Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-62676

Fecha de publicación:
21/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, the shared shell-command parser in omnigent/policies/builtins/_shell.py fails to recognize combined interpreter flags, the timeout, nice, setsid, and stdbuf wrappers, command substitutions, and a single background control operator. A gated git push or gh write hidden with these forms produces no parsed operation, causing the github.py write_repos and write_branches allowlist and the working_dir.py workspace confinement policies to abstain and allow the command. An authenticated or prompt-injected agent can therefore push to an unauthorized repository or branch or escape the intended workspace. This issue is fixed in version 0.3.0.
Gravedad CVSS v3.1: ALTA
Última modificación:
21/08/2026

CVE-2026-62675

Fecha de publicación:
21/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, multipart POST /v1/sessions accepts an authenticated user's agent bundle and omnigent/server/bundles.py validate_agent_bundle does not reject a tools..callable dotted Python path. omnigent/runner/tool_dispatch.py _resolve_spec_callable imports the specified module and _execute_spec_callable_tool invokes the resolved function, allowing a bundle to select subprocess.check_output and execute a local command with the runner process permissions. This can expose runner files, environment variables, credentials, workspace data, internal services, and availability without administrator access. This issue is fixed in version 0.3.0.
Gravedad CVSS v3.1: ALTA
Última modificación:
21/08/2026

CVE-2026-41450

Fecha de publicación:
21/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _command_collector function where foreach command output lines are substituted directly into command strings via sed without proper escaping before being evaluated with eval. Attackers can exploit this by crafting malicious filenames or artifact definitions containing shell metacharacters such as command substitution syntax or semicolons to execute arbitrary commands on the analyst's host system.
Gravedad CVSS v4.0: ALTA
Última modificación:
21/08/2026

CVE-2026-41451

Fecha de publicación:
21/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the user substitution logic within parse_artifact.sh where usernames and home directories from /etc/passwd are substituted directly into command strings without escaping before execution via eval. Attackers can inject shell metacharacters such as command substitution syntax or semicolons through crafted usernames or home directory paths in /etc/passwd entries to execute arbitrary commands on the analyst's host system.
Gravedad CVSS v4.0: ALTA
Última modificación:
21/08/2026

CVE-2026-55241

Fecha de publicación:
21/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. Prior to 3.9.1, the public POST /api/v1/auth/register route in server/src/api/routes/authRoutes.ts passes multipart profileImage uploads through in-memory Multer parsing before registration validation, without file-size, file-count, or MIME-type limits in server/src/api/middleware/upload.ts. An unauthenticated attacker can submit concurrent oversized files that are buffered before invalid registration or invite-token checks reject the request, exhausting memory and crashing or destabilizing the backend. This issue is fixed in version 3.9.1.
Gravedad CVSS v3.1: ALTA
Última modificación:
21/08/2026

CVE-2026-41449

Fecha de publicación:
21/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _run_command function that allows attackers to execute arbitrary commands by injecting shell metacharacters into untrusted data such as usernames, process names, or filenames. Attackers can exploit this vulnerability through crafted evidence inputs, mounted images with hostile filenames, or tampered artifact definitions to achieve remote code execution on the analyst's host when processing evidence.
Gravedad CVSS v4.0: ALTA
Última modificación:
21/08/2026

CVE-2026-17250

Fecha de publicación:
21/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A<br /> stack-based buffer overflow vulnerability exists in the firmware update<br /> functionality of TL-MR6400 v7 due to unsafe processing of<br /> attacker-controlled metadata within a firmware image. <br /> <br /> <br /> <br /> <br /> <br /> Successful<br /> exploitation may allow an authenticated attacker to trigger memory corruption<br /> and execute arbitrary code on the affected device.
Gravedad CVSS v4.0: ALTA
Última modificación:
21/08/2026

CVE-2026-17251

Fecha de publicación:
21/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A NULL<br /> pointer dereference vulnerability exists in the HTTP request parsing<br /> functionality of <br /> TL-MR6400 v7. An unauthenticated remote attacker can<br /> trigger the vulnerability by sending a specially crafted HTTP request<br /> containing a malformed session cookie header. <br /> <br /> <br /> <br /> <br /> <br /> Successful<br /> exploitation may cause the HTTP service process to crash, resulting in a<br /> denial-of-service condition and temporary loss of management or CGI<br /> functionality until service recovery.
Gravedad CVSS v4.0: ALTA
Última modificación:
21/08/2026

CVE-2026-17252

Fecha de publicación:
21/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A<br /> stack-based out-of-bounds write vulnerability exists in the login request<br /> handling functionality of the administrative web interface of TP-Link TL-MR6400 v7 routers. An unauthenticated adjacent attacker can trigger the vulnerability<br /> by sending a specially crafted malformed HTTP request. <br /> <br /> <br /> <br /> <br /> <br /> Successful<br /> exploitation may cause the web service process to crash, resulting in a<br /> denial-of-service condition and temporary loss of access to the router&amp;#39;s web<br /> management interface.
Gravedad CVSS v4.0: ALTA
Última modificación:
21/08/2026

CVE-2026-9012

Fecha de publicación:
21/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Gravedad: Pendiente de análisis
Última modificación:
21/08/2026

CVE-2026-9244

Fecha de publicación:
21/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Gravedad: Pendiente de análisis
Última modificación:
21/08/2026

CVE-2026-9321

Fecha de publicación:
21/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Gravedad: Pendiente de análisis
Última modificación:
21/08/2026