Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-63000

Fecha de publicación:
23/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** REDAXO is a PHP-based content management system. Prior to 5.21.2, rex_api_install_package_update in redaxo/src/addons/install/lib/api/api_package_update.php inherits the false default from rex_api_function::requiresCsrfProtection() instead of requiring a CSRF token. An unauthenticated attacker can cause a logged-in administrator's browser to request a selected package update from the configured REDAXO package server, changing installed addon code or disrupting the site without the administrator's intent. This issue is fixed in version 5.21.2.
Gravedad CVSS v3.1: MEDIA
Última modificación:
23/09/2026

CVE-2026-63002

Fecha de publicación:
23/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** REDAXO is a PHP-based content management system. Prior to 5.21.2, redaxo/src/addons/mediapool/pages/sync.php inserts filenames held in $diffFiles from the media filesystem into the Mediapool Sync page without rex_escape(). An attacker who can place an unregistered file with HTML metacharacters in the media directory can execute script in the browser of a backend user with media[sync] permission when that user opens the Sync page, enabling session theft or unauthorized backend actions. This issue is fixed in version 5.21.2.
Gravedad CVSS v3.1: MEDIA
Última modificación:
23/09/2026

CVE-2026-63001

Fecha de publicación:
23/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** REDAXO is a PHP-based content management system. Prior to 5.21.2, the mediaIsInUse() handler in redaxo/src/addons/media_manager/lib/media_manager.php inserts a Media Manager type name into raw backend warning HTML without escaping it when invoked through MEDIA_IS_IN_USE. An administrator with Media Manager access can store HTML in a type name, and the payload executes in another administrator's browser when that administrator tries to delete media referenced by the type's effects, enabling session theft or unauthorized backend actions. This issue is fixed in version 5.21.2.
Gravedad CVSS v3.1: MEDIA
Última modificación:
23/09/2026

CVE-2026-61413

Fecha de publicación:
23/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
Gravedad CVSS v3.1: MEDIA
Última modificación:
23/09/2026

CVE-2026-55610

Fecha de publicación:
23/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates. Prior to version 2.4.1, in InvoiceShelf's multi-company installations, any user who is an Owner of one company can read and overwrite any user account in any other company on the same installation. `GET/PUT /api/v1/users/{user}` resolves the target `User` by global primary key, and `UserPolicy` checks only that the requester owns their own header-company — it never verifies that the target user belongs to that company. This allows cross-tenant disclosure of user data and full account takeover (email/password overwrite + company re-assignment). Version 2.4.1 fixes the issue.
Gravedad CVSS v3.1: ALTA
Última modificación:
23/09/2026

CVE-2026-96560

Fecha de publicación:
23/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** LightLLM through 1.2.0 contains a remote code execution vulnerability in the KV-transfer worker when started with --pd_trans_mode nccl, which exposes an unauthenticated RPyC control channel that deserializes attacker-supplied data. Attackers can send malicious pickled objects to the exposed RPyC ThreadedServer to execute arbitrary code with the privileges of the LightLLM service account.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
23/09/2026

CVE-2026-96559

Fecha de publicación:
23/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Rejected reason: This ID was for testing
Gravedad: Pendiente de análisis
Última modificación:
23/09/2026

CVE-2026-96512

Fecha de publicación:
23/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in sudo. When sudoers rules use NOTBEFORE or NOTAFTER time-based access restrictions with timestamps that omit the trailing 'Z' timezone indicator, the time evaluation relies on the TZ environment variable inherited from the calling user. Because sudo is a setuid-root program, an unprivileged local user can set TZ to an extreme timezone offset to shift the authorization window by up to approximately 25 hours, causing expired rules to be treated as valid. This allows the user to execute commands outside the intended time window. Authentication is not bypassed; only the time-based authorization check is affected.
Gravedad CVSS v3.1: ALTA
Última modificación:
23/09/2026

CVE-2026-86679

Fecha de publicación:
23/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** ZohoCorp ManageEngine Applications Manager versions 182000 and below were vulnerable to a permissions validation issue that allowed a low-privileged user to delete service monitors outside their assigned scope.
Gravedad CVSS v3.1: ALTA
Última modificación:
23/09/2026

CVE-2026-86681

Fecha de publicación:
23/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to a permissions validation issue that allowed low-privileged users to execute administrator-configured MBean actions on monitors outside their assigned scope.
Gravedad CVSS v3.1: ALTA
Última modificación:
23/09/2026

CVE-2026-86683

Fecha de publicación:
23/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to change the proxy settings.
Gravedad CVSS v3.1: ALTA
Última modificación:
23/09/2026

CVE-2026-86708

Fecha de publicación:
23/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could allow an unauthenticated attacker to impersonate the service account and access or modify associated cloud resources.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
23/09/2026