Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-77102

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** CommServe contained a heap-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.
Gravedad CVSS v4.0: ALTA
Última modificación:
08/09/2026

CVE-2026-75021

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** fastify-cli starts the Node.js Inspector when a debug flag is used, but it ignores the explicit bind address the user supplies and binds the Inspector to a broadly reachable address instead of the intended loopback. As a result the debugging interface can be exposed beyond the local machine, and because the Inspector protocol allows arbitrary code evaluation, a remote party that reaches it can achieve remote code execution on the developer's machine. This affects fastify-cli from 1.5.0 up to 8.0.1. Users should upgrade to fastify-cli 8.0.1, which honors the configured Inspector bind address.
Gravedad CVSS v3.1: ALTA
Última modificación:
08/09/2026

CVE-2026-62437

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** When guests are terminated, various pieces of cleanup need carrying out.<br /> The cleaning up of PCI devices which were assigned to guests, and the<br /> associated removal of tracking structures for IRQs used by the devices<br /> occurs relatively early in the process. Unfortunately after that point<br /> the guest about to be terminated could cause its device model (DM) to<br /> re-establish such tracking structures, by having it bind one or more IRQs<br /> anew. While some of those tracking structures would still be cleaned up<br /> later on, at least one would not be.
Gravedad: Pendiente de análisis
Última modificación:
08/09/2026

CVE-2026-19203

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A client may issue specially crafted HTTP/1.1 chunked requests to a Jetty server that cause Jetty and an intermediary proxy to interpret different request boundaries, potentially resulting in HTTP request smuggling.<br /> <br /> <br /> <br /> <br /> This is caused by Jetty accepting a lone LF character as a terminator in parts of chunked request parsing. Depending on the Jetty version and configured HTTP compliance mode, this may occur in chunk extensions, chunk data termination, or trailer termination.
Gravedad CVSS v4.0: ALTA
Última modificación:
08/09/2026

CVE-2026-11573

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Uncontrolled recursion in Qt&amp;#39;s QDomDocument serialization (QtXml) lets deeply nested untrusted XML crash the app via stack exhaustion (DoS only).
Gravedad CVSS v4.0: ALTA
Última modificación:
08/09/2026

CVE-2026-12611

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A client may issue HTTP/2 requests to a Jetty server that result in blocking writes that are never unblocked, eventually causing all threads to be blocked and the whole server to become unresponsive.<br /> <br /> <br /> <br /> <br /> This is caused by a race condition in the server when handling RST_STREAM frames and GOAWAY frames sent by the client.<br /> <br /> <br /> <br /> <br /> The race condition "resets" the HTTP2Flusher.terminated, previously set to a non-null value, to the null value, allowing entries to be enqueued in the flusher that however will never be processed. These unprocessed entries are the ones that would unblock the write-blocked threads.
Gravedad CVSS v4.0: ALTA
Última modificación:
08/09/2026

CVE-2026-86713

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in the load_mon module&amp;#39;s stop path where exit_and_cleanup() deletes the LoadMon object and frees the performance counter before perf_end() attempts to access it. Attackers can trigger this vulnerability by issuing the load_mon stop command from any PXH or MAVLink shell, causing reads and writes through freed memory that corrupt heap objects and destabilize the flight stack.
Gravedad CVSS v4.0: ALTA
Última modificación:
08/09/2026

CVE-2026-86714

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** PX4 Autopilot through 1.17.0 contains a stack buffer over-read vulnerability in the netman system command that fails to validate interface name length. Attackers can supply interface names of 74 bytes or more via the -i option to read beyond buffer boundaries, leaking stack memory to console output or writing it into persistent network configuration files.
Gravedad CVSS v4.0: MEDIA
Última modificación:
08/09/2026

CVE-2026-80219

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.
Gravedad CVSS v3.1: ALTA
Última modificación:
21/09/2026

CVE-2026-76931

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in all versions up to, and including, 3.3.205 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability can only be exploited when the &amp;#39;Directly link to project&amp;#39; plugin setting is disabled.
Gravedad CVSS v3.1: MEDIA
Última modificación:
08/09/2026

CVE-2026-77968

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in hawtio-operator. The operator&amp;#39;s ClusterRole grants secrets: [create, get, list, update, watch] across all namespaces. While the operator uses a controller-runtime label-selector cache as a memory optimization, the ServiceAccount token authorizes read access to every Secret in the cluster. The operator also bypasses the cache via direct API calls. Compromise of the operator pod would yield read access to every Secret in the cluster, including bootstrap tokens, cloud credentials, and other operators&amp;#39; secrets.
Gravedad CVSS v3.1: ALTA
Última modificación:
08/09/2026

CVE-2026-78234

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint client certificates with a Subject Common Name (CN) supplied by the author of a namespaced Hawtio custom resource. Because the operator ships a ClusterRole that aggregates Hawtio CR permissions into the edit and admin roles, any user with edit access in any namespace can obtain a Service-CA-signed certificate with an arbitrary subject. This certificate can be used to impersonate any in-cluster service identity to peers that trust the Service CA for client authentication, including Jolokia agents and other Service-CA-trusting components.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
08/09/2026