Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-89013

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Dolibarr 23.0.4 before 24.0.1 contains an authorization bypass vulnerability that allows unauthenticated attackers to read arbitrary files through the document storage endpoints by supplying a crafted hashp parameter value. Attackers can send a request with hashp=shared to skip token validation while satisfying the authorization condition in htdocs/document.php and htdocs/viewimage.php, gaining access to application logs, uploaded business documents, database backups containing password hashes, and files belonging to other multicompany entities.
Gravedad CVSS v4.0: ALTA
Última modificación:
23/09/2026

CVE-2026-70341

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
Gravedad CVSS v3.1: ALTA
Última modificación:
06/10/2026

CVE-2026-71641

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via thenteraction between traj_server, poscmd_2_odom, and the EGOReplanFSM emergency recovery logic
Gravedad CVSS v3.1: ALTA
Última modificación:
22/09/2026

CVE-2026-71644

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause unsafe trajectory planning and potential UAV collisions via a missing default case in the FSM that stops publishing swarm trajectories when the drone enters IDLE
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
22/09/2026

CVE-2026-71416

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Headroom compresses data before the data reaches a large language model. Prior to version 0.35.0, the Headroom WebSocket server does not validate the `Origin` header of incoming client WebSocket requests before forwarding the request to the upstream server, allowing malicious WebSocket clients to perform arbitrary LLM requests without authentication. This can be exploited by a malicious WebSocket client executed in a traditional or headless browser such as lightpanda, if the browser has access to the Headroom proxy and the OpenAI API key is stored in the `OPENAI_API_KEY` environment variable. Version 0.35.0 fixes the issue.
Gravedad CVSS v3.1: ALTA
Última modificación:
30/09/2026

CVE-2026-57843

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** NetBSD contains an information disclosure vulnerability in mm_open() within sys/dev/mm.c that allows unprivileged local users to obtain real kernel virtual addresses by opening world-accessible devices such as /dev/null or /dev/zero, which incorrectly receive the PK_KMEM process flag. Attackers can exploit this misconfigured flag to bypass the CANSEE_KPTR obfuscation mechanism and read kernel virtual addresses for sensitive kernel structures including struct proc, kauth_cred, filedesc, and vmspace via sysctl KERN_PROC queries.
Gravedad CVSS v4.0: MEDIA
Última modificación:
24/09/2026

CVE-2026-57842

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** NetBSD contains a use-after-free and double-free vulnerability in msg_recv_copyin() within the COMPAT_NETBSD32 compatibility layer due to a missing return statement before the cleanup label on the success path. Any local user able to execute a 32-bit binary on a 64-bit NetBSD system can trigger a kernel panic or memory corruption by calling recvmsg() with msg_iovlen between 9 and IOV_MAX, causing the kernel to access a freed iovec buffer and subsequently free the same allocation a second time.
Gravedad CVSS v4.0: ALTA
Última modificación:
24/09/2026

CVE-2026-89259

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Hugo is a static site generator. From v0.161.0, Hugo executes Node tools under Node's permission model, but TailwindCSS — included in the default security.exec.allow list — requires a highly permissive configuration (--allow-addons, --allow-child-process, --allow-worker). As a result, the restrictions intended by the fix for GHSA-x597-9fr4-5857 could still be bypassed, allowing a Node tool invoked during a build to read and write files outside the project's working directory. Affected versions are those after v0.43; the issue was fixed in v0.165.0 by removing tailwindcss from the default security.exec.allow list. Users who do not use TailwindCSS, or who only build trusted sites, are not affected. As a workaround, users can define a restrictive security.exec.allow list in hugo.toml.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
24/09/2026

CVE-2026-89147

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Net-SNMP through 5.9.5.2 contains a denial of service vulnerability in the SMUX module where smux_accept() performs an unauthenticated blocking read without timeout on newly accepted connections. An unauthenticated remote client can connect to the SMUX listener and send no data, causing the single-threaded snmpd main loop to block indefinitely and suspend all SNMP processing.
Gravedad CVSS v4.0: ALTA
Última modificación:
24/09/2026

CVE-2026-89146

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** libp2p-rendezvous through 0.17.1 fails to validate registration TTL values in discovery responses, allowing attackers to trigger timer arithmetic overflow. A malicious rendezvous server can send a discovery response with an unbounded TTL value that causes the client node process to panic when computing the expiry timer.
Gravedad CVSS v4.0: ALTA
Última modificación:
23/09/2026

CVE-2026-89060

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed cluster’s ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources outside the permitted namespace. If those resources reference Secrets, the add-on may copy the referenced Secrets to the attacker-controlled managed cluster.
Gravedad CVSS v3.1: ALTA
Última modificación:
21/09/2026

CVE-2026-89169

Fecha de publicación:
11/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing.
Gravedad CVSS v4.0: MEDIA
Última modificación:
22/09/2026