Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-50736

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscriber, executes message payloads on the subscriber at the privilege level of the apply worker, which is equivalent to a PostgreSQL superuser in default installations. A party acting as the publisher can send crafted queue messages that cause arbitrary SQL to be executed on the subscriber as superuser, escalating from a role permitted to use pglogical to full superuser and breaking the isolation between tenants in shared deployments. To exploit the issue an attacker must be able to direct a subscription at an endpoint they control. In default installations this requires privileges normally reserved for a superuser, so the issue is most relevant to managed deployments where the ability to create subscriptions has been delegated to non-superuser roles.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
30/07/2026

CVE-2026-50737

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** When applying replicated changes for a row that is missing one or more columns, pglogical evaluates the affected table&amp;#39;s default expressions on the subscriber. Because the apply worker runs at a privilege level equivalent to a PostgreSQL superuser in default installations, any function invoked by such a default expression also runs at that privilege. A party acting as the publisher can use this path to cause functions to be executed on the subscriber as superuser, escalating from a role permitted to use pglogical to full superuser.<br /> <br /> This is a second, independent path to the same superuser escalation tracked under CVE-2026-50736 (the pglogical queue issue). To exploit the issue an attacker must be able to direct a subscription at an endpoint they control. In default installations this requires privileges normally reserved for a superuser, so the issue is most relevant to managed deployments where the ability to create subscriptions has been delegated to non-superuser roles.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
30/07/2026

CVE-2026-50738

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A use-after-free condition exists in pglogical&amp;#39;s worker signaling code, where a worker structure can be dereferenced after the underlying slot has been freed or recycled during normal worker lifecycle events. The condition is reachable during normal replication operation, including by a low-privileged user able to influence worker start, stop, and restart timing through permitted pglogical operations. In the typical case the condition crashes replication workers, causing an availability impact. In the worst case a use-after-free in a PostgreSQL backend can be leveraged as a remote code execution primitive at the privilege of that backend.
Gravedad CVSS v4.0: ALTA
Última modificación:
30/07/2026

CVE-2026-49258

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and below, the web UI (/ui/*) does not apply the per-operator CA scoping employed by the JSON API. This was partially addressed by GHSA-598g-h2vc-h5vg, but the changes were not implemented in the web read/mutation surface. Any authenticated non-admin operator (for example, one created via self-registration or OIDC) can access resources belonging to other operators. The host create/edit/mobile-bundle/network-create paths and all CA-management routes were already correctly scoped. A malicious operator could block or delete any other operator&amp;#39;s host, or read any operator&amp;#39;s hosts and networks. This issue has been fixed in version 0.3.6.
Gravedad CVSS v3.1: ALTA
Última modificación:
30/07/2026

CVE-2026-48395

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Gravedad CVSS v3.1: ALTA
Última modificación:
03/08/2026

CVE-2026-48390

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Gravedad CVSS v3.1: ALTA
Última modificación:
03/08/2026

CVE-2026-48392

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Gravedad CVSS v3.1: ALTA
Última modificación:
03/08/2026

CVE-2026-48391

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Gravedad CVSS v3.1: ALTA
Última modificación:
03/08/2026

CVE-2026-48393

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Gravedad CVSS v3.1: ALTA
Última modificación:
03/08/2026

CVE-2026-48394

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Gravedad CVSS v3.1: ALTA
Última modificación:
03/08/2026

CVE-2026-48396

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Bridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Gravedad CVSS v3.1: ALTA
Última modificación:
03/08/2026

CVE-2026-47725

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.3, every /ui/* POST / PUT / PATCH / DELETE route processes the request as soon as the session cookie validates. SameSite=Lax on the session cookie prevents most cross-site form submits but does not protect: top-level form-submit navigations from third-party pages (some browsers still send Lax cookies on top-level POSTs); same-registrable-domain attackers (sibling-subdomain XSS, subdomain takeover); the GET /ui/logout route, which a third-party can force-trigger. This issue has been patched in version 0.3.3.
Gravedad CVSS v4.0: MEDIA
Última modificación:
30/07/2026