JF / 2026
Available
02
Security Research

Vulnerability disclosures

04 entries
2025 — 2026

Independent discovery of vulnerabilities in production software, each managed through coordinated disclosure with the vendor and INCIBE.

CVE-2026-14856 CWE-79 Medium · 6.5

Stored Cross-Site Scripting in Media Manager of TastyIgniter

Vulnerability in the Media Manager of TastyIgniter allowing Stored XSS. Coordinated and published via official INCIBE advisory, with a dedicated public PoC repository.

INC-2026-0152 CWE-250 · CWE-269 Critical · 9.3

Local Privilege Escalation in Corporate Backup Software

Independently identified a critical LPE vulnerability in a widely deployed corporate backup solution. The flaw allows a low-privileged user to escalate to SYSTEM on affected hosts. Patch under development with vendor.

INC-2026-0168 CWE-434 · CWE-94 High · 8.6

Remote Code Execution via File Upload in School Management Software

Remote Code Execution vulnerability in the add-on upload functionality of a school management platform. Vendor and product name withheld while disclosure is coordinated directly.

INC-2026-0175 CWE-538 High · 8.7

Unauthenticated Disclosure of Sensitive Configuration (.env)

An information disclosure vulnerability in a gym management platform: a misconfigured access-control file, written in syntax unsupported by the deployed web server, allowed unauthenticated remote access to a sensitive environment configuration file — exposing database and SMTP credentials.