Vulnerabilidades publicadas recientemente en el software que administramos a diario. La lista está filtrada: solo aparece lo que afecta a servidores en producción, no el catálogo completo de CVE.
| CVE | Severidad | Software | Resumen | Corregido en | Publicado |
|---|---|---|---|---|---|
| CVE-2026-17543 | Crítica 9.8 | PHP | Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.*… | Debian:13: 8.4.24-1~deb13u1 |
2026-07-30 |
| CVE-2026-17544 | Crítica 9.8 | PHP | Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from… | Debian:13: 8.4.24-1~deb13u1 |
2026-07-30 |
| CVE-2026-54876 | Alta 7.5 | OpenSSL | [Client-Side Memory Leak in OCSP Response Checking] | Sin parche aún | 2026-08-05 |
| CVE-2024-14040 | Alta 7.8 | Kernel Linux | In the Linux kernel, the following vulnerability has been resolved: net: nexthop: Increase weight to u16 In CLOS networks, as link failures occur at various… | Sin parche aún | 2026-07-26 |
| CVE-2026-11331 | Alta 7.5 | BIND | An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error… | Debian:11: 1:9.16.50-1~deb11u6Debian:12: 1:9.18.49-1~deb12u2Debian:13: 1:9.20.26-1~deb13u1Debian:14: 1:9.20.26-1 |
2026-07-22 |
| CVE-2026-11605 | Alta 7.5 | BIND | The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG records in an answer, even if they are not… | Debian:11: 1:9.16.50-1~deb11u6Debian:12: 1:9.18.49-1~deb12u2Debian:13: 1:9.20.26-1~deb13u1Debian:14: 1:9.20.26-1 |
2026-07-22 |
| CVE-2026-11622 | Alta 7.5 | BIND | A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to… | Debian:11: 1:9.16.50-1~deb11u6Debian:12: 1:9.18.49-1~deb12u2Debian:13: 1:9.20.26-1~deb13u1Debian:14: 1:9.20.26-1 |
2026-07-22 |
| CVE-2026-11721 | Alta 7.5 | BIND | It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained… | Debian:11: 1:9.16.50-1~deb11u6Debian:12: 1:9.18.49-1~deb12u2Debian:13: 1:9.20.26-1~deb13u1Debian:14: 1:9.20.26-1 |
2026-07-22 |
| CVE-2026-12617 | Alta 7.5 | BIND | The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME or DNAME, and A records. Specifically… | Debian:11: 1:9.16.50-1~deb11u6Debian:12: 1:9.18.49-1~deb12u2Debian:13: 1:9.20.26-1~deb13u1Debian:14: 1:9.20.26-1 |
2026-07-22 |
| CVE-2026-13204 | Alta 7.5 | BIND | If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may… | Debian:11: 1:9.16.50-1~deb11u6Debian:12: 1:9.18.49-1~deb12u2Debian:13: 1:9.20.26-1~deb13u1Debian:14: 1:9.20.26-1 |
2026-07-22 |
| CVE-2026-13321 | Alta 8.6 | BIND | The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. This issue affects BIND 9 versions… | Debian:11: 1:9.16.50-1~deb11u6Debian:12: 1:9.18.49-1~deb12u2Debian:13: 1:9.20.26-1~deb13u1Debian:14: 1:9.20.26-1 |
2026-07-22 |
| CVE-2026-60163 | Alta 8.4 | MariaDB | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected… | Sin parche aún | 2026-07-21 |
| CVE-2026-60315 | Alta 8.2 | MariaDB | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: X Plugin). Supported versions that are affected are MySQL Server… | Sin parche aún | 2026-07-21 |
| CVE-2026-60316 | Alta 7.2 | MariaDB | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: X Plugin). Supported versions that are affected are MySQL Server… | Sin parche aún | 2026-07-21 |
| CVE-2026-61094 | Alta 7.2 | MariaDB | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL… | Sin parche aún | 2026-07-21 |
| CVE-2026-42533 | Alta 8.1 | Nginx | A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture… | Sin parche aún | 2026-07-15 |
| CVE-2026-60005 | Alta 8.2 | Nginx | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured… | Debian:14: 1.30.1-7Ubuntu:22.04: 1.18.0-6ubuntu14.17Ubuntu:24.04: 1.24.0-2ubuntu7.14Ubuntu:26.04: 1.28.3-2ubuntu1.7 |
2026-07-15 |
