Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-91145

Fecha de publicación:
14/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Activiti through 7.1.0.M6 fails to validate hash-brace deferred expressions in process variables, allowing attackers to bypass expression filtering. Attackers can inject expressions beginning with #{ that are stored and later evaluated in the full Spring context when a mail task uses variable-backed body fields, enabling method invocation on application beans.
Gravedad CVSS v4.0: ALTA
Última modificación:
24/09/2026

CVE-2026-91144

Fecha de publicación:
14/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoint. Attackers holding a share link can supply arbitrary file paths as query parameters to download any file under the shared base directory, bypassing the intended access restrictions.
Gravedad CVSS v4.0: ALTA
Última modificación:
24/09/2026

CVE-2026-91146

Fecha de publicación:
14/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Takahe through 0.11.0 fails to restrict URL schemes in link hrefs within federated post content and profile summaries, allowing remote actors to inject javascript: links. Attackers can deliver federated content with malicious javascript: hrefs that execute in the instance origin when clicked, enabling session hijacking or impersonation of viewers.
Gravedad CVSS v4.0: MEDIA
Última modificación:
23/09/2026

CVE-2026-90828

Fecha de publicación:
14/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible of the file ld/ldelf.c of the component ELF Orphan Section Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet.
Gravedad CVSS v4.0: BAJA
Última modificación:
21/09/2026

CVE-2026-91143

Fecha de publicación:
14/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** goproxy through 15.3 fails to apply HTTP proxy basic authentication to CONNECT tunnel requests, allowing unauthenticated clients to bypass credential requirements. Attackers can issue CONNECT requests to establish tunnels through the authenticated proxy without providing credentials, enabling arbitrary TCP traffic relay and access to restricted destinations.
Gravedad CVSS v4.0: MEDIA
Última modificación:
23/09/2026

CVE-2026-18117

Fecha de publicación:
14/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Concrete CMS 9.0.0 through 9.5.3 is vulnerable to stored XSS via the custom page alias name (customAliasName) because the Edit Alias dialog applied only trim() to the submitted value and performed no input neutralization. An authenticated user holding canWrite (editor) permission on a page could store a malicious alias name that was later rendered unescaped in the administrative Sitemap panel, where it executed automatically in any administrator or editor session that opened the panel, allowing an editor to escalate to administrator through the victim's active session. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N. Thanks Nguyen Manh Thuan for reporting.
Gravedad CVSS v4.0: ALTA
Última modificación:
29/09/2026

CVE-2026-86888

Fecha de publicación:
14/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. A local app may be able to read a persistent account identifier.
Gravedad CVSS v3.1: BAJA
Última modificación:
21/09/2026

CVE-2026-86887

Fecha de publicación:
14/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, visionOS 27. An app may be able to bypass certain Privacy preferences.
Gravedad CVSS v3.1: BAJA
Última modificación:
21/09/2026

CVE-2026-84628

Fecha de publicación:
14/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. A sandboxed app may be able to access the System Keychain.
Gravedad CVSS v3.1: MEDIA
Última modificación:
23/09/2026

CVE-2026-84625

Fecha de publicación:
14/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27, watchOS 27. An app may be able to fingerprint the user.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
23/09/2026

CVE-2026-84624

Fecha de publicación:
14/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A permissions issue was addressed with improved path validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27. A sandboxed app may be able to access restricted files.
Gravedad CVSS v3.1: MEDIA
Última modificación:
23/09/2026

CVE-2026-84623

Fecha de publicación:
14/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27. An app may be able to fingerprint the device.
Gravedad CVSS v3.1: ALTA
Última modificación:
23/09/2026