Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-92555

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** Insertion of sensitive information into sent data vulnerability in AKIN Software Computer Import-Export Industry and Trade Co. Ltd. AKINSOFT WOLVOX Control Panel allows Pull Data from System Resources.<br /> <br /> This issue affects AKINSOFT WOLVOX Control Panel: from 26.02.25 before 26.02.26.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
08/10/2026

CVE-2026-19083

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** Authorization bypass through User-Controlled key vulnerability in AKIN Software Computer Import-Export Industry and Trade Co. Ltd. OctoCloud allows Accessing Functionality Not Properly Constrained by ACLs.<br /> <br /> This issue affects OctoCloud: from 1.12.06 before 1.12.07.
Gravedad CVSS v3.1: ALTA
Última modificación:
08/10/2026

CVE-2026-107580

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** Inefficient algorithmic complexity in the decoding of message header fields in Progressive Robot hMailServer 6.0.0 through 6.3.5 allows a remote unauthenticated attacker to make the IMAP, SMTP and POP3 services, or the webmail, unavailable by sending a message. The server unfolded a decoded header value by finding each line break from the end of the value and removing it, moving the rest of the value each time, so its work grew with the square of the number of line breaks, and an RFC 2047 encoded word may decode to any number of them. A received message whose Subject or other header field holds such a value keeps a worker thread busy for minutes or longer each time the value is read: when the recipient&amp;#39;s IMAP client searches, sorts or threads the folder by a header, when the webmail lists the folder, and, where configured, when a rule tests a header, a spam tag is added to the Subject or an abuse report is read during delivery. The IMAP worker threads are shared with SMTP and POP3, so a few such messages stop those services responding. The server&amp;#39;s reading of a message header from its file also searched everything read so far after each 4,000 bytes, costing seconds for a header of tens of megabytes.
Gravedad CVSS v3.1: MEDIA
Última modificación:
08/10/2026

CVE-2026-107581

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** Progressive Robot hMailServer 6.0.0 through 6.3.5 processes several IMAP commands from a signed-in account in time quadratic in the command&amp;#39;s length or in the number of elements it names, and can be made to hold memory out of proportion to a command. The FETCH data-item parser normalised a BODY[] section with a case-insensitive string replacement that copied the whole item per occurrence and split the item list by repeatedly copying the remainder of the command; the server&amp;#39;s case-insensitive search compared a needle afresh at every position, so a long SEARCH TEXT key over a message cost the product of the two lengths; SEARCH message sets and the saved-result marker ($), SORT criteria, HEADER.FIELDS name lists and UID ranges were each read once per message rather than once per command; and a FETCH naming a message&amp;#39;s sections very many times read and held every section in memory before sending any. An IMAP command may continue past one line through non-synchronizing literals, so one command can reach about eleven megabytes. The IMAP worker threads are a small pool shared with SMTP and POP3, so a signed-in user sending such commands can make the IMAP, SMTP and POP3 services stop responding (CWE-407) and can consume excessive memory (CWE-400).
Gravedad CVSS v3.1: MEDIA
Última modificación:
08/10/2026

CVE-2026-107582

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** Inefficient algorithmic complexity in the REST API (6.3.3 through 6.3.5) and the IMAP PREVIEW response (6.2.22 through 6.3.5) of Progressive Robot hMailServer allows a remote unauthenticated attacker to make the webmail, the administration console and the REST API unavailable by sending a message. To show a snippet of each message in a folder&amp;#39;s message list, the server decoded the character entity references of a message that has an HTML part and no text part with a string replacement whose work grew with the square of their number. A received HTML-only message holding a very large number of entity references therefore keeps one of the listener&amp;#39;s four worker threads busy for minutes or longer each time the recipient&amp;#39;s webmail lists the folder, without the message being opened, so that a few such listings leave the HTTP listener unable to answer anybody. The IMAP PREVIEW response read such text the same way, holding an IMAP thread for each client that asks for the preview of such a message. The flaw is in the server&amp;#39;s shared string class, whose replace and remove both ran in quadratic time.
Gravedad CVSS v3.1: MEDIA
Última modificación:
08/10/2026

CVE-2026-107583

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** Inefficient algorithmic complexity in the webmail&amp;#39;s message view of the REST API in Progressive Robot hMailServer 6.3.2 through 6.3.5 allows a remote unauthenticated attacker to make the webmail, the administration console and the REST API unavailable by sending a message. The route that renders a received message&amp;#39;s HTML replaced each reference to an embedded image in place, with work that grew with the square of the number of references, and wrote the image out for every reference while counting it against its size limit only once. A message whose HTML refers to one small embedded image a very large number of times, opened in the webmail by its recipient, therefore keeps one of the listener&amp;#39;s four worker threads busy for minutes and makes it build a document of gigabytes, so that a few such messages leave the HTTP listener unable to answer anybody.
Gravedad CVSS v3.1: MEDIA
Última modificación:
08/10/2026

