Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-33799

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An Out-of-bounds Write vulnerability in the SNMP daemon (snmpd) of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated network-based attacker sending specific valid SNMPv3 queries to trigger a memory leak. Over time, continuous receipt of these queries will result in snmpd process memory exhaustion, resulting in a process crash and restart, impacting the ability to monitor the system via SNMP.<br /> <br /> Memory usage can be monitored using the following command:<br /> <br /> user@device&gt; show system processes extensive | match snmpd<br /> <br /> <br /> <br /> <br /> This issue affects:<br /> <br /> Junos OS:<br /> <br /> <br /> * all versions before 21.2R3-S8;<br /> * from 21.4 before 21.4R3-S7;<br /> * from 22.1 before 22.1R3-S6;<br /> * from 22.2 before 22.2R3-S4;<br /> * from 22.3 before 22.3R3-S3;<br /> * from 22.4 before 22.4R3-S2;<br /> * from 23.2 before 23.2R2;<br /> * from 23.4 before 23.4R2.<br /> <br /> <br /> <br /> Junos OS Evolved:<br /> * all versions before 21.2R3-S8-EVO;<br /> * from 21.4 before 21.4R3-S7-EVO;<br /> * all versions of 22.1-EVO,<br /> * from 22.2 before 22.2R3-S4-EVO;<br /> * from 22.3 before 22.3R3-S3-EVO;<br /> * all versions of 22.4-EVO,<br /> * from 23.2 before 23.2R2-EVO;<br /> * from 23.4 before 23.4R2-EVO.
Gravedad CVSS v4.0: MEDIA
Última modificación:
13/07/2026

CVE-2026-33794

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An Improper Check for Unusual or Exceptional Conditions vulnerability in the <br /> <br /> advanced forwarding toolkit (evo-aftmand)<br /> <br /> of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated network-based attacker generating continuous routing updates, resulting in unilist ECMP routes, to crash the <br /> <br /> evo-aftmand process on the PFE, leading to a Denial-of-Service (DoS). The conditions required for successful exploitation are based on a sequence of events that are outside an attacker&amp;#39;s direct control.<br /> <br /> Unified list (unilist) ECMP routes are a specific ECMP behavior where multiple equal-cost routes share a single logical next-hop list entry. The router treats them as one route with multiple next hops and load balances traffic across that unified list. Due to an issue processing unilist ECMP routing updates, internal state corruption may occur, especially in large-scale ECMP unilist deployments, leading to the evo-aftmand process crashing, resulting in an evo-aftmand-bx core. Manual intervention is required to recover by rebooting the system or restarting the FPC.<br /> <br /> This issue affects Junos OS Evolved on PTX :<br /> <br /> <br /> * from 24.4R2-EVO before 24.4R2-S3-EVO;<br /> * from 25.2 before 25.2R2-EVO.
Gravedad CVSS v4.0: ALTA
Última modificación:
13/07/2026

CVE-2026-15270

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A weakness has been identified in D-link DIR-823G 1.0.2B05_20181207. Affected by this vulnerability is an unknown functionality of the file /etc/boa/boa.conf of the component Web Interface. Executing a manipulation can lead to least privilege violation. The attack can be launched remotely. The attack requires a high level of complexity. The exploitation appears to be difficult. The exploit has been made available to the public and could be used for attacks.
Gravedad CVSS v4.0: MEDIA
Última modificación:
13/07/2026

CVE-2026-0278

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Multiple protection mechanism failures in the Prisma Access Agent Data Loss Prevention (DLP) component for Windows allow a local user to bypass DLP policy enforcement controls.<br /> <br /> <br /> <br /> The Prisma Access Agent on macOS is not affected.
Gravedad CVSS v4.0: MEDIA
Última modificación:
16/07/2026

CVE-2026-0277

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. <br /> <br /> The Prisma Access Agent on Windows, macOS, Linux, Android and ChromeOS are not affected.
Gravedad CVSS v4.0: MEDIA
Última modificación:
16/07/2026

CVE-2026-0276

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A privilege escalation vulnerability in Palo Alto Networks Cortex® XDR Broker VM enables a locally authenticated user to perform actions as the root user.
Gravedad CVSS v4.0: BAJA
Última modificación:
16/07/2026

CVE-2026-0275

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A local privilege escalation vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated administrator with access to the macOS local filesystem to perform actions on the device with root privileges. <br /> <br /> This issue only affects Prisma® Browser on macOS.
Gravedad CVSS v4.0: BAJA
Última modificación:
14/07/2026

CVE-2026-59148

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Mockoon provides way to design and run mock APIs. Prior to 9.7.0, Mockoon&amp;#39;s admin API in commons-server/src/libs/server/admin-api.ts is mounted on the same Express listener as user-defined mock routes, enabled by default in shipped runtimes, serves Access-Control-Allow-Origin: * with write methods allowed, and has no authentication. Any unauthenticated caller who can reach the mock server port can read MOCKOON_* environment variables, write arbitrary process environment variables through /mockoon-admin/env-vars, rewrite mock route bodies, statuses, and headers through PUT /mockoon-admin/environment, read transaction logs and SSE streams, and purge state. This issue is fixed in version 9.7.0.
Gravedad CVSS v3.1: ALTA
Última modificación:
10/07/2026

CVE-2026-59149

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Mockoon provides way to design and run mock APIs. Prior to 9.7.0, a FILE response whose filePath embeds request data is confined by getSafeFilePath in packages/commons-server/src/libs/server/server.ts with resolvedPath.startsWith(staticBaseDir). That prefix test has no path-separator boundary, so a ../-escaped path whose absolute form string-prefixes the base directory passes, allowing an unauthenticated client to read files from sibling paths outside the served directory through HTTP sendFile, WebSocket, or callbacks. This issue is fixed in version 9.7.0.
Gravedad CVSS v3.1: MEDIA
Última modificación:
10/07/2026

CVE-2026-58198

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** ChatterBot is a machine learning, conversational dialog engine for creating chat bots. Prior to 1.2.14, UbuntuCorpusTrainer.extract() uses a predictable home-rooted output directory (~/ubuntu_data/ubuntu_dialogs) with a check-then-create pattern followed by tar.extractall(path=self.data_path), allowing a local attacker who pre-plants a symlink at the predictable path to cause archive contents to be written through the symlink to an attacker-chosen directory. This issue is fixed in version 1.2.14.
Gravedad CVSS v3.1: MEDIA
Última modificación:
09/07/2026

CVE-2026-54003

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Kirby is an open-source content management system. Prior to 4.9.4 and from 5.4.4, Kirby sites with no configured user accounts that run on publicly accessible servers behind a reverse proxy setting the Forwarded, X-Client-IP, or X-Real-IP request header could allow remote attackers to install the Panel and create the first admin user because local-IP checks trusted those headers incorrectly. This issue is fixed in versions 4.9.4 and 5.4.4.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
10/07/2026

CVE-2026-54004

Fecha de publicación:
09/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites with content.fileRedirects enabled could redirect unauthenticated clean file URL requests for files stored in top-level draft pages to physical media URLs without checking page access permissions or preview tokens, leading to disclosure of draft file contents. This issue is fixed in versions 4.9.4 and 5.4.4.
Gravedad CVSS v4.0: MEDIA
Última modificación:
10/07/2026