Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-17110

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands and obtain sensitive information due to improper privilege management.
Gravedad CVSS v3.1: ALTA
Última modificación:
17/08/2026

CVE-2026-16906

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** IBM i 7.6, and 7.5 could allow a remote authenticated attacker to execute arbitrary commands with elevated privileges due to improper neutralization of special elements used in an OS command.
Gravedad CVSS v3.1: ALTA
Última modificación:
13/08/2026

CVE-2026-16904

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper privilege management during monitor owner reassignment.
Gravedad CVSS v3.1: ALTA
Última modificación:
13/08/2026

CVE-2026-16863

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-of-bounds read.
Gravedad CVSS v3.1: ALTA
Última modificación:
13/08/2026

CVE-2026-16860

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncontrolled search path element.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
13/08/2026

CVE-2026-16856

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** IBM i 7.6, and 7.5 could allow a local attacker to gain elevated privileges due to improper neutralization of special elements used in an OS command.
Gravedad CVSS v3.1: ALTA
Última modificación:
17/08/2026

CVE-2026-16907

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to improper bounds checking.
Gravedad CVSS v3.1: ALTA
Última modificación:
17/08/2026

CVE-2026-16627

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to escalate privileges due to improper sanitization of HTML content rendered in a CI job modal.
Gravedad CVSS v3.1: ALTA
Última modificación:
19/08/2026

CVE-2026-15423

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute CI/CD pipelines on a protected branch without the required push permissions due to improper authorization in pipeline reference validation.
Gravedad CVSS v3.1: ALTA
Última modificación:
19/08/2026

CVE-2026-73297

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, _is_blocked_ip in ufo/utils/url_security.py did not block NAT64 prefixes 64:ff9b::/96 and 64:ff9b:1::/48, the 6to4 prefix 2002::/16, or the Teredo prefix 2001::/32 and did not re-check embedded IPv4 destinations, allowing an unauthenticated remote attacker who can influence URLs processed by validate_url to bypass the SSRF guard and reach cloud metadata, internal services, or localhost. This issue is fixed in version 3.0.8.
Gravedad CVSS v4.0: MEDIA
Última modificación:
12/08/2026

CVE-2026-73296

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and create_mobile_action_server in ufo/client/mcp/http_servers/mobile_mcp_server.py exposed Streamable HTTP MCP services on TCP ports 8020 and 8021 without authentication, allowing an unauthenticated remote attacker to invoke capture_screenshot, get_ui_tree, tap, swipe, type_text, launch_app, press_key, and click_control against an ADB-connected Android device, disclose screen and device data, and modify device state. This issue is fixed in version 3.0.8.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
13/08/2026

CVE-2026-73295

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Material for MkDocs is a powerful documentation framework built on top of MkDocs. From 7.2.0 until 9.7.7, the mountSearchSuggest function in src/templates/assets/javascripts/components/search/suggest/index.ts contains a DOM-based cross-site scripting vulnerability in the optional search.suggest feature that allows a crafted q URL parameter to execute JavaScript in a documentation site's origin after user interaction. This issue is fixed in version 9.7.7.
Gravedad CVSS v3.1: MEDIA
Última modificación:
13/08/2026