CVE-2026-107584

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** Progressive Robot hMailServer 6.0.0 through 6.3.5 fails open when applying DANE (RFC 7672) to outbound SMTP delivery. The server&amp;#39;s validating DNSSEC resolver treated a TLSA or MX lookup that did not complete (no answer, SERVFAIL, a malformed reply), an answer without the requested records and without an NSEC/NSEC3 proof of their absence, and an answer whose records carried no applicable RRSIG as if the recipient domain were unsigned, and from 6.2.19 it also delivered to mail exchangers taken from an unvalidated MX lookup that the DNSSEC-validated MX record set did not name. An attacker who can drop, forge or strip DNS answers on the path to the server&amp;#39;s resolver, at the resolver, or between the resolver and the recipient domain&amp;#39;s name servers, and who holds an active position on the SMTP path, can thereby disable DANE for a DNSSEC-signed recipient domain and cause messages to be delivered in cleartext or to a host of the attacker&amp;#39;s choosing with an arbitrary certificate, where they can be read and modified.
Gravedad CVSS v3.1: ALTA
Última modificación:
08/10/2026

CVE-2026-107587

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper certificate validation in the webmail of Progressive Robot hMailServer 6.3.2 through 6.3.5 allows a remote unauthenticated attacker to have S/MIME-encrypted mail that the account later sends to another correspondent also encrypted to the attacker&amp;#39;s key. When its recipient opened a signed message, the webmail kept the signer&amp;#39;s certificate for encrypting replies whether or not the server found its chain trusted, under the first e-mail address the certificate listed rather than the message&amp;#39;s From address, and beside any certificate already held for that address. Encrypted mail later sent from the webmail to that address was encrypted to every certificate held for it, so a holder of the kept certificate&amp;#39;s key who obtains a copy of such a message can read it.
Gravedad CVSS v3.1: MEDIA
Última modificación:
08/10/2026

CVE-2026-107573

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** Incorrect default permissions in the Windows installer of Progressive Robot hMailServer 6.0.0 through 6.3.5 allow a local authenticated user to read the mail server&amp;#39;s data. The installer created the data, log, temp, database and event folders and the hMailServer.INI configuration file with the permissions inherited from the installation folder, by default under Program Files, which give the local Users group read access. Any user who can sign in to the computer could read every stored message, the logs, the built-in database with the accounts&amp;#39; password hashes whenever the service is stopped, and the configuration file, including the database password, which is sealed only with the machine&amp;#39;s DPAPI key and can be unsealed by any local account; with an external database that password gives full control of it. The Linux AppImage of 6.3.0 through 6.3.5 likewise created its per-user data folders readable by other local users.
Gravedad CVSS v3.1: ALTA
Última modificación:
08/10/2026

CVE-2026-107574

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** Inefficient algorithmic complexity in the JSON reader of Progressive Robot hMailServer allows a remote unauthenticated attacker to make the mail services unavailable. Reading a JSON object kept the first of each duplicated member name by searching the members already read, so an object of N distinct member names cost O(N^2): 1 MB took 8.9 seconds and 4 MB took 300 seconds against the affected code. A remote attacker reaches the reader without an account by mailing a crafted TLS-RPT report (up to 16 MB after decompression) to a hosted domain&amp;#39;s published report mailbox, which is read on a delivery thread; a few such reports hold every delivery thread (ten by default), so the server delivers no mail, local or outbound, for over an hour per report. A signed-in account reaches the same 16 MB body through the webmail&amp;#39;s own REST routes, holding the REST API&amp;#39;s own worker threads. Where no report mailbox is configured, the unauthenticated REST sign-in routes that read a JSON body are capped at 64 KB and are not affected.
Gravedad CVSS v3.1: ALTA
Última modificación:
08/10/2026

CVE-2026-107575

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** Inefficient algorithmic complexity in the SPF macro expansion of Progressive Robot hMailServer 6.3.4 and 6.3.5 allows a remote unauthenticated attacker to consume worker-thread time by publishing a crafted SPF record. RFC 7208 section 7.1 requires a name too long to look up to lose whole labels from the left; the server did this by removing one label at a time and copying the rest of the name each time, so the work grew with the square of the expansion. An attacker who publishes an SPF record for a domain they control, with a mechanism whose domain-spec expands through macros to a name far longer than 253 characters, makes the SPF check of a message from that domain take several seconds. The expansion is bounded by SPF&amp;#39;s own per-term and per-macro limits, so the loss of availability is partial.
Gravedad CVSS v3.1: MEDIA
Última modificación:
08/10/2026

CVE-2026-107576

Fecha de publicación:
08/10/2026
Idioma:
Inglés
*** Pendiente de traducción *** Inefficient algorithmic complexity in the inbound DKIM and ARC signature verification of Progressive Robot hMailServer 6.0.0 through 6.3.5 allows a remote unauthenticated attacker to make the mail services unavailable by sending a message. Building the canonical header and choosing the header fields named in a signature&amp;#39;s h= tag took time growing with the square of the message&amp;#39;s header: the &amp;#39;simple&amp;#39; canonicalisation prepended each continuation line of a folded field to the lines already gathered, and both canonicalisations searched the gathered fields from the bottom for each h= name and erased the match from the middle of the list. A message whose header holds very many fields, or a field folded over very many lines, with a DKIM-Signature the attacker signs for a domain they control, keeps a worker thread busy for tens of seconds per signature; up to ten signatures are evaluated per message by each of the DKIM and DMARC tests, on the threads that serve delivery and SMTP.
Gravedad CVSS v3.1: ALTA
Última modificación:
08/10/2026