Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-65590

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in the @n8n/computer-use package (sandboxing was applied only on macOS). Shell commands executed by the tool run without any filesystem or network restrictions, allowing unrestricted access to the host filesystem and network from within the computer-use agent process. This issue only affects deployments where the @n8n/computer-use package is explicitly installed and running; standard n8n installations are not affected.
Gravedad CVSS v4.0: MEDIA
Última modificación:
22/07/2026

CVE-2026-65015

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-execution tool lacks proper authorization checks. A Project Viewer user can escalate privileges by chatting with an agent that has node tools enabled, executing arbitrary nodes and accessing credential secrets without proper authorization verification.
Gravedad CVSS v4.0: ALTA
Última modificación:
22/07/2026

CVE-2026-61390

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** There is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to cause device malfunction by sending specially crafted packets.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/07/2026

CVE-2026-61391

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** There is a stack-based buffer overflow vulnerability in some Hikvision cameras, which may allow authenticated attackers to cause device malfunction by sending specially crafted packets.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/07/2026

CVE-2026-61392

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** There is a information disclosure vulnerability in some Hikvision cameras, allowing unauthenticated attackers to obtain partial information from the device’s memory.
Gravedad CVSS v3.1: MEDIA
Última modificación:
22/07/2026

CVE-2026-65589

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secrets to workflow execution records. Authenticated users with access to execution data can read exposed header values and credentials that persist in the database and can be exported.
Gravedad CVSS v4.0: MEDIA
Última modificación:
23/07/2026

CVE-2026-65016

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in Enterprise SSO instance-role provisioning. The provisioning path maps an IdP-asserted role claim to an n8n global role but does not prevent assignment of the global:owner role (unlike the token-exchange identity path, which rejects it). An SSO-authenticated user whose instance-role claim resolves to global:owner is provisioned as instance owner, gaining full administrative control over workflows, credentials, users, and instance configuration. Exploitation requires that Enterprise SSO is configured, instance-role provisioning is enabled via N8N_SSO_SCOPES_PROVISION_INSTANCE_ROLE (disabled by default), and the attacker controls the instance-role claim value issued by the IdP.
Gravedad CVSS v4.0: ALTA
Última modificación:
23/07/2026

CVE-2026-57599

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** There is a privilege escalation vulnerability in some Hikvision cameras. Due to incorrect permission allocation in the device program, attackers can escalate privileges and gain full control of the device after authenticating via SSH.
Gravedad CVSS v3.1: MEDIA
Última modificación:
22/07/2026

CVE-2026-57600

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Insufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers to retrieve partial sensitive data.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/07/2026

CVE-2026-4773

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper validation of specified type of input vulnerability in Magarsus Consulting Ltd. Co. IDM-MFA allows Authentication Bypass.<br /> <br /> This issue affects IDM-MFA: from 2025.11.27 before 2026.03.10.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/07/2026

CVE-2026-44192

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in the Ansible Lightspeed Model Context Protocol (MCP) server. This vulnerability, known as path traversal, allows an attacker to manipulate an AI agent through indirect prompt injection. By doing so, the attacker can cause the server to write files to unauthorized locations on the user&amp;#39;s system. This can result in the exposure of sensitive host information and enable the attacker to execute malicious commands, potentially leading to a full system compromise.
Gravedad CVSS v3.1: MEDIA
Última modificación:
22/07/2026

CVE-2026-44189

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in the Visual Studio Code Ansible Lightspeed extension&amp;#39;s AnsiblePlaybookRunProvider. This command injection vulnerability allows an attacker to craft a malicious playbook filename containing special characters. When a victim runs the playbook, these characters are not properly sanitized, leading to the execution of arbitrary code with the privileges of the user running VS Code. This could result in a full system compromise, including the exfiltration of sensitive data, modification of project files, and permanent data loss.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/07/2026