Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-16008

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A security vulnerability has been detected in sagold json-schema-library 11.5.0/11.5.1. This impacts the function parsePropertyDependencies of the file src/keywords/propertyDependencies.ts. The manipulation leads to improperly controlled modification of object prototype attributes. The attack can be initiated remotely. Upgrading to version 11.6.0 will fix this issue. The identifier of the patch is 432287ee6f68a02ce6f015354618486ec427a32d. It is advisable to upgrade the affected component.
Gravedad CVSS v4.0: BAJA
Última modificación:
17/07/2026

CVE-2026-59252

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet, resulting in denial of service for legitimate clients.<br /> <br /> When the mpp Elixir library is configured as fee payer (fee_payer: true), the MPP.Methods.Tempo payment method co-signs and broadcasts a client-supplied EVM transaction without first validating that the client-supplied gas_limit is sufficient to complete the intended call. A malicious client can submit a signed transferWithMemo transaction with gas_limit deliberately set just below the amount required for successful execution. The server co-signs the transaction and broadcasts it via rpc_broadcast_sync. The transaction runs out of gas during EVM execution and reverts, but the fee-payer wallet is still charged for the burned gas while the client pays nothing and receives no resource. Repeated requests from one or more malicious clients drain the fee-payer wallet at near-zero cost to the attacker, ultimately preventing the server from sponsoring gas for legitimate payment requests.<br /> <br /> The wait_for_confirmation = false (optimistic) path is also affected: it invokes simulate_payment_call via eth_call, but that simulation omits the gas parameter and therefore does not catch out-of-gas conditions.<br /> <br /> This issue affects mpp: from 0.2.0 before 0.6.0.
Gravedad CVSS v4.0: ALTA
Última modificación:
17/07/2026

CVE-2026-59694

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer&amp;#39;s gas cost per payment by a large multiplier, degrading the sponsor&amp;#39;s operating margin.<br /> <br /> When the mpp Elixir library is configured as fee payer (fee_payer: true), MPP.Tempo.Transaction.cosign_fee_payer/3 re-signs the client-supplied base fields of the 0x76 AASigned envelope verbatim, including the EIP-2930 access list, without validating its length or contents. EIP-2930 access list entries incur intrinsic gas (~2,400 gas per address, plus 1,900 gas per storage key) charged before any opcode executes, regardless of whether the listed addresses are ever touched. A malicious client submits a valid transferWithMemo call alongside a large number of fabricated access-list entries. The server co-signs and broadcasts the transaction. The intended transfer executes normally, but the fee-payer wallet pays a large multiple of the expected gas cost with no corresponding on-chain work.<br /> <br /> At the maintainer&amp;#39;s default of 137 access-list entries (fitting within Bandit&amp;#39;s 10,000-byte per-header-field limit) and 100 Gwei max_fee_per_gas, per-payment gas cost rises from ~51,287 to ~380,087 gas, a 7.4x multiplier. Sustained abuse destroys the sponsor&amp;#39;s operating margin on low-cost payments and, over time, drains the fee-payer wallet.<br /> <br /> This issue affects mpp: from 0.2.0 before 0.6.0.
Gravedad CVSS v4.0: ALTA
Última modificación:
17/07/2026

CVE-2026-22104

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper access control in Hashtopolis server web-interface chunk activity component for versions prior to 0.14.8 allows any created account to read all cracked hashes of a Hashtopolis server instance.
Gravedad CVSS v4.0: ALTA
Última modificación:
17/07/2026

CVE-2026-62764

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo.<br /> An authenticated, but low-privileged user without system permissions may<br /> issue a remote command to gracefully shutdown system components<br /> (compaction-coordinator, compactor, gc, manager, monitor, tserver, or sserver),<br /> leading to a denial of service.<br /> <br /> This issue affects Apache Accumulo 2.1.4 and 2.1.5.<br /> <br /> Users are recommended to upgrade to version 2.1.6, which fixes the issue.
Gravedad CVSS v4.0: MEDIA
Última modificación:
17/07/2026

CVE-2026-9656

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.3.62 via the wp_localize_script() / window.leadinConfig JavaScript object. This makes it possible for authenticated attackers, with contributor-level access and above, to extract the site&amp;#39;s plaintext HubSpot OAuth refresh token exposed via the window.leadinConfig JavaScript object, which can then be used to access or modify data in the connected HubSpot tenant. Although the refresh token is stored at rest with AES-256-CTR encryption, decryption occurs server-side before the plaintext value is passed to wp_localize_script(), rendering the at-rest encryption ineffective against this exposure path.
Gravedad CVSS v3.1: MEDIA
Última modificación:
17/07/2026

CVE-2026-15380

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A non-administrator interactive user can obtain full SYSTEM code execution through a DCOM/task scheduler logic chain — no network access, no memory corruption required (ITMS 8.7.3)
Gravedad CVSS v4.0: MEDIA
Última modificación:
21/07/2026

CVE-2026-15379

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Altiris WMI provider exposes a class (AltirisAgent_Stream) that allows any local standard user to read the contents of any file accessible to the SYSTEM account, bypassing filesystem ACLs. No admin privileges required. The provider reverts to the LocalSystem context when servicing WMI queries without re-impersonating the caller. Any local standard user can therefore read SYSTEM-readable files — including configuration files, service logs, and secrets stored with SYSTEM/Administrator-only ACLs — by querying the provider directly.
Gravedad CVSS v4.0: MEDIA
Última modificación:
21/07/2026

CVE-2026-12393

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The WPS Bookings for WooCommerce WordPress plugin before 3.11.7 does not verify that a booking order belongs to the requesting user before cancelling it, allowing any authenticated user, such as a Subscriber or Customer, to cancel and void other customers&amp;#39; booking orders.
Gravedad CVSS v3.1: MEDIA
Última modificación:
17/07/2026

CVE-2026-13402

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of menu items or the templates they reference in one of its REST endpoints, allowing unauthenticated users to retrieve the rendered HTML content of private or draft Elementor templates linked from non-public navigation menu items.
Gravedad CVSS v3.1: MEDIA
Última modificación:
17/07/2026

CVE-2026-9810

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator session, allowing unauthenticated attackers who complete the public OAuth flow to execute privileged MCP tools as an administrator, including arbitrary user creation and role escalation.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
17/07/2026

CVE-2026-11575

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not properly verify the authenticity of incoming payment callbacks: the secret used to validate the callback signature is empty on sites configured through the current setup flow, so the expected signature reduces to an unkeyed hash of the request body that anyone can compute. This allows unauthenticated attackers to forge a payment-success notification and mark unpaid WooCommerce orders as paid without any payment being made.
Gravedad CVSS v3.1: ALTA
Última modificación:
17/07/2026