Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-7511

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** PKCS7_verify signer confusion allows forged signatures, where the signer associated with a signature is not correctly bound, permitting a forged signature to be accepted.
Gravedad CVSS v4.0: MEDIA
Última modificación:
27/06/2026

CVE-2026-6331

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** HMAC zero-length tag forgery in EVP_DigestVerifyFinal, where a zero-length tag could be accepted as valid during HMAC verification. In the OpenSSL-compatibility HMAC verify path the supplied signature length was only checked as not exceeding the MAC length, so a zero-length or otherwise truncated tag could pass verification. The fix requires the supplied tag length to exactly equal the MAC length and rejects a zero-length MAC, so a forged short or empty tag is no longer accepted.
Gravedad CVSS v4.0: BAJA
Última modificación:
27/06/2026

CVE-2026-7532

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** iPAddress name constraints bypass when WOLFSSL_IP_ALT_NAME is not defined. IP address name constraints are not enforced in that configuration, allowing a certificate to bypass an issuing CA's IP address constraints.
Gravedad CVSS v4.0: MEDIA
Última modificación:
01/07/2026

CVE-2026-6330

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** The ML-KEM ARM64 NEON ciphertext comparison only compares half of the input, breaking the Fujisaki-Okamoto transform's implicit rejection and weakening IND-CCA2 security on that code path. The constant-time comparison effectively ignored part of the re-encrypted ciphertext, so a decapsulating party could fail to detect a manipulated ciphertext and proceed without the standard's required implicit rejection.
Gravedad CVSS v4.0: MEDIA
Última modificación:
27/06/2026

CVE-2026-6329

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** PKCS#12 MAC verification uses an attacker-controlled comparison length, weakening the integrity check on the MAC and allowing a mismatched MAC to be accepted. The PKCS#12 verify path compared the locally computed HMAC against the MAC parsed from the PKCS#12 structure using a length taken directly from the attacker-supplied input, without first verifying that it equals the length of the digest actually produced by the configured algorithm. A truncated or zero-length stored MAC could therefore be accepted, defeating the integrity protection of the MAC.
Gravedad CVSS v4.0: MEDIA
Última modificación:
27/06/2026

CVE-2026-6325

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Out-of-bounds write in SetSuitesHashSigAlgo when processing an oversized signature algorithms list, allowing a write past the bounds of the destination buffer.
Gravedad CVSS v4.0: BAJA
Última modificación:
27/06/2026

CVE-2026-6092

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** When HAVE_ENCRYPT_THEN_MAC is configured, the implementation could fall back to MAC-then-Encrypt rather than enforcing Encrypt-then-MAC.
Gravedad CVSS v4.0: BAJA
Última modificación:
27/06/2026

CVE-2026-55962

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** TLS 1.3 post-handshake authentication (PHA) issue where a server could accept a client's Finished message without the client having sent a Certificate and CertificateVerify. The post-handshake-auth exemption that allows an empty/absent peer certificate was only intended for the initial handshake, but it was also being applied while a post-handshake CertificateRequest was still outstanding. The check is now scoped to the initial handshake only: on the server, once a post-handshake CertificateRequest has been sent (certReqCtx is set), a peer certificate and a valid CertificateVerify are required again before the Finished is accepted, with empty-certificate handling following the configured verify mode (FAIL_IF_NO_PEER_CERT) just as during first-handshake client authentication. Only affects TLS 1.3 servers built with post-handshake authentication support (WOLFSSL_POST_HANDSHAKE_AUTH / --enable-postauth, included in --enable-all) that enable WOLFSSL_VERIFY_POST_HANDSHAKE and request a client certificate after the handshake via wolfSSL_request_certificate(). Clients, and servers that do not use post-handshake authentication, are unaffected.
Gravedad CVSS v4.0: MEDIA
Última modificación:
27/06/2026

CVE-2026-54479

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend with valid session requests.
Gravedad CVSS v4.0: MEDIA
Última modificación:
26/06/2026

CVE-2026-13283

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Use after free in AdFilter in Google Chrome on Android prior to 149.0.7827.201 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Gravedad CVSS v3.1: ALTA
Última modificación:
27/06/2026

CVE-2026-40702

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
26/06/2026

CVE-2026-44622

Fecha de publicación:
25/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Gravedad CVSS v4.0: MEDIA
Última modificación:
26/06/2026