Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-45072

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.4.24 until 6.4.40, 7.4.12, and 8.0.12, the development profiler file_excerpt Twig filter escapes PHP files through highlight_string() but interpolates lines from non-PHP files directly into elements, allowing stored XSS against a developer who opens an attacker-written file such as var/log/dev.log in the profiler. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.
Gravedad CVSS v4.0: BAJA
Última modificación:
16/07/2026

CVE-2026-45063

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, X509Authenticator extracts the user identifier from $_SERVER['SSL_CLIENT_S_DN'] with an unanchored regex that matches emailAddress= anywhere in the distinguished name, allowing an attacker with a trusted certificate containing emailAddress=victim inside another RDN value such as CN to authenticate as the victim. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
15/07/2026

CVE-2026-45064

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, UrlSanitizer::parse() passes Unicode explicit-direction BiDi formatting characters through into sanitized href and src attributes, allowing sanitized content to display a link destination that visually differs from the actual destination and enabling phishing-style visual spoofing. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.
Gravedad CVSS v4.0: BAJA
Última modificación:
21/07/2026

CVE-2026-15642

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Insertion of sensitive information into a file in the Recovery Kit response file generation feature in Devolutions Server 2026.1.22.0, 2026.2.11.0 allows an attacker with access to the generated response file to obtain the Azure Key Vault client secret in cleartext, even when the option to exclude sensitive data is selected.
Gravedad CVSS v3.1: BAJA
Última modificación:
15/07/2026

CVE-2026-15712

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A heap buffer over-read vulnerability was discovered in libsoup's (versions: libsoup 3.0 to 3.7.0) HTTP/2 connection tracking framework. When the library processes an HTTP/2 GOAWAY frame, it improperly handles the "Additional Debug Data" payload by assuming the data stream is a safely NUL-terminated C-string. Because the parser lacks strict length-boundary verification before reading this data, a remote, unauthenticated attacker can intentionally send a malformed GOAWAY frame missing the appropriate null delimiter. This causes the library to read past the end of the allocated buffer, triggering an application crash that results in a denial of service (DoS), or potentially exposing fragments of memory contents.
Gravedad CVSS v3.1: MEDIA
Última modificación:
15/07/2026

CVE-2026-15720

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** In Open5GS through version 2.7.7 a pre-authentication heap out-of-bounds read in the AMF NAS 5GS mobile-identity handler may result in subscriber-wide denial of service.
Gravedad CVSS v3.1: ALTA
Última modificación:
15/07/2026

CVE-2026-15641

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to approve their own pending access request via a direct call to the request status endpoint, bypassing the required approver review.
Gravedad CVSS v3.1: ALTA
Última modificación:
30/07/2026

CVE-2026-15637

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper authorization in the PAM SSH key and certificate retrieval <br /> endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an <br /> authenticated low-privileged user to disclose the private key of an SSH <br /> key or certificate PAM credential via a direct object reference to the <br /> credential identifier.
Gravedad CVSS v3.1: ALTA
Última modificación:
30/07/2026

CVE-2026-15058

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper authorization in the secure messages deletion endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated user to delete another user&amp;#39;s messages via a direct object reference to the message identifier.
Gravedad CVSS v3.1: BAJA
Última modificación:
30/07/2026

CVE-2026-62658

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A security flaw was discovered in certain NETGEAR Nighthawk RAX series routers<br /> that could allow someone already logged in to the device to run unauthorized commands<br /> or code on the router.
Gravedad CVSS v4.0: MEDIA
Última modificación:
15/07/2026

CVE-2026-62659

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A<br /> security flaw was discovered in the NETGEAR WAX333 Access Point that could<br /> allow someone already logged in and connected to the local network to make<br /> unauthorized changes to the device&amp;#39;s settings
Gravedad CVSS v4.0: MEDIA
Última modificación:
15/07/2026

CVE-2026-62655

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A<br /> security flaw was found in certain NETGEAR Orbi models that<br /> could allow an unauthorized user to cause the device to stop responding or<br /> restart unexpectedly, disrupting network connectivity and making the device<br /> temporarily unavailable.
Gravedad CVSS v4.0: MEDIA
Última modificación:
15/07/2026