Datos actualizados a diario

Avisos de seguridad

Vulnerabilidades publicadas recientemente en el software que administramos a diario. La lista está filtrada: solo aparece lo que afecta a servidores en producción, no el catálogo completo de CVE.

2 crítica 15 alta 26 media 3 baja 55 vulnerabilidades · últimos 30 días · actualizado el 2026-08-10
CVE Severidad Software Resumen Corregido en Publicado
CVE-2026-17543 Crítica 9.8 PHP Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.*… Debian:13: 8.4.24-1~deb13u1 2026-07-30
CVE-2026-17544 Crítica 9.8 PHP Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from… Debian:13: 8.4.24-1~deb13u1 2026-07-30
CVE-2026-54876 Alta 7.5 OpenSSL [Client-Side Memory Leak in OCSP Response Checking] Sin parche aún 2026-08-05
CVE-2024-14040 Alta 7.8 Kernel Linux In the Linux kernel, the following vulnerability has been resolved: net: nexthop: Increase weight to u16 In CLOS networks, as link failures occur at various… Sin parche aún 2026-07-26
CVE-2026-11331 Alta 7.5 BIND An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error… Debian:11: 1:9.16.50-1~deb11u6
Debian:12: 1:9.18.49-1~deb12u2
Debian:13: 1:9.20.26-1~deb13u1
Debian:14: 1:9.20.26-1
2026-07-22
CVE-2026-11605 Alta 7.5 BIND The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG records in an answer, even if they are not… Debian:11: 1:9.16.50-1~deb11u6
Debian:12: 1:9.18.49-1~deb12u2
Debian:13: 1:9.20.26-1~deb13u1
Debian:14: 1:9.20.26-1
2026-07-22
CVE-2026-11622 Alta 7.5 BIND A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to… Debian:11: 1:9.16.50-1~deb11u6
Debian:12: 1:9.18.49-1~deb12u2
Debian:13: 1:9.20.26-1~deb13u1
Debian:14: 1:9.20.26-1
2026-07-22
CVE-2026-11721 Alta 7.5 BIND It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained… Debian:11: 1:9.16.50-1~deb11u6
Debian:12: 1:9.18.49-1~deb12u2
Debian:13: 1:9.20.26-1~deb13u1
Debian:14: 1:9.20.26-1
2026-07-22
CVE-2026-12617 Alta 7.5 BIND The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME or DNAME, and A records. Specifically… Debian:11: 1:9.16.50-1~deb11u6
Debian:12: 1:9.18.49-1~deb12u2
Debian:13: 1:9.20.26-1~deb13u1
Debian:14: 1:9.20.26-1
2026-07-22
CVE-2026-13204 Alta 7.5 BIND If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may… Debian:11: 1:9.16.50-1~deb11u6
Debian:12: 1:9.18.49-1~deb12u2
Debian:13: 1:9.20.26-1~deb13u1
Debian:14: 1:9.20.26-1
2026-07-22
CVE-2026-13321 Alta 8.6 BIND The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. This issue affects BIND 9 versions… Debian:11: 1:9.16.50-1~deb11u6
Debian:12: 1:9.18.49-1~deb12u2
Debian:13: 1:9.20.26-1~deb13u1
Debian:14: 1:9.20.26-1
2026-07-22
CVE-2026-60163 Alta 8.4 MariaDB Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected… Sin parche aún 2026-07-21
CVE-2026-60315 Alta 8.2 MariaDB Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: X Plugin). Supported versions that are affected are MySQL Server… Sin parche aún 2026-07-21
CVE-2026-60316 Alta 7.2 MariaDB Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: X Plugin). Supported versions that are affected are MySQL Server… Sin parche aún 2026-07-21
CVE-2026-61094 Alta 7.2 MariaDB Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL… Sin parche aún 2026-07-21
CVE-2026-42533 Alta 8.1 Nginx A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture… Sin parche aún 2026-07-15
CVE-2026-60005 Alta 8.2 Nginx NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured… Debian:14: 1.30.1-7
Ubuntu:22.04: 1.18.0-6ubuntu14.17
Ubuntu:24.04: 1.24.0-2ubuntu7.14
Ubuntu:26.04: 1.28.3-2ubuntu1.7
2026-07-15
CVE-2026-7260 Media 5.5 PHP Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.*… Debian:13: 8.4.24-1~deb13u1 2026-07-30
CVE-2026-10723 Media 6.8 BIND BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9… Debian:11: 1:9.16.50-1~deb11u6
Debian:12: 1:9.18.49-1~deb12u2
Debian:13: 1:9.20.26-1~deb13u1
Debian:14: 1:9.20.26-1
2026-07-22
CVE-2026-10822 Media 6.5 BIND If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit. BIND will first… Debian:12: 1:9.18.49-1~deb12u2
Debian:13: 1:9.20.26-1~deb13u1
Debian:14: 1:9.20.26-1
2026-07-22
CVE-2026-46936 Media 4.4 MariaDB Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are MySQL Server… Sin parche aún 2026-07-21
CVE-2026-47012 Media 4.4 MariaDB Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are MySQL… Sin parche aún 2026-07-21
CVE-2026-47023 Media 4.9 MariaDB Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL… Sin parche aún 2026-07-21
