Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-28928

Publication date:
27/07/2026
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
Severity CVSS v4.0: Pending analysis
Last modification:
28/07/2026

CVE-2026-28931

Publication date:
27/07/2026
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. Connecting to a malicious NFS server may lead to kernel memory corruption.
Severity CVSS v4.0: Pending analysis
Last modification:
28/07/2026

CVE-2026-20672

Publication date:
27/07/2026
An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to access sensitive user data.
Severity CVSS v4.0: Pending analysis
Last modification:
28/07/2026

CVE-2026-28849

Publication date:
27/07/2026
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A maliciously crafted ZIP archive may bypass Gatekeeper checks.
Severity CVSS v4.0: Pending analysis
Last modification:
28/07/2026

CVE-2026-28896

Publication date:
27/07/2026
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An attacker may be able to cause unexpected system termination or read kernel memory.
Severity CVSS v4.0: Pending analysis
Last modification:
28/07/2026

CVE-2026-12001

Publication date:
27/07/2026
A hardcoded credential<br /> vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, Archer C20 v6 &amp; Archer MR200 v5).  Authentication-related credential material is<br /> embedded within a password file in the firmware image and may be recovered<br /> through firmware analysis.<br /> <br /> <br /> <br /> <br /> <br /> Successful<br /> exploitation could result in unauthorized access to privileged functions on<br /> affected devices.
Severity CVSS v4.0: MEDIUM
Last modification:
28/07/2026

CVE-2026-66018

Publication date:
27/07/2026
Build readers can access another repository&amp;#39;s environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving environment properties for a protected build, exposing build environment secrets (confidentiality impact; no integrity or availability impact demonstrated).
Severity CVSS v4.0: Pending analysis
Last modification:
27/07/2026

CVE-2026-65618

Publication date:
27/07/2026
Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized requests from JFrog Artifactory, potentially exposing internal services and cached response data.
Severity CVSS v4.0: Pending analysis
Last modification:
27/07/2026

CVE-2026-65921

Publication date:
27/07/2026
A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written outside the intended build artifacts location.
Severity CVSS v4.0: Pending analysis
Last modification:
27/07/2026

CVE-2026-65922

Publication date:
27/07/2026
An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository access to write to restricted internal metadata areas under specific conditions. Successful abuse is limited to integrity and availability impact at a low level; confidentiality is not affected.
Severity CVSS v4.0: Pending analysis
Last modification:
27/07/2026

CVE-2026-65923

Publication date:
27/07/2026
A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended server-side requests.<br /> The issue primarily affects confidentiality and integrity and has been addressed in fixed Artifactory versions.
Severity CVSS v4.0: Pending analysis
Last modification:
27/07/2026

CVE-2026-65924

Publication date:
27/07/2026
JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user - or, if anonymous access is enabled on the repository, an unauthenticated user - could cause Artifactory to issue outbound HTTP requests to arbitrary destinations and receive the response content.
Severity CVSS v4.0: Pending analysis
Last modification:
27/07/2026