Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-18710

Fecha de publicación:
11/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity, to application log output in cleartext during routine client initialization. This occurs automatically as part of normal operation and requires no special privileges to trigger. A party able to read the affected application's logs or downstream log-aggregation storage could recover the credential and reuse it to authenticate to the associated network infrastructure. This issue affects confidentiality only.
Gravedad CVSS v4.0: ALTA
Última modificación:
12/08/2026

CVE-2026-71290

Fecha de publicación:
11/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by presenting a valid certificate for a different domain. <br /> <br /> <br /> Please note the classic version of HttpClient is not affected by this vulnerability. <br /> <br /> Affected users are recommended to upgrade to at least version 5.6.4, which fixes the issue.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
17/08/2026

CVE-2026-66148

Fecha de publicación:
11/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.1044) and earlier versions which allows low-privileged local user to execute system commands with root privileges.
Gravedad CVSS v3.1: MEDIA
Última modificación:
11/08/2026

CVE-2026-66149

Fecha de publicación:
11/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Control of Generation of Code (&amp;#39;Code Injection&amp;#39;) Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via netmask.
Gravedad CVSS v3.1: ALTA
Última modificación:
12/08/2026

CVE-2026-66150

Fecha de publicación:
11/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Control of Generation of Code (&amp;#39;Code Injection&amp;#39;) Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via SNMP.
Gravedad CVSS v3.1: ALTA
Última modificación:
12/08/2026

CVE-2026-66832

Fecha de publicación:
11/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user&amp;#39;s live session token is appended to the URL as a query string parameter, and a persistent user identifier is included in the WebView&amp;#39;s User-Agent header. Both are then transmitted to third-party web properties, referrer logs, and any JavaScript running in the WebView context.
Gravedad CVSS v4.0: MEDIA
Última modificación:
12/08/2026

CVE-2026-66147

Fecha de publicación:
11/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
12/08/2026

CVE-2026-66154

Fecha de publicación:
11/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1 (Build 9510.1044) and earlier versions which, under a successful MitM attack and controlled network conditions, could permit unauthorized changes.
Gravedad CVSS v3.1: ALTA
Última modificación:
12/08/2026

CVE-2026-63177

Fecha de publicación:
11/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Nginx OpenResty Lua layer evaluates the raw, unnormalized `ngx.var.request_uri`, while Nginx itself routes requests using the normalized path. An authenticated low-privilege user can prepend a traversal segment (for example `/x/../upload/...`) so that Nginx routes the request to a restricted backend while the Lua role check fails to match any rule and falls open, granting access it should deny. Version 26.07.0 fixes the issue.
Gravedad CVSS v3.1: ALTA
Última modificación:
12/08/2026

CVE-2026-63133

Fecha de publicación:
11/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` extracts uploaded archives with no limit on entry count, directory depth, total entries, or output size. A small malicious archive containing a large number of directory or file entries causes the filebeat processing container to create an unbounded number of filesystem objects, exhausting inodes or filesystem metadata and denying service to the processing pipeline and any service sharing the same mount. Version 26.07.0 fixes the issue.
Gravedad CVSS v3.1: MEDIA
Última modificación:
12/08/2026

CVE-2026-63134

Fecha de publicación:
11/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` protects file extraction with libarchive&amp;#39;s secure flags, but creates directory entries with a raw `os.makedirs(os.path.join(dest, entry.pathname))` that has no traversal protection. An uploaded malicious archive containing a directory entry with a `../` sequence or an absolute path causes the filebeat processing container to create directories outside the intended extraction directory. Version 26.07.0 fixes the issue.
Gravedad CVSS v3.1: MEDIA
Última modificación:
13/08/2026

CVE-2026-55676

Fecha de publicación:
11/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and stores them in a directory served by the same nginx and php-fpm instance. The allow-list that should restrict accepted file types is an empty array by default (`file-upload/php/config.php:16`), so the type check is a no-op and every extension is accepted. The filename sanitizer keeps the `.php` extension intact. Committed files land in `/var/www/upload/server/php/files` (`file-upload/php/config.php:7`), and the component&amp;#39;s nginx routes any URL ending in `.php` to php-fpm. An authenticated `GET /server/php/files/.php` then executes the uploaded code as `www-data`. Prior to version 26.06.1, in RBAC mode, the upload endpoint is reachable by the granular `ROLE_UPLOAD` role (`nginx/lua/nginx_auth_helpers.lua:71`), a role intended only for submitting capture files. As a result, a user holding the upload-only role runs arbitrary PHP as `www-data` inside the file-upload container. Version 26.06.1 fixes the issue.
Gravedad CVSS v3.1: ALTA
Última modificación:
12/08/2026