Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-48949

Fecha de publicación:
07/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Lack of validation leads to an XSS vulnerability in the MFA management views.
Gravedad CVSS v4.0: MEDIA
Última modificación:
09/07/2026

CVE-2026-48948

Fecha de publicación:
07/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.
Gravedad CVSS v4.0: MEDIA
Última modificación:
09/07/2026

CVE-2026-48947

Fecha de publicación:
07/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** An improper access check allows privileged users to overwrite media files without editing permissions.
Gravedad CVSS v4.0: MEDIA
Última modificación:
09/07/2026

CVE-2026-23698

Fecha de publicación:
07/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import feature that allows administrator-level attackers to upload arbitrary PHP files by submitting a crafted zip archive through the ModuleManager import function, which extracts contents directly into the modules/ directory under the web root without validating file types beyond the manifest.xml descriptor. Attackers can place executable PHP files in the modules/ directory that become directly accessible via HTTP, bypassing Vtiger's authentication and authorization layer entirely since Apache resolves the path and invokes the PHP interpreter before the application routing layer is involved, resulting in a persistent web shell independent of the originating session.
Gravedad CVSS v4.0: ALTA
Última modificación:
08/07/2026

CVE-2026-57851

Fecha de publicación:
07/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** MSI Feature Manager contains a local privilege escalation vulnerability in the KernCoreLib64.sys kernel driver that allows any locally logged-on user to perform arbitrary physical memory read/write and unrestricted I/O port operations by accessing exposed IOCTL handlers without administrator privileges. Attackers can exploit the accessible device object through IOCTL handlers to manipulate kernel objects, tamper with kernel-mode callbacks, bypass Protected Process Light protections, and disable security software.
Gravedad CVSS v4.0: ALTA
Última modificación:
10/07/2026

CVE-2026-23697

Fecha de publicación:
07/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve remote code execution by uploading a .phar file containing arbitrary PHP code through the Documents module, bypassing the extension denylist in config.inc.php which omits the .phar extension. The uploaded file is stored with its original .phar extension under the web-accessible storage directory, and a misconfigured .htaccess using Apache 2.2 syntax is silently ignored on Apache 2.4 deployments, allowing unauthenticated HTTP requests to directly execute the uploaded PHP payload.
Gravedad CVSS v4.0: ALTA
Última modificación:
08/07/2026

CVE-2026-14904

Fecha de publicación:
07/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create and manage secure virtual desktops and computing resources on AWS.<br /> <br /> <br /> <br /> Improper link resolution before file access issue (CWE-59) in the Auth.GetUserPrivateKey API. An authenticated remote user could read arbitrary files on the cluster-manager EC2 instance by replacing their SSH private key file (~/.ssh/id_rsa) with a symbolic link targeting any file on the host. Because the cluster-manager process runs as root, any file readable by root is exposed, including other users&amp;#39; SSH private keys and application configuration secrets.<br /> <br /> <br /> <br /> It&amp;#39;s recommended to upgrade to RES version 2026.06.
Gravedad CVSS v4.0: ALTA
Última modificación:
08/07/2026

CVE-2026-13020

Fecha de publicación:
07/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an email server with ArcGIS Enterprise to facilitate user self-service password recovery. The ability for an administrator to reset a user’s password remains unchanged.
Gravedad CVSS v3.1: ALTA
Última modificación:
09/07/2026

CVE-2026-13019

Fecha de publicación:
07/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
09/07/2026

CVE-2025-12799

Fecha de publicación:
07/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in Jastow. Jastow is vulnerable to Cross-Site Scripting (XSS) attack. If using a set of combined configuration to allow unescaped characters in URL with embedded Undertow and Jastow, a server might be vulnerable to improper input handling.
Gravedad CVSS v3.1: MEDIA
Última modificación:
09/07/2026

CVE-2026-56812

Fecha de publicación:
07/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Check for Unusual or Exceptional Conditions vulnerability in phoenixframework phoenix (Presence JavaScript client) allows an attacker with ordinary channel access to cause a persistent client-side denial of service against every viewer of a presence channel topic.<br /> <br /> This vulnerability is associated with program files assets/js/phoenix/presence.js and program routines Presence.syncState and Presence.syncDiff.<br /> <br /> The Phoenix JavaScript presence client checks whether a presence already exists with a bare truthiness test (state[key]) instead of an own-property check. Presence keys can be attacker-controlled, because applications track presences under a username or id supplied by the client. A user who joins a channel choosing a key that is an Object.prototype member name (__proto__, constructor, toString, hasOwnProperty, and similar) makes that lookup return JavaScript&amp;#39;s built-in Object.prototype instead of undefined. Because the prototype is truthy, the code treats it as an existing presence and reads .metas.map(...) off it, which throws an uncaught TypeError.<br /> <br /> The exception propagates out of the presence message handler, so the local state is never updated and onSync() never fires. Because the malicious key is tracked on the server, it is re-pushed on every presence update and keeps re-throwing, so presence sync stays broken for every viewer of that channel topic until the attacker leaves. Both syncState and syncDiff use the same unsafe existence-check pattern. The impact is limited to the affected topic and is a read-time confusion of the prototype object, not a mutation of Object.prototype (it is not prototype pollution).<br /> <br /> This issue affects phoenix: from 1.2.0-rc.0 before 1.5.15, from 1.6.0-rc.0 before 1.6.17, from 1.7.0-rc.0 before 1.7.24, and from 1.8.0-rc.0 before 1.8.9.
Gravedad CVSS v4.0: MEDIA
Última modificación:
09/07/2026

CVE-2026-56811

Fecha de publicación:
07/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Allocation of Resources Without Limits or Throttling vulnerability in phoenixframework phoenix (Phoenix.Socket module) allows an unauthenticated attacker to cause a denial of service against any endpoint that mounts a Phoenix socket with a reachable channel transport (WebSocket or LongPoll).<br /> <br /> This vulnerability is associated with program files lib/phoenix/socket.ex and program routine &amp;#39;Elixir.Phoenix.Socket&amp;#39;:handle_in/4.<br /> <br /> Phoenix transports do not limit the number of channels that a single transport process may join. Every phx_join message a client sends over one connection starts a persistent channel process, and the socket process accepts an unbounded number of them. A single unauthenticated client can therefore open one WebSocket or LongPoll connection and stream a large number of phx_join messages, spawning hundreds of thousands of channel processes over that one connection and eventually reaching the BEAM maximum process limit. Once the process table is exhausted the virtual machine can no longer start new processes, denying service to legitimate traffic across the whole node. Because the amplification happens inside a single connection, network-layer connection caps and rate limiting do not mitigate it.<br /> <br /> The fix adds a :max_channels_per_transport option (default 100) that bounds the number of channels a single transport process can join, forcing abusive clients to open many connections instead, where external load balancers and reverse proxies can throttle them.<br /> <br /> This issue affects phoenix: from 0.11.0 before 1.5.15, from 1.6.0-rc.0 before 1.6.17, from 1.7.0-rc.0 before 1.7.24, and from 1.8.0-rc.0 before 1.8.9.
Gravedad CVSS v4.0: ALTA
Última modificación:
09/07/2026