Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-74820

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against the instance&amp;#39;s underlying database and gain access to, or modify, instance data beyond what was intended. <br /> <br /> <br /> <br /> <br /> <br /> ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of malicious exploitation against ServiceNow instances. <br /> <br /> <br /> <br /> We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
27/08/2026

CVE-2026-6876

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** ServiceNow has remediated a sandbox escape security issue that was identified in the Now Platform. This security issue could allow an unauthenticated user to execute arbitrary code within the Now Platform, potentially leading to more access to the Now Platform than intended.  <br /> <br /> <br /> <br /> <br /> <br /> ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of malicious exploitation against ServiceNow instances. <br /> <br /> <br /> <br /> We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.
Gravedad CVSS v4.0: ALTA
Última modificación:
27/08/2026

CVE-2026-65931

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** LimeSurvey Community Edition 7.0.5 contains an authenticated improper authorization vulnerability in the survey menu entry creation endpoint.<br /> <br /> <br /> <br /> An authenticated user with only the global settings:read permission can directly invoke POST /index.php/admin/menuentries/sa/create and create new survey menu entries without the expected settings:update privilege. The endpoint also allows the attacker to submit menu IDs that the normal interface and intended update workflow restrict for non-superadministrators, enabling unauthorized changes to administrative navigation records.<br /> <br /> <br /> <br /> This issue affects LimeSurvey: 7.0.5.
Gravedad CVSS v4.0: MEDIA
Última modificación:
27/08/2026

CVE-2026-66353

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Neutralization of Input During Web Page Generation (&amp;#39;Cross-site Scripting&amp;#39;) vulnerability in woylie doggo allows Reflected XSS.<br /> <br /> Doggo.normalize_value/2 in lib/doggo.ex returned date field values wrapped in {:safe, ...}, the Phoenix.HTML marker meaning "already escaped, emit verbatim", without escaping them, so the value reached the value attribute of the rendered by the field component unchanged. Any application rendering over user-controlled params is affected through the ordinary Phoenix form round-trip, where a failed validation re-renders the submitted value. The pattern kept exactly the first ten bytes and discarded shorter values, capping a payload at ten bytes: enough to terminate the attribute and open an element or attach a short event handler, not enough to place attacker-chosen script inline. Only type="date" is affected.<br /> <br /> This issue affects doggo: from 0.1.0 before 0.14.8.
Gravedad CVSS v4.0: MEDIA
Última modificación:
27/08/2026

CVE-2026-59320

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** When a container-level ErrorHandler is configured (the mitigation for finding 221000), each delivery whose processing throws still permanently consumes one link credit. After initialCredits (default 100) failing messages the receiver&amp;#39;s credit reaches zero and the broker stops delivering, leaving the listener silently stalled while isRunning() remains true.<br /> Spring AMQP 4.1.0
Gravedad CVSS v3.1: MEDIA
Última modificación:
27/08/2026

CVE-2026-59321

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A single ScriptEngine instance is reused for every message on a script-backed channel. For JSR-223 engines that report THREADING=null (not thread-safe, e.g. the Kotlin kts engine), concurrent message processing can corrupt engine-internal state, potentially leaking one message&amp;#39;s payload/headers bindings into another message&amp;#39;s script evaluation or throwing spurious exceptions.<br /> Spring Integration 7.1.0<br /> Spring Integration 7.0.0 - 7.0.5<br /> Spring Integration 6.5.0 - 6.5.10<br /> Spring Integration 6.4.0 - 6.4.12<br /> Spring Integration 5.5.21 and earlier
Gravedad CVSS v3.1: MEDIA
Última modificación:
27/08/2026

CVE-2026-59322

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The EmbeddedHeadersJsonMessageMapper defaults to an overly permissive header parsing posture in its constructor. When decodeNativeFormat processes raw byte payloads, it deserializes embedded JSON headers into a plain Map and constructs a GenericMessage with MutableMessageHeaders without sanitizing or filtering untrusted header names by default.<br /> Spring Integration 7.1.0<br /> Spring Integration 7.0.0 - 7.0.5<br /> Spring Integration 6.5.0 - 6.5.10<br /> Spring Integration 6.4.0 - 6.4.12<br /> Spring Integration 5.5.21 and earlier
Gravedad CVSS v3.1: MEDIA
Última modificación:
27/08/2026

CVE-2026-59324

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads, concurrent requests on the same FluxMessageChannel subscription have their reply headers (replyChannel, errorChannel, correlationId, any propagated security/tenant headers) copied from whichever message was most recently consumed upstream.<br /> Spring Integration 7.1.0<br /> Spring Integration 7.0.0 - 7.0.5<br /> Spring Integration 6.5.0 - 6.5.10<br /> Spring Integration 6.4.0 - 6.4.12<br /> Spring Integration 5.5.21 and earlier
Gravedad CVSS v3.1: ALTA
Última modificación:
27/08/2026

CVE-2026-59307

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** An operator who calls JdbcMessageStore.addAllowedPatterns(...) to restrict deserialization receives no protection at all when the store is a Spring-managed bean.<br /> Spring Integration 7.1.0<br /> Spring Integration 7.0.0 - 7.0.5<br /> Spring Integration 6.5.0 - 6.5.10<br /> Spring Integration 6.4.0 - 6.4.12
Gravedad CVSS v3.1: ALTA
Última modificación:
27/08/2026

CVE-2026-59311

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A local unprivileged user on the same host can redirect all Zip/UnZip transformer output into a directory of their choosing by pre-creating /tmp/ziptransformer as a symlink before the application starts.<br /> Spring Integration 7.1.0<br /> Spring Integration 7.0.0 - 7.0.5<br /> Spring Integration 6.5.0 - 6.5.10<br /> Spring Integration 6.4.0 - 6.4.12
Gravedad CVSS v3.1: MEDIA
Última modificación:
27/08/2026

CVE-2026-59313

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent Events (SSE).<br /> Spring Framework 7.0.0 - 7.0.8<br /> Spring Framework 6.2.0 - 6.2.19<br /> Spring Framework 6.1.0 - 6.1.28<br /> Spring Framework 6.0.0 - 6.0.30<br /> Spring Framework 5.3.0 - 5.3.49
Gravedad: Pendiente de análisis
Última modificación:
27/08/2026

CVE-2026-59314

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Applications that build a Content-Disposition header value from untrusted input may be vulnerable to HTTP response splitting when the input is a malicious file name.<br /> Spring Framework 7.0.0 - 7.0.8<br /> Spring Framework 6.2.0 - 6.2.19<br /> Spring Framework 6.1.0 - 6.1.28<br /> Spring Framework 6.0.0 - 6.0.30<br /> Spring Framework 5.3.0 - 5.3.49<br /> Spring Framework 5.2.25.RELEASE and earlier
Gravedad: Pendiente de análisis
Última modificación:
27/08/2026