Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-0284

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corruption of internal LSVPN satellite data.<br /> <br /> Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.
Gravedad CVSS v4.0: MEDIA
Última modificación:
13/07/2026

CVE-2026-0283

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An authentication bypass vulnerability in Large Scale VPN ( LSVPN) functionality of Palo Alto Networks PAN-OS software allows an attacker with network access to bypass security restrictions and establish an unauthorized site-to-site VPN connection.<br /> <br /> Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.
Gravedad CVSS v4.0: MEDIA
Última modificación:
13/07/2026

CVE-2026-0282

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A file deletion vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web interface to delete files from a temporary directory.<br /> <br /> The security risk posed by this issue is minimized by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .<br /> <br /> This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).<br /> <br /> Cloud NGFW and Prisma® Access are not impacted by this vulnerability.
Gravedad CVSS v4.0: BAJA
Última modificación:
13/07/2026

CVE-2026-0281

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web interface to obtain web session tokens. This requires a legitimate user to first click on a malicious link provided by the attacker.<br /> <br /> The security risk posed by this issue is minimized by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .<br /> <br /> This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).<br /> <br /> Cloud NGFW and Prisma® Access are not impacted by this vulnerability.
Gravedad CVSS v4.0: BAJA
Última modificación:
13/07/2026

CVE-2026-0280

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to bypass firewall security policy enforcement, allowing network traffic that should be blocked to reach protected services.<br /> <br /> Cloud NGFW and Panorama are not impacted by this vulnerability.
Gravedad CVSS v4.0: BAJA
Última modificación:
13/07/2026

CVE-2026-0279

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Multiple cross site scripting vulnerabilities in the User-ID™ Authentication Portal (aka Captive Portal) service, GlobalProtect™ gateway/portal features and Clientless VPN of Palo Alto Networks PAN-OS® software enables a malicious unauthenticated user to store or execute malicious JavaScript payload.<br /> <br /> <br /> The security risk posed by this issue is minimized when the management interface and access to the User-ID™ Authentication Portal is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .<br /> <br /> This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).<br /> <br /> Cloud NGFW is not affected by this vulnerability.
Gravedad CVSS v4.0: BAJA
Última modificación:
13/07/2026

CVE-2025-63579

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Unauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The security measure that encrypts incoming data ian be bypassed with this vulnerability, allowing encrypted data to be decrypted. Passwords and other sensitive information can be obtained. This affects Kyocera Command Center RX TASKalfa 2552ci, TASKalfa 3252ci, TASKalfa 2553ci, TASKalfa 3253ci, TASKalfa 3554ci, TASKalfa 4052ci, TASKalfa 5052ci, TASKalfa 6052ci, TASKalfa 7052ci, TASKalfa 8052ci, TASKalfa 7353ci, TASKalfa 8353ci, TASKalfa 2554ci, TASKalfa 3254ci, TASKalfa 505.
Gravedad CVSS v3.1: ALTA
Última modificación:
10/07/2026

CVE-2026-61344

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Superior Court of California Hearing Reminder Service at https://www.hrs.courts.ca.gov exposes an API endpoint that returns court reminder records containing potentially sensitive information without authentication.
Gravedad CVSS v4.0: MEDIA
Última modificación:
21/07/2026

CVE-2026-61343

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** LibreBooking&amp;#39;s email template editor save action passes the submitted template name directly into the destination file path, allowing a remote attacker with administrator credentials to write an arbitrary file outside the template directory and execute code. Fixed in 5.1.0.
Gravedad CVSS v4.0: ALTA
Última modificación:
30/07/2026

CVE-2026-59734

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, Coolify&amp;#39;s app/Jobs/ApplicationDeploymentJob.php generate_healthcheck_commands() function directly interpolated the health_check_host, health_check_method, and health_check_path parameters into shell commands without proper sanitization, allowing authenticated users to execute arbitrary commands inside deployment containers. This issue is fixed in version 4.0.0-beta.469.
Gravedad CVSS v3.1: ALTA
Última modificación:
09/07/2026

CVE-2026-59720

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, mock server creation in mock-server.service.ts does not persist the isPublic input field while schema.prisma defaults isPublic to true, causing mock servers linked to private collections to be publicly accessible without authentication and potentially expose sensitive API data. This issue is fixed in version 2026.6.0.
Gravedad CVSS v3.1: ALTA
Última modificación:
10/07/2026

CVE-2026-59721

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the updateInfraConfigs GraphQL mutation in admin/infra.resolver.ts accepts an attacker-controlled MAILER_SMTP_URL value, and validateSMTPUrl in utils.ts permits path, query, or fragment content that nodemailer parses into sendmail transport options, allowing an admin to execute arbitrary commands as root in the backend container after restart and mail sending. This issue is fixed in version 2026.6.0.
Gravedad CVSS v3.1: ALTA
Última modificación:
10/07/2026