CVE-2026-47052 Media 4.9 MariaDB Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: InnoDB). Supported versions that are affected are MySQL Server… Sin parche aún 2026-07-21
CVE-2026-47064 Media 6.5 MariaDB Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are MySQL… Sin parche aún 2026-07-21
CVE-2026-60145 Media 4.9 MariaDB Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are MySQL… Sin parche aún 2026-07-21
CVE-2026-60177 Media 4.4 MariaDB Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin). Supported versions that are affected are MySQL… Sin parche aún 2026-07-21
CVE-2026-60178 Media 6.6 MariaDB Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin). Supported versions that are affected are MySQL… Sin parche aún 2026-07-21
CVE-2026-60182 Media 4.4 MariaDB Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin). Supported versions that are affected are MySQL… Sin parche aún 2026-07-21
CVE-2026-60183 Media 6.4 MariaDB Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin). Supported versions that are affected are MySQL… Sin parche aún 2026-07-21
CVE-2026-60184 Media 4.4 MariaDB Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL… Sin parche aún 2026-07-21
CVE-2026-60185 Media 4.4 MariaDB Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL… Sin parche aún 2026-07-21
CVE-2026-60186 Media 4.4 MariaDB Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected… Sin parche aún 2026-07-21
CVE-2026-60187 Media 4.4 MariaDB Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL… Sin parche aún 2026-07-21
CVE-2026-60188 Media 4.4 MariaDB Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL… Sin parche aún 2026-07-21
CVE-2026-60189 Media 4.4 MariaDB Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL… Sin parche aún 2026-07-21
CVE-2026-60191 Media 4.1 MariaDB Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL… Sin parche aún 2026-07-21
CVE-2026-60331 Media 6.4 MariaDB Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL… Sin parche aún 2026-07-21
CVE-2026-60332 Media 6.4 MariaDB Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication GCS). Supported versions that are affected are… Sin parche aún 2026-07-21
CVE-2026-60585 Media 6.6 MariaDB Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL… Sin parche aún 2026-07-21
CVE-2026-60747 Media 6.2 MariaDB Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL… Sin parche aún 2026-07-21
CVE-2026-61109 Media 6.5 MariaDB Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: JSON). Supported versions that are affected are MySQL Server… Sin parche aún 2026-07-21
CVE-2026-56434 Media 6.5 Nginx NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI)… Debian:14: 1.30.1-7
Ubuntu:22.04: 1.18.0-6ubuntu14.17
Ubuntu:24.04: 1.24.0-2ubuntu7.14
Ubuntu:26.04: 1.28.3-2ubuntu1.7
2026-07-15
CVE-2026-60190 Baja 2.2 MariaDB Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL… Sin parche aún 2026-07-21
CVE-2026-61081 Baja 2.7 MariaDB Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Performance Schema). Supported versions that are affected are… Sin parche aún 2026-07-21
CVE-2026-61096 Baja 2.9 MariaDB Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Pluggable Auth). Supported versions that are affected are MySQL… Sin parche aún 2026-07-21
CVE-2026-9672 Sin clasificar PHP Debian:13: 2.3.3-14~deb13u1
Debian:14: 2.3.3-14
2026-07-31
USN-8625-1 Sin clasificar OpenSSL openssl vulnerability Ubuntu:22.04: 3.0.2-0ubuntu1.26
Ubuntu:24.04: 3.0.13-0ubuntu3.12
Ubuntu:26.04: 3.5.5-1ubuntu3.3
2026-07-30
CVE-2026-15791 Sin clasificar Docker A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The action that can normally be used to delete… Sin parche aún 2026-07-21
CVE-2026-15792 Sin clasificar Docker A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic. Sin parche aún 2026-07-21
CVE-2026-15793 Sin clasificar Docker BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious… Sin parche aún 2026-07-21
USN-8563-1 Sin clasificar Nginx nginx vulnerabilities Ubuntu:22.04: 1.18.0-6ubuntu14.17
Ubuntu:24.04: 1.24.0-2ubuntu7.14
Ubuntu:26.04: 1.28.3-2ubuntu1.7
2026-07-20
USN-8563-2 Sin clasificar Nginx nginx regression Ubuntu:22.04: 1.18.0-6ubuntu14.18
Ubuntu:24.04: 1.24.0-2ubuntu7.15
Ubuntu:26.04: 1.28.3-2ubuntu1.8
2026-07-20
CVE-2026-12184 Sin clasificar PHP php8.1, php8.3, php8.5 vulnerabilities Ubuntu:22.04: 8.1.2-1ubuntu2.25
Ubuntu:24.04: 8.3.6-0ubuntu0.24.04.10
Ubuntu:26.04: 8.5.4-0ubuntu1.2
2026-07-20
CVE-2026-59995 Sin clasificar OpenSSH openssh vulnerabilities Ubuntu:22.04: 1:8.9p1-3ubuntu0.16
Ubuntu:24.04: 1:9.6p1-3ubuntu13.18
Ubuntu:26.04: 1:10.2p1-2ubuntu3.4
2026-07-13