| CVE-2026-7260 | Media 5.5 | PHP | Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.*… | Debian:13: 8.4.24-1~deb13u1 |
2026-07-30 |
| CVE-2026-10723 | Media 6.8 | BIND | BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9… | Debian:11: 1:9.16.50-1~deb11u6Debian:12: 1:9.18.49-1~deb12u2Debian:13: 1:9.20.26-1~deb13u1Debian:14: 1:9.20.26-1 |
2026-07-22 |
| CVE-2026-10822 | Media 6.5 | BIND | If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit. BIND will first… | Debian:12: 1:9.18.49-1~deb12u2Debian:13: 1:9.20.26-1~deb13u1Debian:14: 1:9.20.26-1 |
2026-07-22 |
| CVE-2026-46936 | Media 4.4 | MariaDB | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are MySQL Server… | Sin parche aún | 2026-07-21 |
| CVE-2026-47012 | Media 4.4 | MariaDB | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are MySQL… | Sin parche aún | 2026-07-21 |
| CVE-2026-47023 | Media 4.9 | MariaDB | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL… | Sin parche aún | 2026-07-21 |
| CVE-2026-47052 | Media 4.9 | MariaDB | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: InnoDB). Supported versions that are affected are MySQL Server… | Sin parche aún | 2026-07-21 |
| CVE-2026-47064 | Media 6.5 | MariaDB | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are MySQL… | Sin parche aún | 2026-07-21 |
| CVE-2026-60145 | Media 4.9 | MariaDB | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are MySQL… | Sin parche aún | 2026-07-21 |
| CVE-2026-60177 | Media 4.4 | MariaDB | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin). Supported versions that are affected are MySQL… | Sin parche aún | 2026-07-21 |
| CVE-2026-60178 | Media 6.6 | MariaDB | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin). Supported versions that are affected are MySQL… | Sin parche aún | 2026-07-21 |
| CVE-2026-60182 | Media 4.4 | MariaDB | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin). Supported versions that are affected are MySQL… | Sin parche aún | 2026-07-21 |
| CVE-2026-60183 | Media 6.4 | MariaDB | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin). Supported versions that are affected are MySQL… | Sin parche aún | 2026-07-21 |
| CVE-2026-60184 | Media 4.4 | MariaDB | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL… | Sin parche aún | 2026-07-21 |
| CVE-2026-60185 | Media 4.4 | MariaDB | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL… | Sin parche aún | 2026-07-21 |
| CVE-2026-60186 | Media 4.4 | MariaDB | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected… | Sin parche aún | 2026-07-21 |
| CVE-2026-60187 | Media 4.4 | MariaDB | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL… | Sin parche aún | 2026-07-21 |
| CVE-2026-60188 | Media 4.4 | MariaDB | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL… | Sin parche aún | 2026-07-21 |
| CVE-2026-60189 | Media 4.4 | MariaDB | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL… | Sin parche aún | 2026-07-21 |
| CVE-2026-60191 | Media 4.1 | MariaDB | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL… | Sin parche aún | 2026-07-21 |
| CVE-2026-60331 | Media 6.4 | MariaDB | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL… | Sin parche aún | 2026-07-21 |
| CVE-2026-60332 | Media 6.4 | MariaDB | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication GCS). Supported versions that are affected are… | Sin parche aún | 2026-07-21 |
| CVE-2026-60585 | Media 6.6 | MariaDB | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL… | Sin parche aún | 2026-07-21 |
| CVE-2026-60747 | Media 6.2 | MariaDB | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL… | Sin parche aún | 2026-07-21 |
