Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-78253

Fecha de publicación:
23/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Uncontrolled recursion in QXmlStreamReader::readElementText() in Qt Group Qt allows attackers to cause a denial of service (application crash via stack exhaustion) via a crafted XML document.
Gravedad CVSS v4.0: BAJA
Última modificación:
23/09/2026

CVE-2026-80444

Fecha de publicación:
23/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** URL redirection to untrusted site (&amp;#39;open redirect&amp;#39;) vulnerability in Abis Technology Ltd. Co. AVESİS allows Input Data Manipulation.<br /> <br /> This issue affects AVESİS: from 202608201331 before 202608240351.
Gravedad CVSS v3.1: MEDIA
Última modificación:
23/09/2026

CVE-2026-84787

Fecha de publicación:
23/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Privilege Escalation vulnerability that allowed an authenticated low-privilege user to gain Administrator privileges through Report Profile import.
Gravedad CVSS v3.1: ALTA
Última modificación:
23/09/2026

CVE-2026-84789

Fecha de publicación:
23/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to create alert notifications for firewalls outside their assigned scope.
Gravedad CVSS v3.1: ALTA
Última modificación:
23/09/2026

CVE-2026-78383

Fecha de publicación:
23/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Allocation of resources without limits or throttling vulnerability in Apache Tomcat allows an unauthenticated AJP request to pin an AJP processing thread leading to denial of service.<br /> <br /> <br /> <br /> This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M1 through 9.0.121.<br /> <br /> <br /> <br /> The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected.<br /> <br /> <br /> <br /> Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.
Gravedad CVSS v3.1: ALTA
Última modificación:
23/09/2026

CVE-2026-78437

Fecha de publicación:
23/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Incomplete cleanup vulnerability in Apache Tomcat allows a malformed request to potentially (depends on timing) cause one request from another user to fail.<br /> <br /> <br /> <br /> This issue affects Apache Tomcat: from 11.0.19 through 11.0.25, from 10.1.53 through 10.1.59, from 9.0.116 through 9.0.121.<br /> <br /> <br /> <br /> Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.
Gravedad CVSS v3.1: ALTA
Última modificación:
23/09/2026

CVE-2026-79677

Fecha de publicación:
23/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Missing release of resource after effective lifetime, Comparison using wrong factors vulnerability in Apache Tomcat allows a denial of service as a result of lost time outs for asynchronous WebSocket writes.<br /> <br /> <br /> <br /> This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M1 through 9.0.121.<br /> <br /> <br /> <br /> The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected.<br /> <br /> <br /> <br /> Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.
Gravedad CVSS v3.1: ALTA
Última modificación:
23/09/2026

CVE-2026-73581

Fecha de publicación:
23/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Check for Certificate Revocation vulnerability in Apache Tomcat. Both the OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore.<br /> <br /> <br /> <br /> This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.58, from 9.0.0-M1 through 9.0.121.<br /> <br /> <br /> <br /> The following versions were EOL at the time the CVE was created but are <br /> known to be affected: from 8.5.0 through 8.5.100. Other unsupported versions may also be affected.<br /> <br /> <br /> <br /> Users are recommended to upgrade to version 11.0.26, 10.1.59, 9.0.122, which fixes the issue.
Gravedad CVSS v3.1: MEDIA
Última modificación:
23/09/2026

CVE-2026-75973

Fecha de publicación:
23/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Authentication vulnerability in Apache Tomcat. When Jakarta Authentication was configured with SimpleAuthConfigProvider as the default provider and multiple web application used that provider, the realm for the first web application to authenticate a request would be used for all web applications.<br /> <br /> <br /> <br /> This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M4 through 9.0.121.<br /> <br /> <br /> <br /> The following versions were EOL at the time the CVE was created but are <br /> known to be affected: from 8.5.0 through 8.5.100. Other unsupported versions may also be affected.<br /> <br /> <br /> <br /> <br /> Users are recommended to upgrade to version 11.0.26, 10.1.60, 9.0.122, which fixes the issue.
Gravedad CVSS v3.1: ALTA
Última modificación:
23/09/2026

CVE-2026-76183

Fecha de publicación:
23/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Authentication Bypass by Alternate Name vulnerability in Apache Tomcat allowed the security constraints for any WebSocket endpoint to be bypassed.<br /> <br /> <br /> <br /> This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M1 through 9.0.121.<br /> <br /> <br /> <br /> The following versions were EOS at the time the CVE was created but are <br /> known to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected.<br /> <br /> <br /> <br /> <br /> Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
23/09/2026

CVE-2026-77756

Fecha de publicación:
23/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Inconsistent Interpretation of HTTP Requests (&amp;#39;HTTP Request/Response Smuggling&amp;#39;) vulnerability in Apache Tomcat caused by processing the transfer-encoding header for an HTTP/1.0 request may allow an attacker to cause one request from another user to fail when Tomcat is located behind a reverse proxy.<br /> <br /> <br /> <br /> This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.47 through 9.0.121.<br /> <br /> <br /> <br /> The following versions were EOL at the time the CVE was created but are <br /> known to be affected: from 8.5.67 through 8.5.100. Other unsupported versions may also be affected.<br /> <br /> <br /> <br /> Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.
Gravedad CVSS v3.1: BAJA
Última modificación:
23/09/2026

CVE-2026-77762

Fecha de publicación:
23/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Concurrent Execution using Shared Resource with Improper Synchronization (&amp;#39;Race Condition&amp;#39;) vulnerability in Apache Tomcat allows an attacker to inject trailer fields into another HTTP/2 request.<br /> <br /> <br /> <br /> This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.39 through 9.0.121.<br /> <br /> <br /> <br /> The following versions were EOL at the time the CVE was created but are <br /> known to be affected: from 8.5.59 through 8.5.100. Other unsupported versions may also be affected.<br /> <br /> <br /> <br /> <br /> Users are recommended to upgrade to version 11.0.26, 10.1.60, 9.0.122, which fix the issue.
Gravedad CVSS v3.1: ALTA
Última modificación:
23/09/2026