Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-77634

Fecha de publicación:
24/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** CakePHP is a rapid development framework for PHP. Prior to versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7 on their respective release lines, custom mail headers added with Message::setHeaders() or Message::addHeaders() do not have CRLF bytes removed, allowing header injection when user-controlled data is used in message headers. This issue is fixed in versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7.
Gravedad CVSS v4.0: ALTA
Última modificación:
24/08/2026

CVE-2026-75464

Fecha de publicación:
24/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** OneNav 1.2.4 contains an authenticated arbitrary file deletion vulnerability via import_link().
Gravedad: Pendiente de análisis
Última modificación:
24/08/2026

CVE-2026-75542

Fecha de publicación:
24/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Incorrect Authorization vulnerability in the OAuth token endpoint in hexpm hexpm allows an API key holding the repositories permission to read another organization&amp;#39;s private packages.<br /> <br /> When an API key is exchanged for a token through the OAuth client_credentials grant, validate_scopes_against_key/2 in lib/hexpm_web/controllers/api/oauth_controller.ex admits a requested scope whenever the key carries the repositories permission and the scope string begins with repository:. The organization name is never resolved against the principal, and expand_repositories_scope/3 only rewrites the literal repositories scope, so an explicit repository: passes through untouched. Both CDN edges authorize repository access from the token claim without querying the database, so the minted token is read access to that organization&amp;#39;s private packages until it expires.<br /> <br /> This issue affects hex.pm: from 2025-10-18 before 2026-08-24.
Gravedad CVSS v4.0: ALTA
Última modificación:
24/08/2026

CVE-2026-75554

Fecha de publicación:
24/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Insufficient Session Expiration vulnerability in the OAuth token refresh grant in hexpm hexpm allows a user removed from an organization to keep reading its private packages.<br /> <br /> expand_repositories_scope/3 in lib/hexpm/permissions.ex only rewrites the literal repositories scope, so an explicitly granted repository: or docs: scope passes through it untouched. The refresh grant re-derives a new token from the stored granted_scopes, which holds that expanded form, so every refresh reproduces the organization scope without revisiting membership. Because both CDN edges authorize repository access from the token claim without querying the database, an account removed from an organization retains read access for as long as it keeps refreshing, bounded by the 30 day refresh token lifetime rather than the 30 minute access token lifetime.<br /> <br /> This issue affects hex.pm: from 2025-10-10 before 2026-08-24.
Gravedad CVSS v4.0: BAJA
Última modificación:
24/08/2026

CVE-2026-5006

Fecha de publicación:
24/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability was identified in HashiCorp Vault and Vault Enterprise (“Vault”) such that an authenticated attacker may manipulate an identity value referenced by a templated policy path to gain unintended access to Vault paths.<br /> <br /> An attacker who can control the referenced identity value may include slash ({{/}}) characters that Vault interprets as additional path segments when rendering the policy.<br /> <br /> This vulnerability, CVE-2026-5006, was fixed in Vault Community Edition 2.0.4 and Vault Enterprise 2.0.4, 1.21.9, 1.20.14, and 1.19.20.
Gravedad CVSS v3.1: MEDIA
Última modificación:
24/08/2026

CVE-2026-56135

Fecha de publicación:
24/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** In NTFS-3G through 2026.2.25, a heap-based buffer overflow exists in the function build_inherited_id() in libntfs-3g/security.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by creating a file in a crafted directory.
Gravedad: Pendiente de análisis
Última modificación:
24/08/2026

CVE-2026-56136

Fecha de publicación:
24/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** In NTFS-3G through 2026.2.25, an out-of-bounds read exists in ntfs_ir_nill() in libntfs-3g/index.c that allows an attacker to read possibly confidential information in an ntfs-3g process by crafting a malicious NTFS image. This read operation is triggered by creation of a file with a crafted name.
Gravedad: Pendiente de análisis
Última modificación:
24/08/2026

CVE-2026-55468

Fecha de publicación:
24/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Wagtail is an open source content management system built on Django. Prior to versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2 on their respective release lines, the internal Pages admin API returns page fields declared in api_fields without sufficient access control, allowing a user with Wagtail admin access to retrieve restricted draft and live page content. This issue is fixed in versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2.
Gravedad CVSS v3.1: MEDIA
Última modificación:
24/08/2026

CVE-2026-52490

Fecha de publicación:
24/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c
Gravedad: Pendiente de análisis
Última modificación:
24/08/2026

CVE-2026-52492

Fecha de publicación:
24/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** An integer overflow in the libtiff rgb2ycbcr utility&amp;#39;s cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based buffer overflow during YCbCr conversion of a crafted TIFF image
Gravedad: Pendiente de análisis
Última modificación:
24/08/2026

CVE-2026-16783

Fecha de publicación:
24/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
Gravedad CVSS v3.1: ALTA
Última modificación:
24/08/2026

CVE-2026-19568

Fecha de publicación:
24/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Gravedad CVSS v3.1: ALTA
Última modificación:
24/08/2026