Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-16006

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Exposure of Sensitive System Information to an Unauthorized Control Sphere in Armoury Crate driver allows a local user to obtain kernel virtual addresses via a crafted IOCTL request by bypassing the driver&amp;#39;s verification, potentially providing further insight into the kernel memory layout.Refer to the &amp;#39;<br /> Security Update for Armoury Crate App  &amp;#39; section on the ASUS Security Advisory for more information.
Gravedad CVSS v4.0: MEDIA
Última modificación:
08/09/2026

CVE-2026-86510

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Gravedad CVSS v4.0: ALTA
Última modificación:
08/09/2026

CVE-2026-76967

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could replace this data with specially crafted content. When the application is next launched, the crafted content is processed and could lead to arbitrary code execution in the context of the user. This results in a high impact on confidentiality, integrity and availability of the application.
Gravedad CVSS v3.1: ALTA
Última modificación:
09/09/2026

CVE-2026-82710

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project usage_rules allows a malicious package publisher to inject terminal control sequences into the output of mix usage_rules.search_docs.<br /> <br /> mix usage_rules.search_docs searches Hex documentation through search.hexdocs.pm, which indexes the documentation of every published package, and prints the matching results (title, package, type, doc reference, and highlighted snippets) to the terminal. The formatter in Mix.Tasks.UsageRules.SearchDocs interpolated those publisher-controlled fields verbatim, neutralizing no terminal control characters; the only transform it applied adds escape sequences rather than removing them. A malicious package can embed ANSI terminal escape sequences (cursor movement, line erase, carriage returns, OSC 52 clipboard writes) in its indexed documentation, so when a developer runs a search that surfaces those docs the sequences reach the terminal unchanged — forging the displayed hexdocs URL or a suggested command, hiding text, or writing to the clipboard. No authentication or privileged position is required; only publishing a package.<br /> <br /> This issue affects usage_rules: from 0.1.18 before 1.2.8.
Gravedad CVSS v4.0: BAJA
Última modificación:
08/09/2026

CVE-2026-76963

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Due to a missing authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform, an authenticated attacker could gain unauthorized access to sensitive system configuration information. Successful exploitation could result in exposure of security relevant settings and internal system details, resulting in low impact on confidentiality while integrity and availability remain unaffected.
Gravedad CVSS v3.1: MEDIA
Última modificación:
08/09/2026

CVE-2026-76968

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state, resulting in information disclosure. This disclosed information could potentially be used to facilitate further attacks. This vulnerability has a high impact on the confidentiality of the application, with no impact on integrity or availability.
Gravedad CVSS v3.1: MEDIA
Última modificación:
08/09/2026

CVE-2026-76969

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** @sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially crafted requests to obtain sensitive credentials and abuse them to replace or delete tenant data. Successful exploitation can result in a high impact on availability and integrity of the application. There may also be partial impact to the confidentiality of business data.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
08/09/2026

CVE-2026-76971

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Due to a Server-Side Request Forgery (SSRF) vulnerability in SAP Manufacturing Integration and Intelligence, an attacker could cause the server to initiate arbitrary outbound requests. If processed by the application, this behavior could be combined with XML/XSL processing to enable execution of scripts. Successful exploitation could result in a low impact on the confidentiality, integrity, and availability of the application.
Gravedad CVSS v3.1: MEDIA
Última modificación:
08/09/2026

CVE-2026-76977

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** SAP UI5 does not sufficiently validate the parent frame&amp;#39;s origin against the configured allowlist. An unauthenticated attacker could host a malicious page to bypass framing restrictions. If an authenticated victim visits the attacker&amp;#39;s page and interacts with it, the attacker could trick the victim into performing unintended actions, resulting in a low impact on integrity. There is no impact on confidentiality and availability.
Gravedad CVSS v3.1: MEDIA
Última modificación:
08/09/2026

CVE-2026-86509

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack can only be done within the local network. The exploit has been published and may be used.
Gravedad CVSS v4.0: ALTA
Última modificación:
08/09/2026

CVE-2026-76958

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. An attacker with low privileges could submit specially crafted XML payloads containing malicious external entity declarations. Successful exploitation could allow the attacker to read sensitive file contents from the server and expose them through monitoring or logging output, resulting in a high impact on confidentiality. It could also lead to resource exhaustion, causing a low impact on availability. There is no impact on integrity.
Gravedad CVSS v3.1: ALTA
Última modificación:
08/09/2026

CVE-2026-76959

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web server on their behalf. This results in a low impact on confidentiality and integrity. There is no impact on availability.
Gravedad CVSS v3.1: MEDIA
Última modificación:
08/09/2026