Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-81688

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** openssl_encrypt versions before 1.4.9 store an unkeyed SHA-256 hash of the plaintext in the cleartext file header metadata. Attackers can read this hash without the password to confirm guessed plaintexts offline or fingerprint identical plaintexts across separately-encrypted files.
Gravedad CVSS v4.0: ALTA
Última modificación:
27/08/2026

CVE-2026-81690

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** openssl-encrypt (pip package) before 1.4.9 contains a symlink-following flaw in its verify-usb v2 added-file allowlist scan. The scan enumerated the drive with rglob(), which in CPython does not descend into symlinked directories and treats the symlink as an ordinary directory, while O_NOFOLLOW on the hash side binds only the final path component. An evil-maid attacker with physical access to the removable drive could replace a tool-tree directory with a symlink to a copy containing byte-identical files plus a planted __pycache__/*.pyc file (which CPython loads in preference to recompiling the clean .py). The planted file is never enumerated, added_files stays 0, and verify-usb reports PASSED, resulting in code execution when the victim runs the portable install. Fixed in 1.4.9 (affects both 1.4.x and 1.5.x lines).
Gravedad CVSS v4.0: ALTA
Última modificación:
27/08/2026

CVE-2026-81691

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** openssl_encrypt versions before 1.4.9 fail to validate server URLs in login and register_with_email functions, accepting unencrypted http:// URLs and unconfigured hosts. Attackers on the network path can intercept cleartext credentials including client_id, passwords, and JWTs to achieve full keyserver account takeover.
Gravedad CVSS v4.0: ALTA
Última modificación:
27/08/2026

CVE-2026-81687

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** openssl_encrypt versions before 1.4.9 fail to enforce a time ceiling on key derivation function iteration counts specified in file metadata. Attackers can craft files with extremely high KDF iteration counts to consume CPU resources for unbounded periods before password verification occurs.
Gravedad CVSS v4.0: ALTA
Última modificación:
27/08/2026

CVE-2026-81689

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** openssl_encrypt versions before 1.4.9 derive the remote-pepper wrap key using unsalted HKDF-SHA256 or bare SHA-256 of the password, allowing identical keys across all users and files. Attackers with access to wrapped pepper blobs can precompute a single dictionary table and perform fleet-wide offline password guessing at hardware speed to recover user passwords.
Gravedad CVSS v4.0: ALTA
Última modificación:
27/08/2026

CVE-2026-81678

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** AVideo before 24.0 contains a server-side request forgery vulnerability in the isSSRFSafeURL function that fails to extract embedded IPv4 addresses from NAT64, 6to4, and Teredo IPv6 transition address formats. Unauthenticated attackers can bypass SSRF protections via the LiveLinks proxy endpoint to reach internal services and cloud metadata endpoints by encoding private IPv4 targets in transition address formats.
Gravedad CVSS v4.0: MEDIA
Última modificación:
27/08/2026

CVE-2026-81680

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, allowing attackers to remove recovery slots without re-encrypting the payload. Attackers can modify the file header to delete recovery-slot fields and bypass authentication, silently removing recovery paths the owner deliberately added.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
27/08/2026

CVE-2026-81681

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** openssl_encrypt (pip package openssl-encrypt) versions
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
27/08/2026

CVE-2026-81683

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** openssl_encrypt (pip package openssl-encrypt) versions 1.4.8 and earlier store an mTLS client private key in cleartext within a world-readable (0644) SharedPreferences file via the desktop GUI's Settings screen 'combined certificate and private key' PEM field. A local attacker with file system access can read the exposed private key. Version 1.4.9 writes the PEM to a dedicated 0600 file, keeps only its path in SharedPreferences, and migrates/scrubs existing cleartext values.
Gravedad CVSS v4.0: ALTA
Última modificación:
27/08/2026

CVE-2026-81679

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** OpenRemote versions before 1.28.0 contain a cross-realm information disclosure vulnerability in the Notification REST API that allows per-realm tenant administrators to read all tenants' sent notifications including message bodies. Attackers with read:admin credentials in one realm can submit a zero-parameter GET request to the notification endpoint to retrieve sensitive notification metadata and message content from all realms.
Gravedad CVSS v4.0: ALTA
Última modificación:
27/08/2026

CVE-2026-81682

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** openssl_encrypt versions before 1.4.9 contain an insecure file permissions vulnerability in the desktop GUI that writes decrypted plaintext with world-readable default permissions. Attackers can read decrypted output files created by the GUI as unprivileged local users on multi-user systems.
Gravedad CVSS v4.0: ALTA
Última modificación:
27/08/2026

CVE-2026-81684

Fecha de publicación:
27/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** In openssl_encrypt (pip package openssl-encrypt) versions
Gravedad CVSS v4.0: MEDIA
Última modificación:
27/08/2026