Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-79603

Publication date:
08/09/2026
x86 PV guests can free memory pages while still keeping a stale TLB entry<br /> pointing to them. A TLB flush is only issued by Xen (if needed) when the<br /> page is re-used. Since it&amp;#39;s possible for the page to be scrubbed ahead of<br /> the TLB flush, there&amp;#39;s a window where a PV guest can modify an already<br /> scrubbed page.
Severity CVSS v4.0: Pending analysis
Last modification:
08/09/2026

CVE-2026-79602

Publication date:
08/09/2026
A guest with a PCI device assigned that has at least a BAR on the IO port<br /> space can trigger a BUG() in Xen.
Severity CVSS v4.0: Pending analysis
Last modification:
08/09/2026

CVE-2026-77105

Publication date:
08/09/2026
CommServe contained a cryptographic signature verification issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update CommServe and Web Server.
Severity CVSS v4.0: HIGH
Last modification:
08/09/2026

CVE-2026-77106

Publication date:
08/09/2026
Cvlaunchd contained a missing authorization issue affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.
Severity CVSS v4.0: HIGH
Last modification:
08/09/2026

CVE-2026-77103

Publication date:
08/09/2026
CommServe contained an authentication bypass issue affecting access authorization and information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.
Severity CVSS v4.0: HIGH
Last modification:
08/09/2026

CVE-2026-77104

Publication date:
08/09/2026
CommServe contained a path traversal issue affecting information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.
Severity CVSS v4.0: HIGH
Last modification:
08/09/2026

CVE-2026-77091

Publication date:
08/09/2026
DataCube contained a path traversal issue affecting security feature enforcement. Software customers upgrade to resolved maintenance release. Update Content Extractor and Index Store.
Severity CVSS v4.0: HIGH
Last modification:
08/09/2026

CVE-2026-77092

Publication date:
08/09/2026
Content Extractor contained a deserialization of untrusted data issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Content Extractor.
Severity CVSS v4.0: HIGH
Last modification:
08/09/2026

CVE-2026-77097

Publication date:
08/09/2026
Private Metrics Server contained a missing authentication condition affecting metrics upload functionality and service availability. Software customers upgrade to resolved maintenance release. Update Private Metrics Server.
Severity CVSS v4.0: HIGH
Last modification:
08/09/2026

CVE-2026-77098

Publication date:
08/09/2026
Private Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to resolved maintenance release. Update Private Metrics Server.
Severity CVSS v4.0: HIGH
Last modification:
08/09/2026

CVE-2026-77089

Publication date:
08/09/2026
Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center.
Severity CVSS v4.0: CRITICAL
Last modification:
08/09/2026

CVE-2026-77101

Publication date:
08/09/2026
CommServe contained a stack-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.
Severity CVSS v4.0: HIGH
Last modification:
08/09/2026