Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-58085

Fecha de publicación:
19/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** After dispatching a decrypt operation to OCF and receiving the result, the wg(4) driver failed to check whether the MAC verification step succeeded. The driver thus silently accepted packets with an invalid Poly1305 authentication tag.<br /> <br /> A remote attacker who can send UDP packets to a WireGuard endpoint, and who can guess the bounds of the receiver&amp;#39;s replay window, can inject forged or modified transport data packets into the tunnel.<br /> <br /> A remote attacker who can intercept WireGuard packets bound for a FreeBSD host can modify the ciphertext and authenticated data without detection by the receiver.
Gravedad: Pendiente de análisis
Última modificación:
19/08/2026

CVE-2026-58086

Fecha de publicación:
19/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** As an inadvertent side effect of an unrelated code change, PRIV_KTRACE was always denied to a jailed root user. Tracing configured by a jailed root user was therefore not flagged as privileged.<br /> <br /> An unprivileged user in a jail that has permission to debug the target process can modify the jailed root user&amp;#39;s ktrace(2) flags, or disable tracing outright. A jailed root user therefore cannot reliably trace unprivileged processes.
Gravedad: Pendiente de análisis
Última modificación:
19/08/2026

CVE-2026-75981

Fecha de publicación:
19/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to unauthenticated Stored Cross-Site Scripting in versions up to and including 3.2.5. The special gettext markers &amp;#39;#!trpst#&amp;#39; and &amp;#39;#!trpen#&amp;#39; are unconditionally rewritten to &amp;#39;&amp;#39; by translate_page() in includes/class-translation-render.php (lines 538-539). Because those markers are plain text with no HTML-special characters, an unauthenticated attacker can embed them in a comment; the markers survive wp_kses, and when the post is viewed in a secondary language the substitution turns the attacker&amp;#39;s &amp;#39;#!trpst#img ... #!trpen#&amp;#39; into a real tag. remove_tags_from_output() only strips /, so an executes in the visitor&amp;#39;s browser.
Gravedad CVSS v3.1: ALTA
Última modificación:
19/08/2026

CVE-2026-49423

Fecha de publicación:
19/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** When building the iovec array for a received TLS 1.2 CBC record, ktls_ocf_tls_cbc_decrypt() incremented the iovec index for every mbuf in the chain, including mbufs that were skipped because they contained only TLS header bytes. This left uninitialized entries in the iovec array. The iovec array was allocated without zeroing.<br /> <br /> A remote TLS peer can cause the kernel to read from uninitialized iovec entries during HMAC computation, resulting in a kernel panic. The peer must be able to control TCP segmentation such that the first mbuf of a CBC record contains only the 5-byte TLS record header.
Gravedad: Pendiente de análisis
Última modificación:
19/08/2026

CVE-2026-15446

Fecha de publicación:
19/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The EWWW Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via &amp;#39;data-script&amp;#39; Lazy Load Attribute in Post Content in all versions up to, and including, 8.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit is achieved by embedding a crafted img element with class=&amp;#39;lazyload&amp;#39; and a data-script attribute pointing to an attacker-controlled URL in post content, which the plugin&amp;#39;s bundled lazysizes ls.unveilhooks addon then uses to dynamically create and insert a script element into the DOM at page view time.
Gravedad CVSS v3.1: MEDIA
Última modificación:
19/08/2026

CVE-2026-15780

Fecha de publicación:
19/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the &amp;#39;utm_campaign&amp;#39; parameter in all versions up to, and including, 14.16.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload can be planted without authentication via the public /wp-statistics/v2/hit REST endpoint, because the required signature is exposed on the public homepage and a base64-encoded page_uri POST parameter overrides the previously sanitized REQUEST_URI, allowing the malicious utm_campaign value to bypass sanitization and be stored in the database.
Gravedad CVSS v3.1: ALTA
Última modificación:
19/08/2026

CVE-2026-49431

Fecha de publicación:
19/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The ZFS_IOC_SET_PROP ioctl, used by zfs-set(8), incorrectly validated the calling user such that an unprivileged user is able to set metadata on a dataset indicating that the dataset has received properties from a zfs-recv(8) stream.<br /> <br /> Any local user can set the internal ZFS metadata flag "$hasrecvd" on datasets via ZFS_IOC_SET_PROP.
Gravedad: Pendiente de análisis
Última modificación:
19/08/2026

CVE-2026-8810

Fecha de publicación:
19/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** On ARM platforms, a vulnerability in the architecture design of HDD Password could allow an attacker to retrieve HDD Password from UEFI variables.
Gravedad CVSS v3.1: MEDIA
Última modificación:
19/08/2026

CVE-2026-49428

Fecha de publicación:
19/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Certain system calls, such open(2) with the O_TRUNC flag set, and fspacectl(2), could incorrectly free memory in largepage objects. These operations are not permitted on largepage objects, but the implementation did not verify this.<br /> <br /> An unprivileged local user can abuse the bug to access freed kernel memory. This can be exploited to escalate privileges.
Gravedad: Pendiente de análisis
Última modificación:
19/08/2026

CVE-2026-49429

Fecha de publicación:
19/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The ZFS_IOC_USERSPACE_MANY ioctl, used by zfs-userspace(8), truncated a 64-bit output buffer size to a 32-bit integer for the kernel allocation, but used the original 64-bit size as the buffer limit when writing records.<br /> <br /> A local user with the "userused" delegated ZFS permission can trigger a kernel heap overflow via the ZFS_IOC_USERSPACE_MANY ioctl, potentially escalating privileges.
Gravedad: Pendiente de análisis
Última modificación:
19/08/2026

CVE-2026-49430

Fecha de publicación:
19/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The ZFS_IOC_RECV_NEW ioctl, in the heal receive path, similarly truncated a 64-bit payload size to a 32-bit integer for allocation, then used the original 64-bit size as the length for a byteswap operation.<br /> <br /> A local user with the "receive" delegated ZFS permission can trigger kernel memory corruption via ZFS_IOC_RECV_NEW by sending a crafted receive stream in heal mode.
Gravedad: Pendiente de análisis
Última modificación:
19/08/2026

CVE-2026-49421

Fecha de publicación:
19/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The kernel function that implements unlinkat(2) and funlinkat(2) validated the AT_RESOLVE_BENEATH flag but failed to pass it through to the underlying path lookup. The flag was silently dropped, so path resolution was not actually restricted.<br /> <br /> A process that uses AT_RESOLVE_BENEATH with unlinkat(2) or funlinkat(2) to confine path resolution can in fact resolve paths above the starting directory. A caller relying on this flag for path containment may delete files outside the intended directory tree.
Gravedad: Pendiente de análisis
Última modificación:
19/08/2026