Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-62433

Publication date:
28/07/2026
Parts of the DM_OP handling code assumes the caller has provided the<br /> required number of buffers for the given operation without any checking<br /> being done. As a result, certain operations might access stack<br /> rubble as structures are possibly uninitialized.
Severity CVSS v4.0: Pending analysis
Last modification:
28/07/2026

CVE-2026-62434

Publication date:
28/07/2026
A guest started with Populated on Demand enabled (PoD) can attempt to<br /> reclaim pages which aren&amp;#39;t regular guest RAM. This can cause corruption<br /> of memory management state in Xen.
Severity CVSS v4.0: Pending analysis
Last modification:
28/07/2026

CVE-2026-62435

Publication date:
28/07/2026
[This CNA information record relates to multiple CVEs; the<br /> text explains which aspects/vulnerabilities correspond to which CVE.]<br /> <br /> With the introduction of Grant Table v2 came the requirement to be able to<br /> switch between versions. Switching from v1 to v2 reduces the number of<br /> valid grant references, as a bigger shared entry structure is then needed<br /> while the shared table doesn&amp;#39;t change size. Switching from v2 back to v1<br /> the status frames, which are separate in v2, go away.<br /> <br /> Code holding, but intermediately dropping and then re-acquiring the grant<br /> table lock, sometimes wrongly assumes that said properties wouldn&amp;#39;t change<br /> across the window in time where the lock is not being held.<br /> <br /> The v1 -&gt; v2 issue is CVE-2026-62435.<br /> <br /> The v2 -&gt; v1 issue is CVE-2026-62436.
Severity CVSS v4.0: Pending analysis
Last modification:
28/07/2026

CVE-2026-62436

Publication date:
28/07/2026
[This CNA information record relates to multiple CVEs; the<br /> text explains which aspects/vulnerabilities correspond to which CVE.]<br /> <br /> With the introduction of Grant Table v2 came the requirement to be able to<br /> switch between versions. Switching from v1 to v2 reduces the number of<br /> valid grant references, as a bigger shared entry structure is then needed<br /> while the shared table doesn&amp;#39;t change size. Switching from v2 back to v1<br /> the status frames, which are separate in v2, go away.<br /> <br /> Code holding, but intermediately dropping and then re-acquiring the grant<br /> table lock, sometimes wrongly assumes that said properties wouldn&amp;#39;t change<br /> across the window in time where the lock is not being held.<br /> <br /> The v1 -&gt; v2 issue is CVE-2026-62435.<br /> <br /> The v2 -&gt; v1 issue is CVE-2026-62436.
Severity CVSS v4.0: Pending analysis
Last modification:
28/07/2026

CVE-2026-62428

Publication date:
28/07/2026
When grant-copy operations are processed, the respective grant may or may<br /> not already be in use by another operation (a mapping or another copy).<br /> For all copy operations the referenced guest frame is looked up. When<br /> another operation is already active for the grant (the grant is "pinned"),<br /> what is being supplied back to actually carry out permission checks and<br /> copy operation may not be consistent: The permission check may be carried<br /> out on a page different from the one involved in the copy.
Severity CVSS v4.0: Pending analysis
Last modification:
28/07/2026

CVE-2026-62429

Publication date:
28/07/2026
Accessing the vNUMA configuration data of a guest is still possible when<br /> domain destruction has already started. The cleaning up of that<br /> configuration information is not synchronized with its retrieval by a<br /> device model controlling the guest.
Severity CVSS v4.0: Pending analysis
Last modification:
28/07/2026

CVE-2026-62430

Publication date:
28/07/2026
Accesses to the CMOS memory contents are done using an indirect IO port<br /> pair. Therefore Xen needs to cache the guest chosen index, and one of<br /> the usages of the index didn&amp;#39;t take the necessary locking to avoid<br /> concurrent changes. As a result, a guest could change the index after<br /> it being checked, causing a subsequent out-of-bound read access to the<br /> contents of an array.
Severity CVSS v4.0: Pending analysis
Last modification:
28/07/2026

