Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-8313

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the linker.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.
Gravedad CVSS v4.0: ALTA
Última modificación:
15/07/2026

CVE-2026-8312

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the expmt.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.
Gravedad CVSS v4.0: ALTA
Última modificación:
15/07/2026

CVE-2026-8085

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the model.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.
Gravedad CVSS v4.0: ALTA
Última modificación:
15/07/2026

CVE-2026-62392

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Neutralization of Special Elements used in an OS Command (&amp;#39;OS Command Injection&amp;#39;) vulnerability in Apache Kylin. A backend API may bring job config parameters to OS command line.<br /> <br /> This issue affects Apache Kylin: from 4 through 5.0.3.<br /> <br /> Users are recommended to upgrade to version 5.0.4, which fixes the issue.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
15/07/2026

CVE-2026-62393

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorization in job information retrieval, where an attacker may get access to unauthorized jobs in other projects.<br /> <br /> This issue affects Apache Kylin: from 4 through 5.0.3.<br /> <br /> Users are recommended to upgrade to version 5.0.4, which fixes the issue.
Gravedad CVSS v3.1: MEDIA
Última modificación:
15/07/2026

CVE-2026-62390

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Neutralization of Special Elements used in an SQL Command (&amp;#39;SQL Injection&amp;#39;) vulnerability in Apache Kylin. A backend API refreshing table catalog may cause the injection to the generated SQL.<br /> <br /> This issue affects Apache Kylin: from 4 through 5.0.3.<br /> <br /> Users are recommended to upgrade to version 5.0.4, which fixes the issue.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
14/07/2026

CVE-2026-53565

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Privilege Management vulnerability in Citrix Secure Access Client for Windows, Citrix Citrix Endpoint Analysis Client for Windows.<br /> <br /> This issue affects Secure Access Client for Windows: before 26.6.1.20; Citrix Endpoint Analysis Client for Windows: before 26. 5.1.7.
Gravedad CVSS v4.0: ALTA
Última modificación:
15/07/2026

CVE-2026-49488

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Limitation of a Pathname to a Restricted Directory (&amp;#39;Path Traversal&amp;#39;) vulnerability in Apache OpenMeetings.<br /> <br /> This issue affects Apache OpenMeetings: from 5.0.0 before 9.1.0.<br /> An attacker with moderator rights in any room can read arbitrary files accessible to the OS account running the OM server, including credentials and secrets, via a crafted download request.<br /> <br /> Users are recommended to upgrade to version 9.1.0, which fixes the issue.
Gravedad CVSS v3.1: MEDIA
Última modificación:
15/07/2026

CVE-2026-15692

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A weakness has been identified in Tenda BE12 Pro 16.03.66.23. This vulnerability affects the function fromSafeUrlFilter of the file /goform/SafeUrlFilter. Executing a manipulation of the argument page can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
Gravedad CVSS v4.0: ALTA
Última modificación:
14/07/2026

CVE-2026-15718

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6, Firefox ESR 140.13, and Thunderbird 140.13.
Gravedad CVSS v3.1: MEDIA
Última modificación:
22/07/2026

CVE-2026-15719

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6, Firefox ESR 115.38, Firefox ESR 140.13, and Thunderbird 140.13.
Gravedad CVSS v3.1: MEDIA
Última modificación:
22/07/2026

CVE-2026-15691

Fecha de publicación:
14/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A security flaw has been discovered in Tenda BE12 Pro 16.03.66.23. This affects the function fromSafeClientFilter of the file /goform/SafeClientFilter. Performing a manipulation of the argument page results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
Gravedad CVSS v4.0: ALTA
Última modificación:
15/07/2026