Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-86513

Publication date:
08/09/2026
A security flaw has been discovered in java-json-tools jackson-coreutils 2.0. This vulnerability affects the function TreePointer.tokensFromInput of the file src/main/java/com/github/fge/jackson/jsonpointer/TreePointer.java of the component JSON Pointer parser. The manipulation results in allocation of resources. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Severity CVSS v4.0: MEDIUM
Last modification:
28/09/2026

CVE-2026-86514

Publication date:
08/09/2026
A weakness has been identified in vgmstream up to r2117. This issue affects the function sscanf of the file src/meta/txth.c of the component txth-txtp. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. Patch name: 4669d37a6af94866f6f0628678f9f90d46954e8b. To fix this issue, it is recommended to deploy a patch.
Severity CVSS v4.0: LOW
Last modification:
28/09/2026

CVE-2026-86515

Publication date:
08/09/2026
A security vulnerability has been detected in vgmstream up to r2117. Impacted is the function add_entry of the file src/meta/txtp_parser.c of the component txtp. Such manipulation of the argument range_start/range_end leads to resource consumption. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The name of the patch is 4b6a02dd1aff6428255db912563d77d4cb0a143e. It is advisable to implement a patch to correct this issue.
Severity CVSS v4.0: LOW
Last modification:
28/09/2026

CVE-2026-18023

Publication date:
08/09/2026
Sensitive Information in Resource Not Removed Before Reuse in ASUS Armoury Crate driver allows a local user to disclose sensitive information from uninitialized memory via a crafted IOCTL request that bypasses the driver&amp;#39;s security verification mechanism.<br /> Refer to the &amp;#39;<br /> Security Update for Armoury Crate App &amp;#39; section on the ASUS Security Advisory for more information.
Severity CVSS v4.0: MEDIUM
Last modification:
28/09/2026

CVE-2026-19397

Publication date:
08/09/2026
Missing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to control the host via a direct connection to the agent when the host has an active login session.<br /> Refer to the &amp;#39; <br /> Security Update for ASUS Control Center Express Agent &amp;#39; section on the ASUS Security Advisory for more information.
Severity CVSS v4.0: HIGH
Last modification:
28/09/2026

CVE-2026-75808

Publication date:
08/09/2026
Allocation of Resources Without Limits or Throttling in ASUS Armoury Crate allows a local user to cause a denial-of-service condition through system memory exhaustion by bypassing driver authentication and allocating an unrestricted amount of memory.Refer to the &amp;#39;<br /> Security Update for Armoury Crate App &amp;#39; section on the ASUS Security Advisory for more information.
Severity CVSS v4.0: MEDIUM
Last modification:
28/09/2026

CVE-2026-75809

Publication date:
08/09/2026
Exposed IOCTL with insufficient access control in ASUS Armoury Crate allows a local user to disclosure information and disabling device functionality by bypassing driver authentication and using IOCTLs to read from and write to PCIe configuration space.Refer to the &amp;#39;<br /> Security Update for Armoury Crate App &amp;#39; section on the ASUS Security Advisory for more information.
Severity CVSS v4.0: MEDIUM
Last modification:
28/09/2026

CVE-2026-75810

Publication date:
08/09/2026
Exposed Dangerous Method or Function in ASUS Armoury Crate allow a local user to cause a brief system stall by bypassing driver authentication and sending requests to trigger system management interrupts (SMIs). Repeatedly triggering SMI may lead to a denial-of-service (DoS) condition.Refer to the &amp;#39;<br /> Security Update for Armoury Crate App &amp;#39; section on the ASUS Security Advisory for more information.
Severity CVSS v4.0: MEDIUM
Last modification:
28/09/2026

CVE-2026-12962

Publication date:
08/09/2026
A Permissive Cross-domain Security Policy with Untrusted Domains in Armoury Crate allows a remote user to obtain a local user&amp;#39;s NTLM hash by convincing the user to visit a crafted web page that sends a request containing a UNC path to the application&amp;#39;s local service endpoint.Refer to the &amp;#39;<br /> Security Update for Armoury Crate App &amp;#39; section on the ASUS Security Advisory for more information.
Severity CVSS v4.0: MEDIUM
Last modification:
08/09/2026

CVE-2026-16004

Publication date:
08/09/2026
Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to read and write arbitrary PCI/PCIe configuration space via crafted IOCTL requests by bypassing the driver&amp;#39;s verification.<br /> Refer to the &amp;#39;<br /> Security Update for Armoury Crate App&amp;#39; section on the ASUS Security Advisory for more information.
Severity CVSS v4.0: MEDIUM
Last modification:
08/09/2026

CVE-2026-16005

Publication date:
08/09/2026
Release of Invalid Pointer or Reference in Armoury Crate driver allows a local user to free arbitrary memory via a crafted IOCTL request by bypassing the driver&amp;#39;s verification, which can corrupt data structures and cause a system crash (BSOD).Refer to the &amp;#39;<br /> Security Update for Armoury Crate App  &amp;#39; section on the ASUS Security Advisory for more information.
Severity CVSS v4.0: MEDIUM
Last modification:
08/09/2026

CVE-2026-16003

Publication date:
08/09/2026
Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to add an arbitrary process identifier to the driver&amp;#39;s whitelist via a crafted IOCTL request by bypassing the driver&amp;#39;s verification.Refer to the &amp;#39;<br /> Security Update for Armoury Crate App  &amp;#39; section on the ASUS Security Advisory for more information.
Severity CVSS v4.0: LOW
Last modification:
08/09/2026