Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-11740

Publication date:
16/07/2026
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Severity CVSS v4.0: Pending analysis
Last modification:
16/07/2026

CVE-2026-14253

Publication date:
16/07/2026
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Severity CVSS v4.0: Pending analysis
Last modification:
16/07/2026

CVE-2026-15997

Publication date:
16/07/2026
Out-of-bounds write vulnerability in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on on ARM allows Overflow Buffers.<br /> <br /> This vulnerability is associated with program files https://github.Com/bcgit/bc-lts-java/blob/main/native_c/arm/sha/shake.C, https://github.Com/bcgit/bc-lts-java/blob/main/native_c/arm/sha/sha3.C.<br /> <br /> <br /> <br /> This issue affects BC-LTS: from 2.73.0 before 2.73.12.1.<br /> <br /> <br /> <br /> Issue is only applicable if application involved is accepting memoable SHA3 / SHAKE states from potentially untrusted sources.
Severity CVSS v4.0: LOW
Last modification:
17/07/2026

CVE-2026-62826

Publication date:
16/07/2026
Improper neutralization of input during web page generation (&amp;#39;cross-site scripting&amp;#39;) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026

CVE-2026-58643

Publication date:
16/07/2026
Improper neutralization of input during web page generation (&amp;#39;cross-site scripting&amp;#39;) in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026

CVE-2026-59117

Publication date:
16/07/2026
Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-58598

Publication date:
16/07/2026
Concurrent execution using shared resource with improper synchronization (&amp;#39;race condition&amp;#39;) in Windows Backup Engine allows an authorized attacker to elevate privileges locally.
Severity CVSS v4.0: Pending analysis
Last modification:
22/07/2026

CVE-2026-57075

Publication date:
16/07/2026
YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64dec.<br /> <br /> The base64 decoder in the bundled libsyck indexes the 256-entry static table b64_xtable with a signed char, so any !!binary byte &gt;= 0x80 sign-extends to a negative index and reads before the table. The decoder receives the raw bytes of any !!binary node, a standard YAML type not gated by $LoadBlessed or $LoadCode, so it is reached on the default Load path.<br /> <br /> Any caller that runs Load or LoadFile on an untrusted document containing a !!binary scalar with a high-bit byte triggers the read, and the value read can surface in the decoded result.
Severity CVSS v4.0: Pending analysis
Last modification:
17/07/2026

CVE-2026-57076

Publication date:
16/07/2026
YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an anchor name reused as an anchors-table key in syck_hdlr_add_anchor.<br /> <br /> In the bundled libsyck an anchor name allocated by syck_strndup is stored both as node-&gt;anchor, freed when the node is freed, and as the key in the parser&amp;#39;s anchors table. Freeing the node frees the shared key, and a later anchor redefinition makes st_delete compare against the freed key, so st_strcmp reads freed heap memory. Anchors are a standard YAML feature and need no special flags, so this is reached on the default Load path.<br /> <br /> Any caller that runs Load or LoadFile on an untrusted document that redefines an anchor reaches the read of freed memory.
Severity CVSS v4.0: Pending analysis
Last modification:
17/07/2026

CVE-2026-57077

Publication date:
16/07/2026
YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len.<br /> <br /> In the bundled libsyck newline_len and is_newline dereference the scan pointer, and the following byte for a "\r\n" pair, with no NUL-terminator or bounds check. During block-scalar lexing at a document boundary the scan runs one byte past the heap lexer buffer. This is an incomplete fix of CVE-2025-11683, on a lexer path the earlier fix did not cover.<br /> <br /> Any caller that runs Load or LoadFile on an untrusted document with a block scalar at a document boundary reaches the over-read.
Severity CVSS v4.0: Pending analysis
Last modification:
17/07/2026

CVE-2026-53411

Publication date:
16/07/2026
A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges.
Severity CVSS v4.0: Pending analysis
Last modification:
17/07/2026

CVE-2026-53412

Publication date:
16/07/2026
Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an account takeover via network access.
Severity CVSS v4.0: Pending analysis
Last modification:
17/07/2026