Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-27033

Publication date:
18/02/2026
Rejected reason: Not used
Severity CVSS v4.0: Pending analysis
Last modification:
18/02/2026

CVE-2026-27034

Publication date:
18/02/2026
Rejected reason: Not used
Severity CVSS v4.0: Pending analysis
Last modification:
18/02/2026

CVE-2026-27035

Publication date:
18/02/2026
Rejected reason: Not used
Severity CVSS v4.0: Pending analysis
Last modification:
18/02/2026

CVE-2026-1344

Publication date:
18/02/2026
Tanium addressed an insecure file permissions vulnerability in Enforce Recovery Key Portal.
Severity CVSS v4.0: Pending analysis
Last modification:
18/02/2026

CVE-2026-22048

Publication date:
18/02/2026
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.12 and 12.0.0.4 with Single Sign-on enabled and configured to use Microsoft Entra ID (formerly Azure AD) as an IdP are susceptible to a Server-Side Request Forgery (SSRF) vulnerability. Successful exploit could allow an authenticated attacker with low privileges to delete configuration data or deny access to some resources.
Severity CVSS v4.0: Pending analysis
Last modification:
18/02/2026

CVE-2026-23599

Publication date:
18/02/2026
A local privilege-escalation vulnerability has been discovered in the HPE Aruba Networking ClearPass OnGuard Software for Linux. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges.
Severity CVSS v4.0: Pending analysis
Last modification:
18/02/2026

CVE-2026-2570

Publication date:
17/02/2026
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.
Severity CVSS v4.0: Pending analysis
Last modification:
17/02/2026

CVE-2026-26119

Publication date:
17/02/2026
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
Severity CVSS v4.0: Pending analysis
Last modification:
19/02/2026

CVE-2026-1670

Publication date:
17/02/2026
The affected products are vulnerable to an unauthenticated API endpoint exposure, which may allow an attacker to remotely change the "forgot password" recovery email address.
Severity CVSS v4.0: CRITICAL
Last modification:
18/02/2026

CVE-2025-62183

Publication date:
17/02/2026
Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. Requires an administrative user and given extensive access rights, impact to Confidentiality and Integrity are low.
Severity CVSS v4.0: MEDIUM
Last modification:
18/02/2026

CVE-2025-13689

Publication date:
17/02/2026
IBM DataStage on Cloud Pak for Data could allow an authenticated user to execute arbitrary commands and gain access to sensitive information due to unrestricted file uploads.
Severity CVSS v4.0: Pending analysis
Last modification:
20/02/2026

CVE-2025-13333

Publication date:
17/02/2026
IBM WebSphere Application Server 9.0, and 8.5 could provide weaker than expected security during system administration of security settings.
Severity CVSS v4.0: Pending analysis
Last modification:
20/02/2026