Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-88344

Fecha de publicación:
22/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** An out-of-bounds read vulnerability exists in the schema lexer of flatcc 4c3b999e. When an exact-length FlatBuffers schema buffer ends with a digit, the integer digit-scan loop in lex() advances past the end of the input buffer and dereferences the out-of-bounds pointer. A specially crafted schema can trigger a one-byte heap buffer over-read, resulting in application crash and denial of service.
Gravedad CVSS v3.1: ALTA
Última modificación:
24/09/2026

CVE-2026-88340

Fecha de publicación:
22/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** An invalid pointer release vulnerability exists in YARA 4.5.8 during deserialization of compiled .yrc rule files. The vulnerability is caused by insufficient validation of external-variable pointers, which may lead to invalid free in yr_rules_destroy() or wild pointer access in yr_object_create(). An attacker can provide a specially crafted .yrc file that causes memory corruption and application crash.
Gravedad CVSS v3.1: ALTA
Última modificación:
25/09/2026

CVE-2026-88418

Fecha de publicación:
22/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** CMSimple 5.24 ships with CSRF protection disabled by default, which turns csrfProtection() into a no-op on every state-changing admin request, and it does not send the csrf_token hidden field in admin forms. Because administrator authentication is cookie-only and no CSRF token is enforced, an unauthenticated attacker can induce a logged-in administrator's browser to issue a forged content-save request with a text payload containing a scripting marker. The marker is stored verbatim into content/content.php; on every subsequent page view evaluate_cmsimple_scripting() (functions.php) executes the marker body with PHP eval() — for all visitors, including unauthenticated ones. This yields persistent remote code execution on the web server.
Gravedad CVSS v3.1: ALTA
Última modificación:
26/09/2026

CVE-2026-88350

Fecha de publicación:
22/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** An integer overflow vulnerability exists in MPack 1.1.1 in mpack_node_cstr_alloc() and mpack_node_utf8_cstr_alloc().
Gravedad CVSS v3.1: MEDIA
Última modificación:
01/10/2026

CVE-2026-88416

Fecha de publicación:
22/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** MCMS 6.1.1 through 6.2.1 has a SQL injection vulnerability in the custom model/form import feature.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
06/10/2026

CVE-2026-87121

Fecha de publicación:
22/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution on the device.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
23/09/2026

CVE-2026-83801

Fecha de publicación:
22/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.37 and 3.1.8, a user with extras.add_relationship or extras.change_relationship permission can store HTML or JavaScript in a Relationship description, and a user with dcim.add_modulefamily or dcim.change_modulefamily permission can store it in a Module Family name. Nautobot assigns these values to form field help_text rendered by render_field.html through Django's |safe filter without adequate neutralization. The stored content executes in the authenticated browser session of any user, including an administrator or superuser, who opens an affected create or edit form. This can enable actions as the victim, session or token theft, and further privilege escalation. This issue is fixed in versions 2.4.37 and 3.1.8.
Gravedad CVSS v3.1: MEDIA
Última modificación:
23/09/2026

CVE-2026-83805

Fecha de publicación:
22/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Nautobot is a Network Source of Truth and Network Automation Platform. From 3.0.0 until 3.1.8, the generic ApprovalWorkflowStageResponse create endpoint does not enforce approver-group membership, change permission on the object under review, or the one-response-per-user restriction applied by the intended approve and deny actions. A user with only extras.add_approvalworkflowstageresponse can submit approved responses directly, while writable user and state fields permit responses to be attributed to arbitrary users. These forged responses can satisfy min_approvers, approve the workflow, and activate its gated ScheduledJob without a legitimate approver. This issue is fixed in version 3.1.8.
Gravedad CVSS v3.1: MEDIA
Última modificación:
26/09/2026

CVE-2026-77322

Fecha de publicación:
22/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.3, WSConnection.Read in sip/transport_ws.go creates a wsutil.Reader without setting MaxFrameSize, allowing NextFrame to accept a client-controlled header.Length before ParseMaxMessageLength is applied. An unauthenticated WS or WSS peer can send a frame header declaring an extremely large payload, causing an oversized allocation or a makeslice length panic before the payload is read and crashing or exhausting memory in the server process. This issue is fixed in version 1.4.3.
Gravedad CVSS v3.1: ALTA
Última modificación:
23/09/2026

CVE-2026-79767

Fecha de publicación:
22/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Gardener implements the automated management and operation of Kubernetes clusters as a service. Prior to 1.142.6, 1.143.3, 1.144.2, and 1.145.0, the customverbauthorizer admission plugin's mustCheckProjectMembers manage-members check compares changes to User subjects but does not account for Group or ServiceAccount subjects in Project.spec.members. A project administrator who lacks manage-members permission can add arbitrary Group or ServiceAccount subjects, including the system:authenticated Group, and thereby grant broad project access. The resulting access can include Shoots, Secrets, and cloud provider credentials. This issue is fixed in versions 1.142.6, 1.143.3, 1.144.2, and 1.145.0.
Gravedad CVSS v3.1: MEDIA
Última modificación:
23/09/2026

CVE-2026-76712

Fecha de publicación:
22/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability exists in the Analytics and Location Engine (ALE) that may allow for unauthorized access, information disclosure, or denial of service. An unauthenticated remote attacker could exploit the vulnerable system by sending specially crafted input or intercepting network communications. Successful exploitation could result in the disclosure of sensitive information, bypass of security controls, or a denial of service condition on the affected system.
Gravedad CVSS v3.1: ALTA
Última modificación:
28/09/2026

CVE-2026-76713

Fecha de publicación:
22/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability exists in the maintenance restore functionality of Analytics and Location Engine (ALE). Successful exploitation of this vulnerability could allow an authenticated remote attacker to gain unauthorized access to the file system with root privileges, potentially resulting in full system compromise.
Gravedad CVSS v3.1: ALTA
Última modificación:
28/09/2026