Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-48911

Fecha de publicación:
05/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Insufficient Verification of Data Authenticity vulnerability in Apache Answer.<br /> <br /> This issue affects Apache Answer: through 2.0.1.<br /> <br /> A missing authorization check in the external-login email binding flow allows unauthenticated attackers to take over arbitrary user accounts by tricking victims into clicking a crafted confirmation link.<br /> Users are recommended to upgrade to version 2.0.2, which fixes the issue.
Gravedad CVSS v3.1: ALTA
Última modificación:
06/08/2026

CVE-2026-49331

Fecha de publicación:
05/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in openshift/oauth-proxy. On paths configured to bypass authentication (skip-auth-regex), the proxy forwards client-supplied identity headers (X-Forwarded-User, X-Forwarded-Email, X-Forwarded-Access-Token) to the upstream application without stripping them. An unauthenticated attacker can inject forged identity headers on whitelisted paths.
Gravedad CVSS v3.1: MEDIA
Última modificación:
06/08/2026

CVE-2026-39924

Fecha de publicación:
05/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers who hold a valid session token to retain full account access after a victim changes their password, because the access_tokens table is never cleared on password change events. The TokensClearer::clearPasswordTokens() function only removes rows from the password_tokens table while leaving all active session cookies and API bearer tokens intact, including long-lived RememberAccessToken entries, and administrator-forced password resets via the user update endpoint are equally ineffective at revoking attacker-held sessions.
Gravedad CVSS v4.0: ALTA
Última modificación:
05/08/2026

CVE-2026-48834

Fecha de publicación:
05/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer.<br /> <br /> This issue affects Apache Answer: through 2.0.1.<br /> <br /> Unauthenticated attackers can cause a denial of service via a specially crafted Accept-Language header that triggers excessive CPU consumption during parsing.<br /> Users are recommended to upgrade to version 2.0.2, which fixes the issue.
Gravedad CVSS v3.1: ALTA
Última modificación:
06/08/2026

CVE-2026-39923

Fecha de publicación:
05/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Flarum before 1.8.16 contains a password reset token expiry bypass vulnerability that allows unauthenticated attackers to reuse expired password reset tokens by submitting them directly to the reset processing endpoint. The SavePasswordController::handle() method calls PasswordToken::findOrFail() without performing any expiry validation, allowing attackers to bypass the 24-hour token lifetime enforced only during form rendering and change any account&amp;#39;s password to gain an authenticated session.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
05/08/2026

CVE-2026-32835

Fecha de publicación:
05/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Gravedad: Pendiente de análisis
Última modificación:
05/08/2026

CVE-2026-18531

Fecha de publicación:
05/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use of a weak HMAC session signing secret.
Gravedad CVSS v3.1: MEDIA
Última modificación:
10/08/2026

CVE-2026-16442

Fecha de publicación:
05/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a provider is restricted to account linking only. This allows an attacker with control over a linked upstream identity to bypass login restrictions and gain full access to a local user account.
Gravedad CVSS v3.1: ALTA
Última modificación:
10/08/2026

CVE-2026-15587

Fecha de publicación:
05/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to escalate privileges to system-level administrative access using a crafted internal authentication header.<br /> <br /> <br /> <br /> <br /> This vulnerability was patched with version 6.3.85, and no customer action is needed.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
05/08/2026

CVE-2026-15656

Fecha de publicación:
05/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.
Gravedad CVSS v3.1: MEDIA
Última modificación:
10/08/2026

CVE-2026-15572

Fecha de publicación:
05/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in Keycloak&amp;#39;s Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Types" policy, which restricts which types of data mappers a client can use, fails to re-validate the mapper type during a client update if the mapper&amp;#39;s configuration remains unchanged. An attacker with client registration privileges can exploit this by first registering an allowed mapper type with a malicious configuration and then swapping it for a restricted, high-privilege mapper type (such as one that hardcodes administrative roles). This allows the attacker to gain full administrative access to the Keycloak realm.
Gravedad CVSS v3.1: ALTA
Última modificación:
10/08/2026

CVE-2026-13477

Fecha de publicación:
05/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input.
Gravedad CVSS v3.1: MEDIA
Última modificación:
10/08/2026