projects/{projectCode}/task-definition/{code}/with-upstream endpoint.<br /> <br /> <br /> <br /> The endpoint fails to verify that the task definition identified by code belongs to the project specified by projectCode. An authenticated user can supply the code of a project they are authorized to access together with a task definition code from another project, bypassing project access restrictions and modifying the target task definition and its upstream dependencies.<br /> <br /> <br /> <br /> This vulnerability can compromise workflow integrity and disrupt task execution in unauthorized projects.This issue affects Apache DolphinScheduler: before 3.4.3.<br /> <br /> <br /> <br /> Users are recommended to upgrade to version 3.4.3, which fixes the issue.
Gravedad: Pendiente de análisis
Última modificación:
08/10/2026

CVE-2026-66087

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to operate task instance in projects they are not authorized to access through the <br /> <br /> <br /> <br /> <br /> <br /> * /dolphinscheduler/projects/{projectCode}/task-instances/{taskInstanceId}/stop<br /> * /dolphinscheduler/projects/{projectCode}/task-instances/{taskInstanceId}/savepoint<br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> This issue affects Apache DolphinScheduler: before 3.4.3.<br /> <br /> <br /> <br /> Users are recommended to upgrade to version 3.4.3, which fixes the issue.
Gravedad: Pendiente de análisis
Última modificación:
08/10/2026

CVE-2026-12260

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** SQL injection in the NetBoard CRM demo platform; specifically, the vulnerable component is the ‘user-name’ POST parameter in the ‘/module/auth/recovery.php’ endpoint. The parameter is vulnerable to blind attacks based on Boolean, error, time-based and UNION techniques. Exploitation allows attackers to extract confidential information (such as the version and type of backend used), alter data or further compromise the CRM environment.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
08/10/2026

CVE-2026-66082

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to perform unauthorized operations on workflow schedules, workflow definitions, and task instances in other projects.<br /> <br /> <br /> <br /> The affected endpoints check permissions against the supplied projectCode but fail to verify that the target resource belongs to that project. An authenticated user with the required permissions in one project can supply that project&amp;#39;s code together with a resource identifier from another project, bypassing the target project&amp;#39;s access restrictions.<br /> <br /> <br /> <br /> The affected endpoints include:<br /> <br /> * <br /> <br /> POST /projects/{projectCode}/schedules/{id}/online and /offline: Activate or deactivate workflow schedules in another project.<br /> <br /> <br /> * <br /> <br /> POST /projects/{projectCode}/workflow-definition/{code}/release: Change the ONLINE/OFFLINE state of workflow definitions in another project.<br /> <br /> <br /> <br /> <br /> <br /> <br /> Successful exploitation allows users to alter workflow availability and interfere with task execution in projects they are not authorized to access.<br /> <br /> <br /> <br /> This issue affects Apache DolphinScheduler: before 3.4.3.<br /> <br /> <br /> <br /> Users are recommended to upgrade to version 3.4.3, which fixes the issue.
Gravedad: Pendiente de análisis
Última modificación:
08/10/2026

CVE-2026-105110

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** OS Command Injection in the login.xgi CGI endpoint in Iskratel Innbox GPON ONT devices allows an unauthenticated remote attacker to execute arbitrary commands as root via the CLI parameter.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
08/10/2026

CVE-2026-107466

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in flatpak-builder. This vulnerability allows an attacker to cause information disclosure by convincing a user or continuous integration (CI) system to process a crafted build manifest. By specifying local file Uniform Resource Identifiers (URIs) within source download definitions, the builder bypasses directory confinement checks. As a result, sensitive host files accessible to the build process can be read and incorporated into the build artifacts.
Gravedad CVSS v3.1: MEDIA
Última modificación:
08/10/2026

CVE-2026-93699

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** Argument injection in WP Toolkit for cPanel allows local users to execute arbitrary code as other accounts on the same server.
Gravedad CVSS v4.0: ALTA
Última modificación:
08/10/2026

CVE-2026-87424

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability in the SupportLink API authentication component of Brocade ASCG versions prior to 3.5.0 allows an attacker to bypass authentication across deployments due to the use of a hard coded cryptographic key.
Gravedad CVSS v4.0: ALTA
Última modificación:
08/10/2026

CVE-2026-87425

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** An unauthenticated remote attacker can modify the TLS client trust store in Brocade ASCG versions before 3.5.0. By supplying an unauthorized Certificate Authority (CA) certificate to an unauthenticated management interface, the attacker can cause the system to trust unauthorized certificates, potentially enabling Man-in-the-Middle (MITM) attacks against outbound communications with managed switches and peer nodes.
Gravedad CVSS v4.0: ALTA
Última modificación:
08/10/2026

CVE-2026-87426

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** An unauthenticated network-based attacker can query specific internal management endpoints on Brocade ASCG versions before 3.5.0 to enumerate the configuration details and state of managed Brocade Fabric OS (FOS) switches. This results in the unauthorized disclosure of the customer&amp;#39;s SAN fabric management topology and switch connectivity attributes.
Gravedad CVSS v4.0: MEDIA
Última modificación:
08/10/2026

CVE-2026-87428

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** In Brocade ASCG before 3.5.0, a  local unauthorized user on the ASCG VM who can issue a request to the SANnav host network namespace can extract stored management credentials for onboarded SANnav instances and compromise connected Brocade SANnav servers or managed Brocade Fibre Channel switches.
Gravedad CVSS v4.0: ALTA
Última modificación:
08/10/2026