Datos de OSV.dev, que agrega los avisos de Debian, Ubuntu, Alpine y Rocky Linux. La severidad es la puntuación base CVSS 3.1 calculada a partir del vector publicado. Esta tabla se genera automáticamente y no sustituye a los avisos oficiales de tu distribución.

Buscar por software o distribución

Por software

Por distribución

Cómo se elabora esta lista

Qué software se vigila

El servicio que administramos en la práctica, no todo el catálogo: Kernel Linux, systemd, OpenSSH y OpenSSL como base; Nginx y Apache como servidores web; PostgreSQL y MariaDB como bases de datos; Docker, containerd y Kubernetes en contenedores; y PHP, Postfix y BIND. Se consulta sobre Debian 12, Ubuntu 24.04 y Alpine 3.20.

Qué queda fuera

Todo lo que no llega a un servidor en producción: escritorio, navegadores, aplicaciones de usuario y hardware de consumo. Una lista que lo incluyera todo sería más larga y menos útil, porque obligaría a filtrar a mano lo que aquí ya viene filtrado.

Cómo leer las columnas

  • Severidad es la puntuación base CVSS 3.1 calculada desde el vector publicado, no una estimación nuestra. Cuando el mismo fallo tiene vectores distintos según la distribución, se muestra el más grave.
  • Corregido en lista las versiones que ya incluyen el parche, por distribución. Que aparezca una versión de Debian 13 y no de Debian 12 significa exactamente eso: el parche existe, pero todavía no ha llegado a esa rama.
  • Sin parche aún significa que ninguna distribución ha publicado versión corregida. Son las que conviene mirar primero, porque la respuesta no es actualizar sino mitigar.

La tabla se regenera automáticamente y ninguna parte de ella la redacta un modelo de lenguaje: son datos copiados de su fuente. Para decidir qué hacer con un aviso concreto, la referencia sigue siendo el aviso oficial de tu distribución, enlazado en cada fila.

¿Quién aplica estos parches en tus servidores?

Revisar avisos es la parte fácil. Lo que cuesta es decidir qué urge, probarlo y aplicarlo sin cortar el servicio. Si eso hoy no lo lleva nadie, hablamos.

Contactar