Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-17630

Fecha de publicación:
05/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary code due to improper validation of configuration parameters.
Gravedad CVSS v3.1: ALTA
Última modificación:
07/08/2026

CVE-2026-17617

Fecha de publicación:
05/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specified in custom resources.
Gravedad CVSS v3.1: ALTA
Última modificación:
10/08/2026

CVE-2026-14587

Fecha de publicación:
05/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Neo4j&amp;#39;s Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask. When an unauthenticated client sends a selected protocol version followed by 32 continuation bytes in the capability mask, the decoder resets the reader index and waits for more bytes instead of rejecting the protocol message and closing the channel.<br /> <br /> <br /> <br /> Because the same unread bytes remain at the front of the decoder buffer, appending a terminating byte later does not recover the connection. The decoder re-reads the same first 32 continuation bytes, returns without producing a handshake-finalization message, and leaves the channel open.<br /> <br /> <br /> <br /> This can be triggered before authentication by any client that can reach the Bolt connector.
Gravedad CVSS v4.0: MEDIA
Última modificación:
19/08/2026

CVE-2026-9195

Fecha de publicación:
05/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a crafted URL to execute arbitrary JavaScript in the administrator&amp;#39;s browser session, capture credentials, and perform privileged actions on the administrator&amp;#39;s behalf.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
05/08/2026

CVE-2026-9192

Fecha de publicación:
05/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, including administrators.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
07/08/2026

CVE-2026-9193

Fecha de publicación:
05/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations against the Security database.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
07/08/2026

CVE-2026-9203

Fecha de publicación:
05/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protections for cloud instance metadata endpoints. Successful exploitation can disclose cloud credentials and compromise cloud resources accessible to the host instance.
Gravedad CVSS v3.1: ALTA
Última modificación:
07/08/2026

CVE-2026-7327

Fecha de publicación:
05/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with an administrative REST role to escalate privileges. This can result in unauthorized disclosure of sensitive server-side data when it is accessed by a higher-privileged user.
Gravedad CVSS v3.1: ALTA
Última modificación:
07/08/2026

CVE-2026-7329

Fecha de publicación:
05/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges to administrator. This enables execution of privileged operations and unauthorized data access.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
07/08/2026

CVE-2026-7557

Fecha de publicación:
05/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
07/08/2026

CVE-2026-8709

Fecha de publicación:
05/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges and execute privileged operations against the Security database.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
07/08/2026

CVE-2026-9190

Fecha de publicación:
05/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication and authorization checks, hijack a legitimate user&amp;#39;s session, or capture credentials. The vulnerability occurs when a crafted HTTP request containing both Content-Length and Transfer-Encoding headers causes a reverse proxy and MarkLogic Server to interpret request boundaries differently.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
07/08/2026