Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-52887

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/plugin-notification-in-app-message exposed GET /api/myInAppChannels:list, where the filter[latestMsgReceiveTimestamp][$lt] value was inserted into a Sequelize.literal() template string without escaping or parameter binding, allowing a signed-up authenticated user to run stacked PostgreSQL statements and potentially execute commands with COPY ... TO PROGRAM. This vulnerability is fixed in 2.0.61.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
20/07/2026

CVE-2026-49353

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** 9Router is an AI router & token saver. In 0.4.45 and earlier, 9Router's src/dashboardGuard.js local-only access gate used Host and Origin headers in isLocalRequest() to protect /api/mcp/*, /api/tunnel/*, and /api/cli-tools/*, allowing header spoofing in reverse proxy or tunnel deployments to reach MCP child process stdin paths.
Gravedad CVSS v3.1: ALTA
Última modificación:
16/07/2026

CVE-2026-49352

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** 9Router is an AI router & token saver. From 0.2.21 until 0.4.44, 9Router used the hardcoded fallback JWT secret 9router-default-secret-change-me in src/app/api/auth/login/route.js, src/middleware.js, and later src/lib/auth/dashboardSession.js, allowing attackers to forge an auth_token cookie when JWT_SECRET was unset. This issue is fixed in version 0.4.44
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
16/07/2026

CVE-2026-46339

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** 9Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect /api/cli-tools/* and /api/mcp/*, allowing unauthenticated registration of customPlugins through src/app/api/cli-tools/cowork-settings/route.js and command execution through the MCP bridge. This vulnerability is fixed in 0.4.37.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
16/07/2026

CVE-2026-33684

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** WWBN AVideo is an open source video platform. Prior to version 29.0, Privilege Escalation is possible through unguarded permission parameters in signUp API, which allows any user who can solve a CAPTCHA to self-grant elevated permissions during account registration. The set_api_signUp method in the API plugin accepts emailVerified, canUpload, canStream, and canCreateMeet parameters from user-supplied input and applies them to newly created accounts without verifying that the request was authenticated with a valid APISecret. By self-granting account attributes, attackers can mark their own accounts as email-verified without owning the address (bypassing email-gated functionality) and award themselves upload, streaming, and meeting-creation permissions, circumventing administrator access controls that intentionally restrict these capabilities for new users. This issue has been fixed in version 29.0
Gravedad CVSS v3.1: MEDIA
Última modificación:
16/07/2026

CVE-2026-33445

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** CVE-2026-33445 is a memory management<br /> vulnerability in Secure Access servers prior to 14.55. Attackers with an<br /> intimate knowledge of and total control over the tunnel protocol can create a<br /> persistent DoS against the server.
Gravedad CVSS v4.0: ALTA
Última modificación:
16/07/2026

CVE-2026-33444

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** CVE-2026-33444 is a memory management<br /> vulnerability in Secure Access servers prior to 14.55. Attackers with intimate<br /> knowledge of and total control over the tunnel protocol can create a<br /> non-persistent DoS against the server.
Gravedad CVSS v4.0: MEDIA
Última modificación:
16/07/2026

CVE-2026-38753

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
Gravedad CVSS v3.1: MEDIA
Última modificación:
20/07/2026

CVE-2026-56743

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Cilium is a networking, observability, and security solution. From 1.19.0 to 1.19.4, standard Kubernetes NetworkPolicy specifications using CIDR-based ipBlock rules without pod or namespace selectors erroneously generate a wildcard namespace allow rule when Cilium is configured with a custom clusterName rather than the default any value. The parser incorrectly instantiates a pod selector on selectorless peer definitions, allowing traffic from other workloads in the same namespace as the subject of the policy. This issue is fixed in version 1.19.5.
Gravedad CVSS v3.1: MEDIA
Última modificación:
17/07/2026

CVE-2026-56742

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters using Gateway API allow users with permissions to create or update namespaced HTTPRoutes to mirror HTTP traffic to any Service in any namespace, bypassing the ReferenceGrant authorization mechanism. Gateway API functionality is disabled by default. This issue is fixed in versions 1.17.17, 1.18.11, and 1.19.5.
Gravedad CVSS v3.1: MEDIA
Última modificación:
17/07/2026

CVE-2026-52869

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2, the SSE and stateful Streamable HTTP transports mcp.server.sse.SseServerTransport and mcp.server.streamable_http_manager.StreamableHTTPSessionManager route requests to existing sessions using only the session_id query parameter or Mcp-Session-Id header without verifying the authenticated principal that created the session, allowing a different bearer-token-authenticated client with a known session ID to inject JSON-RPC messages into that session. This issue is fixed in version 1.27.2.
Gravedad CVSS v3.1: ALTA
Última modificación:
17/07/2026

CVE-2026-52870

Fecha de publicación:
15/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers installed by server.experimental.enable_tasks() for tasks/list, tasks/get, tasks/result, and tasks/cancel operate only on task identifiers without recording the session that created each task, allowing any connected client to enumerate, read results from, consume messages for, or cancel other clients&amp;#39; tasks. This issue is fixed in version 1.27.2.
Gravedad CVSS v3.1: ALTA
Última modificación:
17/07/2026