Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-76960

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web server on their behalf. This results in a low impact on confidentiality and integrity. There is no impact on availability.
Gravedad CVSS v3.1: BAJA
Última modificación:
08/09/2026

CVE-2026-76962

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** SAP S/4HANA (Manage Bank Chains app) does not perform sufficient authorization checks within certain affected functionality. An attacker with low privileges could send specially crafted requests to delete specific entries that should not be accessible to them. This results in a low impact on availability. There is no impact on confidentiality and integrity.
Gravedad CVSS v3.1: MEDIA
Última modificación:
08/09/2026

CVE-2026-76961

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web server on their behalf. This results in a low impact on confidentiality and integrity. There is no impact on availability.
Gravedad CVSS v3.1: BAJA
Última modificación:
08/09/2026

CVE-2026-66768

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating a connected backend system to trigger affected functionality. This could allow arbitrary command execution on the victim's machine, leading to a high impact on the confidentiality, integrity, and availability of the affected system.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
09/09/2026

CVE-2026-58240

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to register an unauthorized component and potentially perform unauthorized actions within the application environment, resulting in a high impact on the confidentiality, integrity, and availability of the affected system.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
09/09/2026

CVE-2026-66767

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session under narrow timing conditions. Successful exploitation could result in high impact on confidentiality and integrity, with low impact on availability of the application.
Gravedad CVSS v3.1: ALTA
Última modificación:
09/09/2026

CVE-2026-58234

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** SAP Process Integration (SOAP Adapter) allows a privileged user to send specially crafted requests containing deeply nested entity definitions, which under certain conditions could temporarily increase processor load and degrade system responsiveness. Successful exploitation results in low impact on availability with no impact on confidentiality and integrity.
Gravedad CVSS v3.1: BAJA
Última modificación:
08/09/2026

CVE-2026-44766

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** SAP S/4HANA (Intercompany Matching and Reconciliation) allows a low-privileged authenticated user to inject malicious input into certain functions, which may be processed by the database without proper validation. This could allow the user to access sensitive information, resulting in high impact on confidentiality, with no impact on integrity and availability of the application.
Gravedad CVSS v3.1: MEDIA
Última modificación:
08/09/2026

CVE-2026-44756

Fecha de publicación:
08/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
22/09/2026

CVE-2026-86542

Fecha de publicación:
07/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory. Attackers can supply traversal sequences in the name parameter to escape the imports directory and overwrite arbitrary files writable by the server process.
Gravedad CVSS v4.0: ALTA
Última modificación:
08/09/2026

CVE-2026-86543

Fecha de publicación:
07/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthenticated /api/tunnel/start endpoint to provision a public tunnel and republish the API at a publicly accessible address.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
08/09/2026

CVE-2026-86544

Fecha de publicación:
07/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with read-restricted sessions can exploit code.replace to modify permission configurations and escalate privileges on subsequent calls.
Gravedad CVSS v4.0: ALTA
Última modificación:
08/09/2026