Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-66009

Fecha de publicación:
24/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Parse Server versions >= 9.0.0 before 9.10.0-alpha.5 and >= 8.2.2 before 8.6.86 return GraphQL validation error messages that name required custom input fields even when public introspection is disabled (graphQLPublicIntrospection: false, the default). A client holding only the public application id — with no user session, master key, or maintenance key — can trigger validation errors to learn the names of required (non-null) custom fields on classes it already references by name, partially defeating the schema-hiding intent of disabling public introspection. No stored data, credentials, optional field names, unreferenced class names, or Cloud Code function names are exposed.
Gravedad CVSS v4.0: MEDIA
Última modificación:
30/07/2026

CVE-2026-66010

Fecha de publicación:
24/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies. Attackers can preserve sensitive attributes on custom elements that later re-inject them into innerHTML sinks, creating second-order XSS gadgets.
Gravedad CVSS v4.0: MEDIA
Última modificación:
30/07/2026

CVE-2026-46452

Fecha de publicación:
24/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Input Validation vulnerability in Apache NimBLE in Mesh Proxy SAR reassembly could result in passing broken data toward application resulting in memory pressure and unstable parsing behavior.<br /> <br /> This issue affects Apache NimBLE: through 1.9.0.<br /> <br /> Users are recommended to upgrade to version 1.10.0, which fixes the issue.
Gravedad CVSS v3.1: MEDIA
Última modificación:
27/07/2026

CVE-2026-45816

Fecha de publicación:
24/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event.<br /> <br /> This requires disabled asserts (otherwise assert would trigger before NULL dereference) and bogus (or misbehaving) controller, thus severity is low.<br /> <br /> This issue affects Apache NimBLE: through 1.9.0.<br /> <br /> Users are recommended to upgrade to version 1.10.0, which fixes the issue.
Gravedad CVSS v3.1: ALTA
Última modificación:
27/07/2026

CVE-2026-45815

Fecha de publicación:
24/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Reachable Assertion vulnerability in Apache NimBLE.<br /> A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_READ_MULT_VAR_RSP) may trigger assert in ATT parser.<br /> <br /> Severity is medium as this requires DUT to first send ATT Read Multiple Variable Request.<br /> <br /> This issue affects Apache NimBLE: through 1.9.0.<br /> <br /> Users are recommended to upgrade to version 1.10.0, which fixes the issue.
Gravedad CVSS v3.1: ALTA
Última modificación:
27/07/2026

CVE-2026-45813

Fecha de publicación:
24/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service.<br /> Improper validation when parsing BASS service  "Add Source" and "Modify Source" operation PDU could results in stack buffer overflow or arbitrary out-of-bound read.<br /> <br /> <br /> This can be triggered by nearby devices over Bluetooth connection, however pairing is required prior to accessing BASS service, which depending on device configuration may or may not require user action.<br /> <br /> This issue affects Apache NimBLE: through 1.9.0.<br /> <br /> Users are recommended to upgrade to version 1.10.0, which fixes the issue.
Gravedad CVSS v3.1: ALTA
Última modificación:
27/07/2026

CVE-2026-45812

Fecha de publicación:
24/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Incorrect Calculation of Buffer Size vulnerability in Apache NimBLE when processing Legacy Advertising Report HCI event.<br /> <br /> When a single HCI advertising report event bundles multiple reports, NimBLE miscalculated the offset to the next report. This can cause the host to read past the end of the buffer and deliver a GAP event with bogus data to the application.<br /> <br /> Severity is low: NimBLE&amp;#39;s own controller never batches multiple reports into one event, so this only matters when NimBLE&amp;#39;s host is paired with a third-party controller that does.<br /> <br /> This issue affects Apache NimBLE: through 1.9.0.<br /> <br /> Users are recommended to upgrade to version 1.10.0, which fixes the issue.
Gravedad CVSS v3.1: MEDIA
Última modificación:
27/07/2026

CVE-2026-45811

Fecha de publicación:
24/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Buffer Copy without Checking Size of Input (&amp;#39;Classic Buffer Overflow&amp;#39;) vulnerability in Apache NimBLE.<br /> The HCI socket transport did not check whether a received HCI event would fit the configured event pool before copying it, allowing a buffer overflow. Severity is low: exploitation requires either a misconfigured pool size or a malicious/compromised controller on the other end of the HCI socket link, not over-the-air Bluetooth access.<br /> <br /> This issue affects Apache NimBLE: through 1.9.0.<br /> <br /> Users are recommended to upgrade to version 1.10.0, which fixes the issue.
Gravedad CVSS v3.1: ALTA
Última modificación:
27/07/2026

CVE-2026-16743

Fecha de publicación:
24/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user-supplied filename as root without the validation and privilege drop performed by the classic handler. A local attacker with a systemd-homed-managed account can read arbitrary files accessible to the accounts-daemon process.
Gravedad CVSS v3.1: MEDIA
Última modificación:
24/07/2026

CVE-2026-16730

Fecha de publicación:
24/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. A local attacker who can open many connections to the user session bus can trigger this and deny service to the desktop session. Flatpak applications can reach the host session bus through the dbus proxy.
Gravedad CVSS v3.1: MEDIA
Última modificación:
24/07/2026

CVE-2026-15810

Fecha de publicación:
24/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A Cross-Site Scripting (XSS) vulnerability in Google Cloud Looker versions prior to 25.6.103, 25.12.65, 25.18.68, 26.0.66, 26.2.47, 26.4.36, 26.6.28, and 26.8.7 on Looker-hosted and Self-hosted allows an attacker to execute arbitrary JavaScript leading to administrative account takeover using a maliciously crafted URL.<br /> <br /> <br /> Looker-hosted and Self-hosted were found to be vulnerable.<br /> This issue has already been mitigated for Looker-hosted instances. No user action is required for these.<br /> <br /> <br /> Self-hosted instances must be upgraded to the patched versions: 25.6.103+, 25.12.65+, 25.18.68+, 26.0.66+, 26.2.47+, 26.4.36+, 26.6.28+, or 26.8.7+.
Gravedad CVSS v4.0: ALTA
Última modificación:
27/07/2026

CVE-2026-15243

Fecha de publicación:
24/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Apereo CAS Client accepts any CA-trusted certificate for any hostname, provided the URL the client is calling matches the configured allowlist or regex. An attacker with a MITM position (DNS poisoning, rogue Wi-Fi, malicious proxy, etc.) can provide any CA-signed certificate for a hostname that matches the configured allowlist or regex. This can lead to intercepting the CAS exchange, capturing the Ticket-Granting Ticket (TGT), and subsequently obtaining Service Tickets on behalf of the victim. <br /> <br /> <br /> Because maintainers contact attempts were unsuccessful, vulnerabilities have only been confirmed in version 4.1.0 (Java Apereo CAS Client) and 3.6.4 (Jasig CAS Client) but may also affect other versions.
Gravedad CVSS v4.0: ALTA
Última modificación:
30/07/2026