Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-66408

Fecha de publicación:
10/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords.<br /> Physical access to an affected product may allow to obtain the password of the root account.
Gravedad CVSS v4.0: MEDIA
Última modificación:
10/08/2026

CVE-2026-66409

Fecha de publicación:
10/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks.<br /> The password may be analyzed and obtained to connect to the access point of an affected robot.
Gravedad CVSS v4.0: MEDIA
Última modificación:
10/08/2026

CVE-2026-66410

Fecha de publicación:
10/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Android and iOS apps ECOVACS PRO App improperly validate server certificates.<br /> Communication may be retrieved and/or altered.
Gravedad CVSS v4.0: BAJA
Última modificación:
10/08/2026

CVE-2026-66411

Fecha de publicación:
10/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algorithm in Websocket communications.<br /> An unauthenticated attacker may connect and operate the affected robot.
Gravedad CVSS v4.0: MEDIA
Última modificación:
10/08/2026

CVE-2026-66403

Fecha de publicación:
10/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log information stored on the affected products may be retrieved.
Gravedad CVSS v4.0: ALTA
Última modificación:
10/08/2026

CVE-2026-66404

Fecha de publicación:
10/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** DEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificates in MQTT communications. Operation logs and activity logs stored on the affected products may be retrieved.
Gravedad CVSS v4.0: MEDIA
Última modificación:
10/08/2026

CVE-2026-66405

Fecha de publicación:
10/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be leveraged to log in to the affected products.
Gravedad CVSS v4.0: ALTA
Última modificación:
10/08/2026

CVE-2026-66406

Fecha de publicación:
10/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** DEEBOT PRO M1 and DEEBOT PRO K1VAC use wget command with server certificate validation disabled.<br /> A man-in-the-middle attack may allow to obtain and/or alter communications of the affected products. As a result, arbitrary code may be executed with the administrative privilege.
Gravedad CVSS v4.0: BAJA
Última modificación:
10/08/2026

CVE-2026-66407

Fecha de publicación:
10/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication.<br /> The WebSocket private key may be retrieved through analyzing the traffic data via a man-in-the-middle attack, and communication contents may be altered.
Gravedad CVSS v4.0: ALTA
Última modificación:
10/08/2026

CVE-2026-21084

Fecha de publicación:
10/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper access control in SmartThings prior to version 1.8.47.24 allows local attackers to access sensitive information.
Gravedad CVSS v4.0: MEDIA
Última modificación:
18/08/2026

CVE-2026-21083

Fecha de publicación:
10/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.
Gravedad CVSS v4.0: MEDIA
Última modificación:
19/08/2026

CVE-2026-21075

Fecha de publicación:
10/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper authorization in handler for custom URL scheme in My Galaxy prior to version 6.3 allows remote attackers to access sensitive information.
Gravedad CVSS v4.0: MEDIA
Última modificación:
18/08/2026