Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-17048

Fecha de publicación:
24/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. Due to improper boundary enforcement, a delegated administrator with view-only permissions can retrieve the actual resolved secret instead of the vault placeholder, leading to the exposure of sensitive credentials.
Gravedad CVSS v3.1: MEDIA
Última modificación:
24/07/2026

CVE-2026-9765

Fecha de publicación:
24/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Note: The CVE and blog post don&amp;#39;t exist because we determined this is actually a cloud-only issue.<br /> <br /> Access Controls are “Broken” when a user can access resources they are not authorized to access. An attacker can bypass any access control mechanisms in a web application, and gain unauthorized access to resources that are not available with their permissions. <br /> <br /> Broken access control can allow attackers to:<br /> Access resources only accessible to certain users, thus allowing unauthorized access to data<br /> Perform operations on behalf of other users, leading to account takeovers in the worst cases<br /> Attempt privilege escalation<br /> Attempt to take over an account
Gravedad CVSS v3.1: ALTA
Última modificación:
30/07/2026

CVE-2026-7484

Fecha de publicación:
24/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** External control of Assumed-Immutable web parameter vulnerability in ABIS Technology Ltd. Co. AVESİS allows Accessing Functionality Not Properly Constrained by ACLs.<br /> <br /> This issue affects AVESİS: before 202606251646.
Gravedad CVSS v3.1: MEDIA
Última modificación:
24/07/2026

CVE-2026-66144

Fecha de publicación:
24/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API it can cause a denial of service attack if a huge policy is retrieved. Users are recommended to upgrade to version 3.2.3, which fixes this issue by imposing a default maximum size on data read from remote policy references.
Gravedad CVSS v3.1: ALTA
Última modificación:
27/07/2026

CVE-2026-66143

Fecha de publicación:
24/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies, which may lead to a denial of service attack via resource consumption. Users are recommended to upgrade to version 3.2.3, which fixes this issue.
Gravedad CVSS v3.1: ALTA
Última modificación:
27/07/2026

CVE-2026-66142

Fecha de publicación:
24/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to a denial of service attack when parsing policies due to runtime memory exhaustion. Users are recommended to upgrade to version 3.2.3, which fixes this issue.
Gravedad CVSS v3.1: ALTA
Última modificación:
27/07/2026

CVE-2026-66008

Fecha de publicación:
24/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Parse Server versions &gt;= 9.0.0 before 9.10.0-alpha.6 and &gt;= 8.2.2 before 8.6.87 disclose Pointer and Relation target class names through GraphQL validation and input-coercion error messages when public schema introspection is disabled (graphQLPublicIntrospection: false, the default). Because these errors are produced before authentication, authorization, or any resolver runs, an unauthenticated client possessing only the public application ID can trigger errors on Pointer or Relation fields to reconstruct hidden schema class names, partially defeating the schema-hiding protection. Only schema metadata (class names) is exposed; no object data, credentials, or user records are disclosed.
Gravedad CVSS v4.0: MEDIA
Última modificación:
27/07/2026

CVE-2026-66009

Fecha de publicación:
24/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Parse Server versions &gt;= 9.0.0 before 9.10.0-alpha.5 and &gt;= 8.2.2 before 8.6.86 return GraphQL validation error messages that name required custom input fields even when public introspection is disabled (graphQLPublicIntrospection: false, the default). A client holding only the public application id — with no user session, master key, or maintenance key — can trigger validation errors to learn the names of required (non-null) custom fields on classes it already references by name, partially defeating the schema-hiding intent of disabling public introspection. No stored data, credentials, optional field names, unreferenced class names, or Cloud Code function names are exposed.
Gravedad CVSS v4.0: MEDIA
Última modificación:
30/07/2026

CVE-2026-66010

Fecha de publicación:
24/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies. Attackers can preserve sensitive attributes on custom elements that later re-inject them into innerHTML sinks, creating second-order XSS gadgets.
Gravedad CVSS v4.0: MEDIA
Última modificación:
06/08/2026

CVE-2026-46452

Fecha de publicación:
24/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Input Validation vulnerability in Apache NimBLE in Mesh Proxy SAR reassembly could result in passing broken data toward application resulting in memory pressure and unstable parsing behavior.<br /> <br /> This issue affects Apache NimBLE: through 1.9.0.<br /> <br /> Users are recommended to upgrade to version 1.10.0, which fixes the issue.
Gravedad CVSS v3.1: MEDIA
Última modificación:
27/07/2026

CVE-2026-45816

Fecha de publicación:
24/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event.<br /> <br /> This requires disabled asserts (otherwise assert would trigger before NULL dereference) and bogus (or misbehaving) controller, thus severity is low.<br /> <br /> This issue affects Apache NimBLE: through 1.9.0.<br /> <br /> Users are recommended to upgrade to version 1.10.0, which fixes the issue.
Gravedad CVSS v3.1: ALTA
Última modificación:
27/07/2026

CVE-2026-45815

Fecha de publicación:
24/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Reachable Assertion vulnerability in Apache NimBLE.<br /> A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_READ_MULT_VAR_RSP) may trigger assert in ATT parser.<br /> <br /> Severity is medium as this requires DUT to first send ATT Read Multiple Variable Request.<br /> <br /> This issue affects Apache NimBLE: through 1.9.0.<br /> <br /> Users are recommended to upgrade to version 1.10.0, which fixes the issue.
Gravedad CVSS v3.1: ALTA
Última modificación:
27/07/2026