| CVE-2026-61109 | Media 6.5 | MariaDB | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: JSON). Supported versions that are affected are MySQL Server… | Sin parche aún | 2026-07-21 |
| CVE-2026-56434 | Media 6.5 | Nginx | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI)… | Debian:14: 1.30.1-7Ubuntu:22.04: 1.18.0-6ubuntu14.17Ubuntu:24.04: 1.24.0-2ubuntu7.14Ubuntu:26.04: 1.28.3-2ubuntu1.7 |
2026-07-15 |
| CVE-2026-60190 | Baja 2.2 | MariaDB | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL… | Sin parche aún | 2026-07-21 |
| CVE-2026-61081 | Baja 2.7 | MariaDB | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Performance Schema). Supported versions that are affected are… | Sin parche aún | 2026-07-21 |
| CVE-2026-61096 | Baja 2.9 | MariaDB | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Pluggable Auth). Supported versions that are affected are MySQL… | Sin parche aún | 2026-07-21 |
| CVE-2026-9672 | Sin clasificar | PHP | Debian:13: 2.3.3-14~deb13u1Debian:14: 2.3.3-14 |
2026-07-31 | |
| USN-8625-1 | Sin clasificar | OpenSSL | openssl vulnerability | Ubuntu:22.04: 3.0.2-0ubuntu1.26Ubuntu:24.04: 3.0.13-0ubuntu3.12Ubuntu:26.04: 3.5.5-1ubuntu3.3 |
2026-07-30 |
| CVE-2026-15791 | Sin clasificar | Docker | A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The action that can normally be used to delete… | Sin parche aún | 2026-07-21 |
| CVE-2026-15792 | Sin clasificar | Docker | A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic. | Sin parche aún | 2026-07-21 |
| CVE-2026-15793 | Sin clasificar | Docker | BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious… | Sin parche aún | 2026-07-21 |
| USN-8563-1 | Sin clasificar | Nginx | nginx vulnerabilities | Ubuntu:22.04: 1.18.0-6ubuntu14.17Ubuntu:24.04: 1.24.0-2ubuntu7.14Ubuntu:26.04: 1.28.3-2ubuntu1.7 |
2026-07-20 |
| USN-8563-2 | Sin clasificar | Nginx | nginx regression | Ubuntu:22.04: 1.18.0-6ubuntu14.18Ubuntu:24.04: 1.24.0-2ubuntu7.15Ubuntu:26.04: 1.28.3-2ubuntu1.8 |
2026-07-20 |
| CVE-2026-12184 | Sin clasificar | PHP | php8.1, php8.3, php8.5 vulnerabilities | Ubuntu:22.04: 8.1.2-1ubuntu2.25Ubuntu:24.04: 8.3.6-0ubuntu0.24.04.10Ubuntu:26.04: 8.5.4-0ubuntu1.2 |
2026-07-20 |
| CVE-2026-59995 | Sin clasificar | OpenSSH | openssh vulnerabilities | Ubuntu:22.04: 1:8.9p1-3ubuntu0.16Ubuntu:24.04: 1:9.6p1-3ubuntu13.18Ubuntu:26.04: 1:10.2p1-2ubuntu3.4 |
2026-07-13 |
Datos de OSV.dev, que agrega los avisos de Debian, Ubuntu, Alpine y Rocky Linux. La severidad es la puntuación base CVSS 3.1 calculada a partir del vector publicado. Esta tabla se genera automáticamente y no sustituye a los avisos oficiales de tu distribución.
El servicio que administramos en la práctica, no todo el catálogo: Kernel Linux, systemd, OpenSSH y OpenSSL como base; Nginx y Apache como servidores web; PostgreSQL y MariaDB como bases de datos; Docker, containerd y Kubernetes en contenedores; y PHP, Postfix y BIND. Se consulta sobre Debian 12, Ubuntu 24.04 y Alpine 3.20.
Todo lo que no llega a un servidor en producción: escritorio, navegadores, aplicaciones de usuario y hardware de consumo. Una lista que lo incluyera todo sería más larga y menos útil, porque obligaría a filtrar a mano lo que aquí ya viene filtrado.
La tabla se regenera automáticamente y ninguna parte de ella la redacta un modelo de lenguaje: son datos copiados de su fuente. Para decidir qué hacer con un aviso concreto, la referencia sigue siendo el aviso oficial de tu distribución, enlazado en cada fila.
Revisar avisos es la parte fácil. Lo que cuesta es decidir qué urge, probarlo y aplicarlo sin cortar el servicio. Si eso hoy no lo lleva nadie, hablamos.
Contactar