Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-44191

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in the Visual Studio Code Ansible Lightspeed extension. This command injection vulnerability (CWE-78) arises from improper handling of the ansible.executionEnvironment.containerOptions and ansible.executionEnvironment.volumeMounts settings, allowing an attacker to inject shell separators. This can be triggered automatically during Language Server initialization or manually when executing a playbook. Successful exploitation leads to remote code execution (RCE) on the victim's machine with the privileges of the Visual Studio Code user, potentially resulting in a complete system compromise.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/07/2026

CVE-2026-16270

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Open Mercato does not validate regex rules. An attacker with privileges to create the regex rule can add an unsafe regex to a field. When someone provide the proper string it can result in a DoS attack.<br /> <br /> <br /> This issue was fixed in version 0.6.4.
Gravedad CVSS v4.0: MEDIA
Última modificación:
22/07/2026

CVE-2026-65602

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to enforce the crossProviderNamespaces allowlist for IngressRouteTCP service serversTransport references (the allowlist was only enforced for HTTP serversTransport references). A low-privileged Kubernetes user in a namespace not listed in crossProviderNamespaces can set serversTransport: foo@file on an IngressRouteTCP service, causing Traefik to accept the forbidden cross-provider reference and use a file-provider TCPServersTransport — including privileged backend mTLS client certificates, SPIFFE identity, or PROXY-protocol settings. This is fixed in 3.6.23 and 3.7.7.
Gravedad CVSS v4.0: MEDIA
Última modificación:
22/07/2026

CVE-2026-65603

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Grav Login plugin (grav-plugin-login) versions
Gravedad CVSS v4.0: ALTA
Última modificación:
22/07/2026

CVE-2026-65601

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Traefik versions 3.7.0 through 3.7.6 contain a namespace confusion vulnerability in the Kubernetes Gateway API provider. When resolving HTTPRoute.spec.rules[].backendRefs[].filters[].extensionRef, Traefik used the backend Service namespace instead of the HTTPRoute namespace. A low-privileged route author holding a ReferenceGrant for a cross-namespace Service could therefore bind a Traefik Middleware from the backend namespace without a separate grant for that middleware, potentially injecting trusted reverse-proxy identity headers into downstream requests. The issue is fixed in version 3.7.7.
Gravedad CVSS v4.0: MEDIA
Última modificación:
23/07/2026

CVE-2026-65600

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Traefik versions = v3.6.0 = v3.7.0
Gravedad CVSS v4.0: ALTA
Última modificación:
23/07/2026

CVE-2026-65598

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node&amp;#39;s clone operation that allows authenticated users to bypass path restrictions by swapping a directory for a symlink after the path is validated but before the clone runs. This lets an attacker plant a crafted repository in the community node directory, which n8n loads as a custom node on the next restart, executing arbitrary JavaScript on the server. Both self-hosted and cloud instances are affected.
Gravedad CVSS v4.0: ALTA
Última modificación:
27/07/2026

CVE-2026-65599

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a credential exposure vulnerability: when configured with a Google Service Account key, the full PEM private key was mistakenly placed in the JWT header&amp;#39;s kid field (intended only for a key identifier). Because JWT headers are Base64-encoded rather than encrypted, the private key could be recovered by anything that logged or inspected the JWT. An attacker who obtained the key could impersonate the service account and access or modify any Google Cloud resource it was authorized to use. Only instances using Google Service Account credentials are affected.
Gravedad CVSS v4.0: MEDIA
Última modificación:
27/07/2026

CVE-2026-65591

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator&amp;#39;s computed-member handler. An authenticated user with workflow create or modify permissions can craft a malicious expression to bypass the sanitizer and achieve host-level code execution as the n8n process. The legacy expression engine is the default in affected versions. Fixed in n8n 1.123.64, 2.29.8, and 2.30.1.
Gravedad CVSS v4.0: ALTA
Última modificación:
27/07/2026

CVE-2026-65592

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM cross-site scripting vulnerability in the Resource Locator component, which passes the workflow-persisted cachedResultUrl parameter to window.open() without scheme validation. An attacker with workflow creation/editing privileges can craft a workflow with a malicious (e.g., javascript:) scheme in cachedResultUrl; when a victim opens the crafted workflow and interacts with external links, the payload executes in the victim&amp;#39;s browser.
Gravedad CVSS v4.0: ALTA
Última modificación:
27/07/2026

CVE-2026-65593

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a server-side request forgery vulnerability in the dynamic-node-parameters endpoints that lack authorization scopes. Authenticated attackers can supply absolute URLs in routing configuration to override baseURL restrictions and make the n8n server issue HTTP requests to arbitrary internal targets when SSRF protection is disabled.
Gravedad CVSS v4.0: MEDIA
Última modificación:
27/07/2026

CVE-2026-65594

Fecha de publicación:
22/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was introduced) does not verify that the authenticated user has access to the workflow referenced as the OAuth resource. On instances with at least one active MCP Server Trigger workflow configured with n8n OAuth2 authentication, a member-level user can register an OAuth client, self-approve consent for another user&amp;#39;s workflow, and obtain a valid token. The workflow then runs in the owner&amp;#39;s project context with the owner&amp;#39;s stored credentials, and the attacker can set tool inputs and read outputs (potentially including data from the owner&amp;#39;s connected integrations), breaking user and project isolation.
Gravedad CVSS v4.0: MEDIA
Última modificación:
27/07/2026