Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-93841

Fecha de publicación:
18/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** vLLM through 0.29.0 contains a memory corruption vulnerability in the Triton _bincount_kernel where prompt token IDs index the penalty prompt-presence bitset without bounds checking against vocabulary size. Attackers can submit multimodal audio requests with tokens equal to vocabulary size, causing out-of-bounds writes that corrupt concurrent requests' sampler state and alter repetition penalty behavior.
Gravedad CVSS v4.0: MEDIA
Última modificación:
28/09/2026

CVE-2026-93838

Fecha de publicación:
18/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** SGLang versions through 0.5.20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails to validate chunk_idx from ZMQ STAGING_REQ frames in prefill/decode disaggregation deployments. Attackers with access to the decode engine's internal ZMQ rank port can send a frame with an extremely large chunk_idx value, causing the scheduler to allocate memory until the system runs out and terminates the process.
Gravedad CVSS v4.0: ALTA
Última modificación:
22/09/2026

CVE-2026-93031

Fecha de publicación:
18/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This is due to the import action being registered for unauthenticated users via wp_ajax_nopriv_, a missing capability check in can_import(), and the imported file's extension and contents not being validated against get_allowed_mime_types() before it is written to the uploads directory. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload files that may be executable, which makes remote code execution possible.
Gravedad CVSS v3.1: ALTA
Última modificación:
21/09/2026

CVE-2026-92708

Fecha de publicación:
18/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. In versions 5.1.0 through 5.9.2, stringify and uneval functions serialize a typed array by emitting its entire backing ArrayBuffer rather than only the view, so serializing a Node Buffer, whose backing store is a process-wide shared pool, discloses up to 64 KB of unrelated process memory, including bytes from other in-flight requests. In a server-side-rendered framework such as SvelteKit or Nuxt, a public page whose load() returns a small Buffer, or that reads a small file, can therefore ship another user's request body or Authorization header in its HTML without authentication. Because this occurs during serialization, it fires on every such render and is not mitigated by the parse/unflatten prototype-pollution and denial-of-service guards, which only apply when parsing untrusted input. As a workaround, convert Node Buffer objects to Uint8Array before serialization. This issue has been fixed in version 5.9.3.
Gravedad CVSS v3.1: ALTA
Última modificación:
23/09/2026

CVE-2026-91202

Fecha de publicación:
18/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in cockpit-files. A low-privileged local user can exploit this vulnerability by crafting a directory containing a symbolic link (symlink) and then using the privileged "Paste as owner" function. This allows for arbitrary file ownership changes outside the intended pasted directory, leading to a compromise of data integrity. In some cases, this could also lead to reduced confidentiality if the new ownership grants unauthorized read access. Exploitation requires user interaction to select a non-original owner during the paste operation.
Gravedad CVSS v3.1: MEDIA
Última modificación:
22/09/2026

CVE-2026-91203

Fecha de publicación:
18/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in cockpit-files. This vulnerability allows a local attacker to exploit a timing issue, known as a symlink race condition, during privileged file operations such as changing file ownership or permissions. By manipulating directory entries and winning this race, the attacker can redirect these operations to unintended files. This could lead to unauthorized changes in file ownership and permissions on arbitrary files, potentially compromising system integrity and availability by altering system or application states or rendering services unusable.
Gravedad CVSS v3.1: MEDIA
Última modificación:
22/09/2026

CVE-2026-91205

Fecha de publicación:
18/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in cockpit-files. A local unprivileged attacker can exploit a race condition during directory creation with owner assignment. By controlling a writable parent directory, the attacker can replace a newly created directory with a symbolic link (symlink) before the ownership change operation (chown) is applied. This allows the attacker to redirect the ownership change to an arbitrary file, potentially leading to information disclosure or unauthorized modification of sensitive files.
Gravedad CVSS v3.1: MEDIA
Última modificación:
22/09/2026

CVE-2026-84241

Fecha de publicación:
18/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization.
Gravedad CVSS v3.1: ALTA
Última modificación:
06/10/2026

CVE-2026-84105

Fecha de publicación:
18/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.
Gravedad CVSS v3.1: ALTA
Última modificación:
06/10/2026

CVE-2026-84106

Fecha de publicación:
18/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
Gravedad CVSS v3.1: ALTA
Última modificación:
06/10/2026

CVE-2026-84108

Fecha de publicación:
18/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of input during web page generation.
Gravedad CVSS v3.1: ALTA
Última modificación:
06/10/2026

CVE-2026-84239

Fecha de publicación:
18/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.
Gravedad CVSS v3.1: ALTA
Última modificación:
06/10/2026