Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-40955

Publication date:
15/07/2026
CVE-2026-40955 is an integer underflow<br /> vulnerability in the traffic parsing function of Secure Access clients prior to<br /> 14.55. Attackers with intimate knowledge of and total control over the tunnel<br /> protocol can create a non-persistent DoS against their client.
Severity CVSS v4.0: LOW
Last modification:
16/07/2026

CVE-2026-40953

Publication date:
15/07/2026
CVE-2026-40953 is a heap overflow in the<br /> certificate parsing function of Secure Access clients prior to 14.55. Attackers<br /> with local access and administrator permissions can create a denial of service<br /> attack against the client over which they have control.
Severity CVSS v4.0: MEDIUM
Last modification:
16/07/2026

CVE-2026-40954

Publication date:
15/07/2026
CVE-2026-40954<br /> is an integer underflow vulnerability in the traffic parsing function of Secure<br /> Access clients prior to 14.55. Attackers with intimate knowledge of and total<br /> control over the tunnel protocol can create a non-persistent DoS against their<br /> client
Severity CVSS v4.0: LOW
Last modification:
16/07/2026

CVE-2026-40952

Publication date:
15/07/2026
CVE-2026-40952 is a privilege misconfiguration<br /> in the Secure Access installer for the Windows client and server prior to<br /> version 14.55. Attackers with local access to the client or server can use it<br /> to elevate privileges to Administrator when Secure Access is installed in a<br /> non-default location.
Severity CVSS v4.0: HIGH
Last modification:
16/07/2026

CVE-2026-33443

Publication date:
15/07/2026
CVE-2026-33443 is a memory management error in<br /> Secure Access servers prior to 14.55. Attackers with an intimate knowledge of<br /> and total control over the tunnel protocol can create a persistent DoS against<br /> the server.
Severity CVSS v4.0: HIGH
Last modification:
16/07/2026

CVE-2026-62353

Publication date:
15/07/2026
TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.14, source/libs/parser/src/parTokenizer.c tGetToken() incremented past a trailing backslash in a SQL string literal such as &amp;#39;abc\ and read one byte beyond the null terminator, allowing an authenticated user who can submit SQL queries to crash the server and possibly leak adjacent memory. This issue is fixed in version 3.4.1.14.
Severity CVSS v4.0: Pending analysis
Last modification:
15/07/2026

CVE-2026-62355

Publication date:
15/07/2026
TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a Data Reader admin_user on a TDengine Cloud DB instance could run create udf even though standard users should have read-only permissions for non-database objects and show dnodes and create user were denied. This issue is fixed in version 3.4.1.15.
Severity CVSS v4.0: Pending analysis
Last modification:
15/07/2026

CVE-2026-62947

Publication date:
15/07/2026
OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, the cgi-download handler in cgi-io authorizes the requested path against the caller&amp;#39;s ubus session file ACL before canonicalization, and rpcd session.c uses fnmatch() without FNM_PATHNAME, allowing traversal such as an allowed wildcard prefix followed by ../ to read root-readable files including /etc/shadow. This vulnerability is fixed in 25.12.5.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2026

CVE-2026-62349

Publication date:
15/07/2026
TDengine is an open source, time-series database optimized for Internet of Things devices. In 3.4.1.6 and earlier, source/libs/parser/src/parUtil.c trimString() checks space for only one byte before processing SQL string escape sequences \%, \_, or \x, allowing a one-byte out-of-bounds write to the stack buffer tmpTokenBuf that can cause denial of service and potentially remote code execution. This issue is fixed in version 3.4.1.14.
Severity CVSS v4.0: Pending analysis
Last modification:
15/07/2026

CVE-2026-62351

Publication date:
15/07/2026
TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, source/libs/transport/src/transComm.c transDecompressMsg() read STransCompMsg.contLen when pHead-&gt;comp == 1 without first validating that the RPC packet contained the 8-byte STransCompMsg structure, causing an unauthenticated out-of-bounds read, uncontrolled allocation, integer underflow, and server crash. This issue is fixed in version 3.4.1.15.
Severity CVSS v4.0: Pending analysis
Last modification:
15/07/2026

CVE-2026-62348

Publication date:
15/07/2026
TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, TDengine Enterprise allowed an authenticated low-privilege SQL user to run KILL SSMIGRATE against an active shared-storage migration because mndProcessKillSsMigrateReq called mndKillSsMigrate while the intended MND_OPER_SSMIGRATE_DB privilege check was commented out. This issue is fixed in version 3.4.1.15.
Severity CVSS v4.0: Pending analysis
Last modification:
16/07/2026

CVE-2026-62350

Publication date:
15/07/2026
TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a user with create udf privilege could upload a crafted shared library and install it as a user-defined function, such as eval, then execute arbitrary C code on the TDengine server side through database queries. This issue is fixed in version 3.4.1.15.
Severity CVSS v4.0: Pending analysis
Last modification:
18/07/2026