CVE-2026-62423

Publication date:
28/07/2026
[This CNA information record relates to multiple CVEs; the<br /> text explains which aspects/vulnerabilities correspond to which CVE.]<br /> <br /> The directory and Rock Ridge / SUSP walk in libfsimage&amp;#39;s iso9660 driver<br /> derives several lengths directly from attacker-controlled on-disk fields<br /> without validating them:<br /> <br /> * The directory loop itself assumes a good record length. This is<br /> CVE-2026-42494.<br /> <br /> * The calculation of the System Use area may underflow. This is<br /> CVE-2026-42495.<br /> <br /> * The Rock Ridge extension loop assumes a good (inner) record length.<br /> This is CVE-2026-62423.<br /> <br /> * The Rock Ridge NM record processing assumes a good entry length.<br /> This is CVE-2026-62424.<br /> <br /> * The Rock Ridge CE record processing assumes a good size and offset.<br /> This is CVE-2026-62425.
Severity CVSS v4.0: Pending analysis
Last modification:
28/07/2026

CVE-2026-62424

Publication date:
28/07/2026
[This CNA information record relates to multiple CVEs; the<br /> text explains which aspects/vulnerabilities correspond to which CVE.]<br /> <br /> The directory and Rock Ridge / SUSP walk in libfsimage&amp;#39;s iso9660 driver<br /> derives several lengths directly from attacker-controlled on-disk fields<br /> without validating them:<br /> <br /> * The directory loop itself assumes a good record length. This is<br /> CVE-2026-42494.<br /> <br /> * The calculation of the System Use area may underflow. This is<br /> CVE-2026-42495.<br /> <br /> * The Rock Ridge extension loop assumes a good (inner) record length.<br /> This is CVE-2026-62423.<br /> <br /> * The Rock Ridge NM record processing assumes a good entry length.<br /> This is CVE-2026-62424.<br /> <br /> * The Rock Ridge CE record processing assumes a good size and offset.<br /> This is CVE-2026-62425.
Severity CVSS v4.0: Pending analysis
Last modification:
28/07/2026

CVE-2026-62425

Publication date:
28/07/2026
[This CNA information record relates to multiple CVEs; the<br /> text explains which aspects/vulnerabilities correspond to which CVE.]<br /> <br /> The directory and Rock Ridge / SUSP walk in libfsimage&amp;#39;s iso9660 driver<br /> derives several lengths directly from attacker-controlled on-disk fields<br /> without validating them:<br /> <br /> * The directory loop itself assumes a good record length. This is<br /> CVE-2026-42494.<br /> <br /> * The calculation of the System Use area may underflow. This is<br /> CVE-2026-42495.<br /> <br /> * The Rock Ridge extension loop assumes a good (inner) record length.<br /> This is CVE-2026-62423.<br /> <br /> * The Rock Ridge NM record processing assumes a good entry length.<br /> This is CVE-2026-62424.<br /> <br /> * The Rock Ridge CE record processing assumes a good size and offset.<br /> This is CVE-2026-62425.
Severity CVSS v4.0: Pending analysis
Last modification:
28/07/2026

CVE-2026-62426

Publication date:
28/07/2026
[This CNA information record relates to multiple CVEs; the<br /> text explains which aspects/vulnerabilities correspond to which CVE.]<br /> <br /> To manage the system, sysctl and platform operations are used by the<br /> control domain or a possible Xenstore domain. Some of these operations<br /> may not be executed in parallel, so a system-wide lock each is used.<br /> The way those locks are acquired is, however, not providing any fairness.<br /> Furthermore, with XSM/Flask in use, the lock acquire will, for some<br /> operations, occur ahead of any permission checking.<br /> <br /> The sysctl issue is CVE-2026-62426.<br /> <br /> The platform-op issue is CVE-2026-62427.
Severity CVSS v4.0: Pending analysis
Last modification:
28/07/2026

CVE-2026-62427

Publication date:
28/07/2026
[This CNA information record relates to multiple CVEs; the<br /> text explains which aspects/vulnerabilities correspond to which CVE.]<br /> <br /> To manage the system, sysctl and platform operations are used by the<br /> control domain or a possible Xenstore domain. Some of these operations<br /> may not be executed in parallel, so a system-wide lock each is used.<br /> The way those locks are acquired is, however, not providing any fairness.<br /> Furthermore, with XSM/Flask in use, the lock acquire will, for some<br /> operations, occur ahead of any permission checking.<br /> <br /> The sysctl issue is CVE-2026-62426.<br /> <br /> The platform-op issue is CVE-2026-62427.
Severity CVSS v4.0: Pending analysis
Last modification:
28/07/2026