Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-63104

Fecha de publicación:
22/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Kaneo versions 2.3.12 before 2.12.2 contain a missing authorization vulnerability that allows authenticated workspace members with viewer or member roles to delete and modify tasks beyond their assigned permissions by exploiting the bulk task endpoint that omits workspace permission checks. Attackers can send requests to the PATCH /api/task/bulk endpoint, which verifies only workspace membership without calling the role-based permission check enforced on all other task endpoints, to permanently delete all tasks or modify task status, priority, assignee, due date, and labels in a workspace.
Gravedad CVSS v4.0: ALTA
Última modificación:
22/09/2026

CVE-2026-59991

Fecha de publicación:
22/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to 1.17.4, PSDImage.composite() and PSDImage.numpy() allocated output buffers from attacker-controlled PSD header geometry, including width, height, channels, depth, and per-layer rectangles, before validating those values against the available file data. A tiny crafted PSD could therefore cause multi-gigabyte memory allocation, and PSDImage.composite() could return a black image with only a warning instead of raising an exception. Services that composite untrusted PSD files could be terminated by out-of-memory handling. This issue is fixed in version 1.17.4.
Gravedad CVSS v3.1: ALTA
Última modificación:
23/09/2026

CVE-2026-63627

Fecha de publicación:
22/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** mppx is a TypeScript interface for machine payments protocol. Prior to 0.8.2, FeePayerPolicy in src/tempo/internal/fee-payer.ts used decodeFunctionData to validate fee-sponsored calldata but did not reject trailing bytes. A client could append nonzero padding that increased intrinsic calldata gas while gas_limit and max_fee_per_gas remained within policy caps, causing the server fee_payer wallet to pay substantially more than the decoded transaction required. The tested 16 KB header limit bounded the demonstrated padding to about 5,500 bytes and produced approximately five times the normal transaction fee. This issue is fixed in version 0.8.2.
Gravedad CVSS v4.0: MEDIA
Última modificación:
23/09/2026

CVE-2026-62985

Fecha de publicación:
22/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** request-filtering-agent is an http(s).Agent implementation that blocks requests to Private/Reserved IP addresses. Prior to 3.2.1, RequestFilteringHttpAgent and RequestFilteringHttpsAgent synchronously threw from createConnection when rejecting a literal private-IP host such as 169.254.169.254 or 127.0.0.1. Because Node.js http.request and http.get expect connection failures to be delivered asynchronously, the throw bypassed req.on('error') and became an uncaught exception that could terminate the application process. Hostnames resolved through the asynchronous lookup path were not affected by this error-delivery asymmetry. This issue is fixed in version 3.2.1.
Gravedad CVSS v3.1: ALTA
Última modificación:
26/09/2026

CVE-2026-28324

Fecha de publicación:
22/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. Installations configured in a non-default and non-secure configuration are affected.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
24/09/2026

CVE-2026-28325

Fecha de publicación:
22/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is configured to use a specific communication mode.
Gravedad CVSS v3.1: ALTA
Última modificación:
24/09/2026

CVE-2026-47116

Fecha de publicación:
22/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** LTSecurity LTK3500SF contains a hard-coded credentials vulnerability where the root and guest account passwords are stored in /etc/shadow as weak hashes recoverable with dictionary-based cracking tools. The recovered credentials authenticate against the device's Telnet and SSH services and grant root-level access to the operating system. These services are not confirmed to start automatically at boot, so exploitation requires Telnet or SSH to be running, whether enabled by the device configuration or started manually.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
24/09/2026

CVE-2026-58268

Fecha de publicación:
22/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.1, ParserStream.parseSingle in sip/parser_stream.go allocates a SIP body buffer from the client-controlled Content-Length header before ParseMaxMessageLength is enforced. An unauthenticated peer can send a stream-transport message over TCP, TLS, WS, or WSS with an oversized declared length, causing excessive memory allocation and denial of service before the body is read. This issue is fixed in version 1.4.1.
Gravedad CVSS v3.1: ALTA
Última modificación:
23/09/2026

CVE-2026-95861

Fecha de publicación:
22/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A malicious actor with access to the network could exploit an Uncontrolled Recursion vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/09/2026

CVE-2026-95862

Fecha de publicación:
22/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/09/2026

CVE-2026-95831

Fecha de publicación:
22/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL.<br /> <br /> The generate_certificate runs a Python script saved as a certificate file. The pyhton script attempts to retrieve code from a hardcoded http URL that is obfuscated with base64 encoding and run the response body directly.<br /> <br /> The impact is that arbitrary code can be invoked as the user, without a dropped script being saved on the affected host.<br /> <br /> The releases have no test scripts nor build hooks. The intention may have been to trigger the payload after installation.<br /> <br /> For version 1.01, the dropper script is in lib/Crypt/SelfCertificate/sample/validate.p12.<br /> <br /> For version 1.05, the dropper script is in lib/Crypt/SelfCertificate/sample/cert7.pem.<br /> <br /> The SHA-256 digests of the files are<br /> <br /> fbff21f45ff748365062a5e36fb2d72558cad82a507a6f357f320b4fcdf07760 Crypt-SelfCertificate-1.01.tar.gz<br /> 27b2d2d3174ad771474fff2521f5084ec231e9218ea8c832515aef1cbd5897bc lib/Crypt/SelfCertificate/sample/validate.p12<br /> <br /> 9fdfa7d69b034b77d4510cda567e8da1e486ca81c7daaadc5732a45c41d71991 Crypt-SelfCertificate-1.05.tar.gz<br /> 27b2d2d3174ad771474fff2521f5084ec231e9218ea8c832515aef1cbd5897bc lib/Crypt/SelfCertificate/sample/cert7.pem
Gravedad CVSS v3.1: ALTA
Última modificación:
23/09/2026

CVE-2026-94462

Fecha de publicación:
22/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Spree is an open source e-commerce solution built with Ruby on Rails. From 5.4.0 until 5.4.4 and 5.5.4, PATCH /api/v3/store/carts/:id/associate in Spree::Api::V3::Store::CartsController#associate uses find_cart_for_association to locate a cart by prefixed_id but does not require a cart token or otherwise verify possession of the selected guest cart. An authenticated customer can derive reversible prefixed cart IDs, associate an eligible guest cart with the attacker&amp;#39;s account, and receive billing and shipping address data from the cart. Exploitation requires a guest cart with address data on a store that does not require login for checkout, and reassignment can also disrupt the guest&amp;#39;s in-progress cart. This issue is fixed in versions 5.4.4 and 5.5.4.
Gravedad CVSS v3.1: ALTA
Última modificación:
23/09/2026