Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-82053

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A security issue exists in MongoDB's LDAP authorization integration where pooled LDAP connections can retain stale authentication identities after user authentication under certain configurations. Subsequent authorization queries may execute under an unintended LDAP identity rather than the expected one. This can result in incorrect role assignments based on the LDAP directory's access control configuration, potentially allowing an authenticated user to acquire elevated privileges that were not intended by the deployment's authorization policy.
Gravedad CVSS v4.0: ALTA
Última modificación:
08/09/2026

CVE-2026-81531

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** An information<br /> disclosure vulnerability has been identified in Omada Controller.  An API endpoint intended for Controller initialization<br /> remains accessible after completion and may disclose account-related<br /> information to unauthenticated remote users. <br /> <br /> <br /> <br /> <br /> <br /> <br /> Successful<br /> exploitation may allow an attacker to remote query the affected endpoint that<br /> may facilitate user enumeration and subsequent attacks targeting administrative<br /> accounts.
Gravedad CVSS v4.0: MEDIA
Última modificación:
21/09/2026

CVE-2026-82052

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** The $regexFindAll expression can be used by an authenticated user who can run aggregation pipeline stages to crash a MongoDB server (mongod). Under certain specific conditions the  regex match can start in the middle of a multi-code-unit character, triggering an assertion during query execution.
Gravedad CVSS v4.0: ALTA
Última modificación:
08/09/2026

CVE-2026-79569

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Movie_Recommend v1.0.0 was discovered to contain a SQL injection vulnerability in the sort parameter at /loadingmore. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
08/09/2026

CVE-2026-78997

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context of any origin. An attacker hosts a specially crafted URL on a UC-owned domain (via a reflected XSS) that leverages the browser&amp;#39;s internal JavaScript bridge to register a deferred callback, navigate the tab to a victim site, and then execute attacker-controlled code on that site when a login dialog is dismissed.
Gravedad: Pendiente de análisis
Última modificación:
08/09/2026

CVE-2026-79570

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/data. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.
Gravedad: Pendiente de análisis
Última modificación:
08/09/2026

CVE-2026-75156

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login. Deployments are affected only when the FAB auth manager is configured with Azure AD as an OAuth provider. Because the signing keys are fetched from Microsoft&amp;#39;s **multi-tenant** JWKS endpoint, an `id_token` minted in *any* Azure tenant — including one the attacker creates — passes signature verification, and the username and role assignments are then read from that attacker-controlled token. Anyone able to register an Azure tenant can therefore authenticate to the Airflow UI with no prior access to the deployment.<br /> <br /> The fix for **CVE-2026-59243** was incomplete, and this advisory closes the remaining gap: that fix made the provider verify the `id_token` signature, but did not add issuer or audience checks. Operators who already applied the CVE-2026-59243 fix are **still affected and must upgrade again** — 3.7.3 is the release that shipped that fix, so every version containing it falls inside this affected range. Upgrade to apache-airflow-providers-fab `3.8.1` or later.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
08/09/2026

CVE-2026-78216

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** AshLua exposes Ash read actions to Lua scripts run through an eval action. A read call accepts an operation (list, min, max, first, sum, avg) that builds an ad-hoc Ash.Query.Aggregate over a named field and returns its raw value.<br /> <br /> Ash field policies redact forbidden fields on returned records (replacing them with %Ash.ForbiddenField{}), but that redaction does not apply to aggregate values. A script could therefore read a field the calling actor&amp;#39;s field policies forbid by requesting it as an aggregate instead of as a field. This includes fields that are public? true but restricted per-actor by a field policy, such as sensitive PII. The prior hardening only enforced the exposed-field allow-list (field visibility), which is a separate axis from per-actor field-policy authorization.<br /> <br /> The fix authorizes the aggregated field against the resource&amp;#39;s field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible.<br /> <br /> This issue affects ash_lua: from 0.1.0 before 0.2.2.
Gravedad CVSS v4.0: MEDIA
Última modificación:
08/09/2026

CVE-2026-78230

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** AshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type (min, max, sum, avg) that builds an ad-hoc Ash.Query.Aggregate over a named field and returns its raw value.<br /> <br /> Ash field policies redact forbidden fields on returned records (replacing them with %Ash.ForbiddenField{}), but that redaction does not apply to aggregate values. A tool caller could therefore read a field the calling actor&amp;#39;s field policies forbid by requesting it as an aggregate; min/max in particular return an actual field value. This includes fields that are public? true but restricted per-actor by a field policy, such as sensitive PII. The tool&amp;#39;s existing check only required the field to be public, which is a separate axis from per-actor field-policy authorization.<br /> <br /> The fix authorizes the aggregated field against the resource&amp;#39;s field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible.<br /> <br /> This issue affects ash_ai: from 0.1.0 before 1.0.3.
Gravedad CVSS v4.0: MEDIA
Última modificación:
08/09/2026

CVE-2026-52307

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** An authenticated stored cross-site scripting (XSS) vulnerability in the Column Management component of ClassCMS 1CMS v5.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the title field.
Gravedad: Pendiente de análisis
Última modificación:
08/09/2026

CVE-2026-47625

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could abuse missing authorization. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service.
Gravedad CVSS v3.1: ALTA
Última modificación:
08/09/2026

CVE-2026-22575

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** An improper access control vulnerability in Fortinet FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.10, FortiManager 7.2 all versions, FortiManager Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.4.1 through 7.4.10, FortiManager Cloud 7.2 all versions may allow an administrator to bypass the approval process for workflow sessions via crafted HTTP or HTTPs requests.
Gravedad CVSS v3.1: MEDIA
Última modificación:
08/09/2026