Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-26084

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
08/09/2026

CVE-2026-20293

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with the role of user or admin&amp;nbsp;or an unauthenticated attacker with physical access to an affected device to bypass UEFI Secure Boot validation checks and execute unauthorized software.<br /> <br /> This vulnerability is due to the availability of memory write commands in the UEFI Shell while UEFI Secure Boot is enabled on a device. An attacker could exploit this vulnerability by selecting the UEFI Shell boot option at boot time and using available shell commands to modify UEFI memory variables. A successful exploit could allow the attacker to manipulate the preboot environment, overwrite UEFI Secure Boot-related memory values, and execute unauthorized software on the affected device.
Gravedad CVSS v3.1: ALTA
Última modificación:
08/09/2026

CVE-2026-16497

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause excessive iteration. A successful exploit of this vulnerability might lead to denial of service.
Gravedad CVSS v3.1: ALTA
Última modificación:
08/09/2026

CVE-2026-86853

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A malicious webpage could repeatedly trigger external URL schemes, causing system prompts or external application launches. This could make Firefox for iOS temporarily unusable until the page is closed. This vulnerability was fixed in Firefox for iOS 155.1.
Gravedad CVSS v3.1: MEDIA
Última modificación:
08/09/2026

CVE-2026-86840

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution. A signed account can supply an arbitrary registered `channel_id` when minting tokens without verifying that the caller is authorized to mint on behalf of that channel. This allows an attacker to inflate a channel&amp;#39;s recorded mint volume and cause protocol commission payments to be disproportionately distributed to that channel during commission settlement.
Gravedad: Pendiente de análisis
Última modificación:
08/09/2026

CVE-2026-86737

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** snipe-it versions before 8.7.0 fail to enforce asset view authorization in the GET /hardware/{asset}/barcode endpoint. Authenticated attackers can iterate asset IDs to retrieve barcodes and enumerate asset tags across tenants, including soft-deleted and cross-company assets.
Gravedad CVSS v4.0: MEDIA
Última modificación:
08/09/2026

CVE-2026-86738

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability in the Custom CSS field due to incomplete sanitization that reverses HTML encoding on greater-than and double-quote characters. Superusers can plant malicious CSS payloads using @import and url() references to exfiltrate CSRF tokens from other superusers via attribute-selector rules, enabling account takeover.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
08/09/2026

CVE-2026-86735

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** snipe-it versions before 8.7.0 contain a server-side request forgery vulnerability in the ExternalUrl validation rule that fails to detect IPv6 transition addresses encoding private IPv4 targets. Attackers with super-admin privileges can configure webhook URLs using NAT64, 6to4, or Teredo transition addresses to bypass SSRF guards and access internal services or cloud metadata endpoints.
Gravedad CVSS v4.0: MEDIA
Última modificación:
08/09/2026

CVE-2026-86736

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** snipe-it before 8.7.0 contains an incorrect calculation vulnerability in checkout request handling that allows authenticated users to corrupt the assets.requests_counter through duplicate submissions and cancellations without active requests. Attackers can repeatedly call cancel endpoints without active requests to drive the counter negative, or submit duplicate checkout requests to inflate the counter, misrepresenting pending demand in the admin queue.
Gravedad CVSS v4.0: MEDIA
Última modificación:
08/09/2026

CVE-2026-86731

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Craft CMS versions 5.0.0-RC1 through 5.10.11 are missing an admin-target guard in UsersController::actionActivateUser (the users/activate-user action). While the action requires the administrateUsers permission, it does not call requireAdmin() when the targeted user is an administrator, unlike the mirror action actionDeactivateUser. As a result, an authenticated control panel user who is not an administrator but holds the administrateUsers permission can activate a pending or deliberately deactivated administrator account, which can lead to permission escalation when combined with resetting that account&amp;#39;s password. The issue is fixed in Craft CMS 5.10.12.
Gravedad CVSS v4.0: ALTA
Última modificación:
08/09/2026

CVE-2026-86732

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Craft CMS versions before 5.10.12 contain a remote code execution vulnerability in the element-index endpoint that allows authenticated content editors to instantiate arbitrary classes through the criteria parameter. Attackers can inject a malicious class via criteria[withTransforms][0][class] that reaches ImageTransforms::normalizeTransform(), then use a PHP gadget chain with yii\rbac\PhpManager to execute code by pointing itemFile to a request log containing PHP payload in the User-Agent header.
Gravedad CVSS v4.0: ALTA
Última modificación:
08/09/2026

CVE-2026-86733

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Snipe-IT before 8.7.0 streams the SQL entry from an uploaded backup archive directly into the MySQL/MariaDB command-line client (`mysql`) without the --binary-mode flag, so the client interprets lines beginning with backslash commands such as `\!` as local shell commands. An authenticated superadministrator who uploads a crafted ZIP backup (POST /admin/backups/upload) and triggers a restore (POST /admin/backups/restore/{filename}) without the optional `clean` sanitizer parameter — which is not applied by default because DB_SANITIZE_BY_DEFAULT is false — can execute arbitrary OS commands as the web application&amp;#39;s operating-system user, exposing application secrets (including database credentials and APP_KEY) and allowing modification of application-writable files and data. Version 8.7.0 adds the --binary-mode flag to the client invocation.
Gravedad CVSS v4.0: ALTA
Última modificación:
08/09/2026