Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-18157

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit an argument injection vulnerability in the APT backend. This allows specially crafted package names, which begin with a hyphen, to be misinterpreted as command options by apt-get. Successful exploitation could lead to remote code execution (RCE) with root privileges, enabling the attacker to fully compromise the system's integrity, confidentiality, and availability.
Gravedad CVSS v3.1: ALTA
Última modificación:
31/07/2026

CVE-2026-6889

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Gravedad: Pendiente de análisis
Última modificación:
31/07/2026

CVE-2026-6890

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Gravedad: Pendiente de análisis
Última modificación:
31/07/2026

CVE-2026-14541

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0. When a Google authService is initialized with mcpEnabled: true but lacks an explicitly defined audience or clientId, the ValidateMCPAuth pipeline for opaque tokens skips audience validation entirely. As a result, the toolbox will accept any valid Google OAuth access token—even those minted for unrelated ecosystem applications—granting unauthorized clients access to protected tools and data backends.
Gravedad CVSS v4.0: ALTA
Última modificación:
31/07/2026

CVE-2026-14540

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbox versions 0.3.0 through 1.4.0. While the toolbox implements baseline input sanitization for user-controlled parameters, the underlying HTTP client (internal/sources/http/http.go) fails to safely regulate request redirection boundaries. Specifically, the client is initialized without a restrictive CheckRedirect policy hook and lacks target IP validation. An attacker or a malicious data-driven prompt can supply a crafted path parameter that triggers an open redirect or a direct destination swap on the target backend, coercing the mcp-toolbox into blindly following the redirection and making unauthorized requests to internal or arbitrary external endpoints.
Gravedad CVSS v4.0: ALTA
Última modificación:
31/07/2026

CVE-2026-14538

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1 through 1.4.0 allows an authenticated attacker to bypass allowedDatasets validation checks. The toolbox relies on the BigQuery dry-run API to enforce dataset restrictions, but due to a fail-open logic flaw, it bypasses validation when the API returns an empty array for specialized constructs. This allows the attacker to extract structural DDL schemas for explicitly excluded datasets via INFORMATION_SCHEMA, and access downstream federated row data via EXTERNAL_QUERY connections.
Gravedad CVSS v4.0: MEDIA
Última modificación:
31/07/2026

CVE-2026-14539

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up to and including 1.4.0 allows an unauthenticated attacker to cause a denial of service (DoS). The /mcp endpoint handler reads incoming payloads directly into system memory using an unrestricted buffer loop (io.ReadAll) without applying defensive constraints such as http.MaxBytesReader or pre-read Content-Length enforcement. By submitting a single, massive HTTP request body, an attacker can linearly consume available host memory until the runtime process is terminated by an Out-Of-Memory (OOM) error.
Gravedad CVSS v4.0: MEDIA
Última modificación:
31/07/2026

CVE-2026-14537

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated attacker to invoke tools protected by the scopeRequired feature via sending tool invocation requests through legacy HTTP endpoints when the --enable-api flag is active.
Gravedad CVSS v4.0: ALTA
Última modificación:
31/07/2026

CVE-2026-58039

Fecha de publicación:
31/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths.<br /> <br /> This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations.<br /> <br /> This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.
Gravedad CVSS v3.1: BAJA
Última modificación:
31/07/2026

CVE-2026-66360

Fecha de publicación:
30/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The ISO Presentation layer contains a flaw in the handling of specific <br /> parameters during normal mode negotiation. A missing length check in the<br /> processing of the encoded presentation data allows an attacker <br /> controlled field with a zero length value to trigger a bounded heap over<br /> read. This condition occurs before MMS session establishment, a crafted<br /> TCP/102 connection attempt can trigger the issue. The resulting over <br /> read causes the process to terminate, leading to a denial of service <br /> condition.
Gravedad CVSS v4.0: ALTA
Última modificación:
30/07/2026

CVE-2026-66364

Fecha de publicación:
30/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The GOOSE payload parser contains a boundary handling flaw that can be <br /> triggered by a single unauthenticated Layer 2 multicast frame on the <br /> process bus. When processing specific payload fields, an attacker <br /> controlled inner element length may exceed its enclosing length, causing<br /> the parser to over read by one byte. This out-of-bounds read reliably <br /> terminates the subscriber process, resulting in a denial-of-service <br /> condition.
Gravedad CVSS v4.0: ALTA
Última modificación:
30/07/2026

CVE-2026-66369

Fecha de publicación:
30/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The GOOSE parser contains an off-by-one boundary-handling flaw that can <br /> be triggered by a single unauthenticated Layer-2 multicast frame on the <br /> process bus. When specific GOOSE message fields are processed, the <br /> parser advances its internal buffer position incorrectly, resulting in a<br /> heap out-of-bounds read. On affected platforms, this condition reliably<br /> terminates the subscriber process and causes a denial-of-service.
Gravedad CVSS v4.0: ALTA
Última modificación:
30/07/2026