Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-67300

Fecha de publicación:
01/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAIL WINDOW_STATE_ORDER and NOTIFY_ICON_STATE_ORDER when AsyncUpdate is enabled. When a malicious or compromised RDP server sends crafted update orders, the message proxy shallow-copies structures containing nested parser-owned pointers (e.g., titleInfo.string, windowRects, visibilityRects, icon buffers). The parser frees those nested buffers after the callback returns, so the queued async message later dispatches stale pointers, potentially causing memory corruption or a client crash.
Gravedad CVSS v4.0: ALTA
Última modificación:
03/08/2026

CVE-2026-67291

Fecha de publicación:
01/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** FreeRDP before 3.29.0 (affected versions
Gravedad CVSS v4.0: ALTA
Última modificación:
03/08/2026

CVE-2026-67296

Fecha de publicación:
01/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large declared body length to force excessive memory allocation on the server.
Gravedad CVSS v4.0: ALTA
Última modificación:
03/08/2026

CVE-2026-67294

Fecha de publicación:
01/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer certificate during client-side server TLS authentication. In x509_utils_verify(), when server-purpose (X509_PURPOSE_SSL_SERVER) verification fails, the code falls back to client-purpose and any-purpose verification, so a trusted, hostname-matching certificate valid only for clientAuth can be accepted as the RDP server certificate. In environments relying on EKU separation between client and server certificates, this allows a clientAuth-only certificate issued by a trusted CA to bypass server certificate purpose validation.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
03/08/2026

CVE-2026-67297

Fecha de publicación:
01/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies to exhaust client memory resources without triggering the configured size limit.
Gravedad CVSS v4.0: ALTA
Última modificación:
03/08/2026

CVE-2026-67292

Fecha de publicación:
01/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libfreerdp/core/gateway/websocket.c). The client's Pong reply reuses a fixed 1024-byte response stream whose length is not sealed to the actual received Ping payload, so a malicious gateway/WebSocket peer sending a non-empty Ping control frame causes the client to reply with an overlong Pong that discloses bytes beyond the received payload (the peer receives the masking key and can unmask the reply). A zero-length Ping reaches an assertion and terminates the client (denial of service).
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
03/08/2026

CVE-2026-67295

Fecha de publicación:
01/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** FreeRDP before 3.29.0 fails to properly validate server-supplied RDPDR paths in drive redirection, allowing attackers to access prefix-sibling paths outside the configured shared root. A malicious RDP server can read, write, delete, and enumerate files in sibling directories by sending non-rooted paths that bypass the shared-root boundary check.
Gravedad CVSS v4.0: MEDIA
Última modificación:
03/08/2026

CVE-2026-67293

Fecha de publicación:
01/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** FreeRDP before 3.29.0 (affected versions
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
05/08/2026

CVE-2026-66401

Fecha de publicación:
01/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fails to validate descriptor length before accessing the GUID field. A local attacker with a malicious USB video camera can trigger a heap read beyond allocated bounds during camera stream setup, causing denial of service.
Gravedad CVSS v4.0: BAJA
Última modificación:
03/08/2026

CVE-2026-67288

Fecha de publicación:
01/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. When smartcard emulation is enabled, attackers can send crafted smartcard cache requests with NULL lookup-name pointers to trigger strlen() on a null pointer, causing client process termination.
Gravedad CVSS v4.0: ALTA
Última modificación:
03/08/2026

CVE-2026-67290

Fecha de publicación:
01/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. Attackers can send malformed media format data from a server to trigger a crash by reading fixed offsets without validating source buffer length.
Gravedad CVSS v4.0: ALTA
Última modificación:
03/08/2026

CVE-2026-66402

Fecha de publicación:
01/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** FreeRDP before 3.29.0 (affected versions
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
05/08/2026