Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-79304

Fecha de publicación:
23/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** CyberPanel 1.9.1 contains a path traversal vulnerability in the readFileContents method of the /filemanager/controller endpoint. An authenticated remote attacker with ownership of any configured domain can supply an arbitrary absolute or out-of-scope path in the fileName JSON property. Because authorization validates only domainName and does not canonicalize or restrict fileName to that domain's home directory, the application returns the contents of files readable by the CyberPanel execution identity.
Gravedad CVSS v3.1: MEDIA
Última modificación:
23/09/2026

CVE-2026-79306

Fecha de publicación:
23/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** CyberPanel v1.9.1 contains a path traversal vulnerability in the compress method exposed through the /filemanager/controller endpoint. An authenticated remote attacker with ownership of any configured domain can supply absolute or otherwise out-of-scope file paths in the listOfFiles JSON property, together with attacker-controlled basePath and compressedFileName values, in a method=compress request. Because the application validates only domain ownership and does not canonicalize or restrict these paths to the authorized site directory, the backend appends them to zip or tar archive commands and executes them as the website externalApp user, allowing disclosure of arbitrary readable files through the generated archive.
Gravedad CVSS v3.1: MEDIA
Última modificación:
23/09/2026

CVE-2026-79310

Fecha de publicación:
23/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** webpy web.py 0.76 is vulnerable to server-side template injection (SSTI). The template engine can be tricked into executing attacker-controlled template code that built-in security checks are designed to reject. When an application precompiles templates from a directory the attacker can write to and later renders them through the precompiled template loader, the sandbox is bypassed and the attacker's code runs, resulting in arbitrary Python code execution and OS command execution on the server.
Gravedad CVSS v3.1: ALTA
Última modificación:
23/09/2026

CVE-2026-6327

Fecha de publicación:
23/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.
Gravedad CVSS v3.1: MEDIA
Última modificación:
23/09/2026

CVE-2026-3626

Fecha de publicación:
23/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Gravedad CVSS v3.1: MEDIA
Última modificación:
23/09/2026

CVE-2026-4921

Fecha de publicación:
23/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** IBM Guardium Data Protection 12.2 could allow an administrative user to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Gravedad CVSS v3.1: BAJA
Última modificación:
23/09/2026

CVE-2026-19267

Fecha de publicación:
23/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to missing authentication on the Business Rules Manager commands REST endpoint (`CommandsResource.java:31`). A local actor can invoke unauthenticated commands to cause resource exhaustionand halt business-rule management functions.
Gravedad CVSS v3.1: MEDIA
Última modificación:
23/09/2026

CVE-2026-19179

Fecha de publicación:
23/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to manipulate database queries due to improper neutralization of special elements in a boolean expression.
Gravedad CVSS v3.1: ALTA
Última modificación:
23/09/2026

CVE-2026-18185

Fecha de publicación:
23/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to access sensitive information and modify system configurations due to missing authentication for a critical function.
Gravedad CVSS v3.1: ALTA
Última modificación:
23/09/2026

CVE-2026-19087

Fecha de publicación:
23/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to achieve privilege escalation within the container due to improper privilege management.
Gravedad CVSS v3.1: MEDIA
Última modificación:
23/09/2026

CVE-2026-18505

Fecha de publicación:
23/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to open redirect in the PMP `HostHeaderFilter` (`HostHeaderFilter.java:151`). An unauthenticated attacker can craft a request with a manipulated `Host` header to redirect authenticated operators to attacker-controlled sites, enabling credential phishing.
Gravedad CVSS v3.1: MEDIA
Última modificación:
23/09/2026

CVE-2026-18181

Fecha de publicación:
23/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to bypass authentication and access sensitive information due to a hard-coded cryptographic key.
Gravedad CVSS v3.1: ALTA
Última modificación:
23/09/2026