Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-81474

Fecha de publicación:
17/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Gravedad CVSS v3.1: ALTA
Última modificación:
01/10/2026

CVE-2026-81439

Fecha de publicación:
17/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.
Gravedad CVSS v3.1: BAJA
Última modificación:
01/10/2026

CVE-2026-81438

Fecha de publicación:
17/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
Gravedad CVSS v3.1: BAJA
Última modificación:
01/10/2026

CVE-2026-66269

Fecha de publicación:
17/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.
Gravedad CVSS v3.1: ALTA
Última modificación:
06/10/2026

CVE-2026-78426

Fecha de publicación:
17/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equivalent spelling of the RSA signature field until the token validity expires.
Gravedad CVSS v4.0: BAJA
Última modificación:
28/09/2026

CVE-2026-78427

Fecha de publicación:
17/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** The NeuVector admission webhook silently excludes containers from policy evaluation when their image path matches one of three hardcoded service mesh sidecar images. Since the image path is entirely controlled by the workload author, any user capable of deploying workloads can evade admission deny rules simply by naming their image path after one of these sidecar images.
Gravedad CVSS v4.0: MEDIA
Última modificación:
28/09/2026

CVE-2026-78428

Fecha de publicación:
17/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently
Gravedad CVSS v4.0: ALTA
Última modificación:
28/09/2026

CVE-2026-78425

Fecha de publicación:
17/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Authorised users of outside applications behind the same corporate identity provider (IdP), for example, a wiki, a ticketing system, an expenses tool, or anything they legitimately hold an account on can log into their system via SAML SSO. The IdP issues an assertion to them. If that assertion is presented to NeuVector, NeuVector accepts it because the only thing distinguishing "an assertion for NeuVector" from "an assertion for the wiki" is the element, and the `NotInAudience` warning that reports the mismatch is never read.
Gravedad CVSS v4.0: ALTA
Última modificación:
28/09/2026

CVE-2026-87963

Fecha de publicación:
17/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username request parameter before using it in a SQL query, and reads it before WordPress applies its request escaping, allowing unauthenticated attackers to perform SQL injection and read arbitrary database contents including administrator password hashes.
Gravedad CVSS v3.1: ALTA
Última modificación:
20/09/2026

CVE-2026-44940

Fecha de publicación:
17/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecure locations rather than managing them securely. An attacker with minimal access could obtain the token to gain unauthorized access or escalate privileges within the observability environment.
Gravedad CVSS v3.1: MEDIA
Última modificación:
29/09/2026

CVE-2026-25281

Fecha de publicación:
17/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/09/2026

CVE-2026-25282

Fecha de publicación:
17/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/09/2026