Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-66918

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Pivotick fails to sanitize attacker-controlled SVG markup supplied through the per-node style.svgIcon property before inserting it into the document.<br /> <br /> When rendering a graph node, the vulnerable code assigns the SVG icon markup directly to the innerHTML property of a live SVG element. An attacker able to influence graph data can provide crafted markup containing executable event handlers, such as an element with an onerror attribute.<br /> <br /> When a victim loads or renders the malicious graph, the payload may execute arbitrary JavaScript in the security context of the application embedding Pivotick. Successful exploitation could allow the attacker to access application data available to the victim, modify displayed content, or perform actions using the victim’s authenticated session.<br /> <br /> Exploitation requires an application using Pivotick to render graph data that is controlled or modified by an attacker.
Gravedad CVSS v4.0: ALTA
Última modificación:
28/07/2026

CVE-2026-66919

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Pivotick contains a cross-site scripting vulnerability in the inspect and edit node modals. Node labels and descriptions originating from graph data were interpolated directly into HTML used to construct the modal headers.<br /> <br /> An attacker able to supply or modify graph data could insert a malicious HTML or JavaScript payload into a node’s label or description. The payload would be parsed and executed in the application’s origin when a user opened the affected node’s inspect or edit modal.<br /> <br /> Successful exploitation could allow the attacker to access information available to the victim, modify application data, or perform actions using the victim’s active session.<br /> <br /> The vulnerability has been addressed by creating the modal elements without embedding graph data in HTML and assigning node labels and descriptions through textContent.
Gravedad CVSS v4.0: MEDIA
Última modificación:
28/07/2026

CVE-2026-62435

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** [This CNA information record relates to multiple CVEs; the<br /> text explains which aspects/vulnerabilities correspond to which CVE.]<br /> <br /> With the introduction of Grant Table v2 came the requirement to be able to<br /> switch between versions. Switching from v1 to v2 reduces the number of<br /> valid grant references, as a bigger shared entry structure is then needed<br /> while the shared table doesn&amp;#39;t change size. Switching from v2 back to v1<br /> the status frames, which are separate in v2, go away.<br /> <br /> Code holding, but intermediately dropping and then re-acquiring the grant<br /> table lock, sometimes wrongly assumes that said properties wouldn&amp;#39;t change<br /> across the window in time where the lock is not being held.<br /> <br /> The v1 -&gt; v2 issue is CVE-2026-62435.<br /> <br /> The v2 -&gt; v1 issue is CVE-2026-62436.
Gravedad: Pendiente de análisis
Última modificación:
28/07/2026

CVE-2026-62436

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** [This CNA information record relates to multiple CVEs; the<br /> text explains which aspects/vulnerabilities correspond to which CVE.]<br /> <br /> With the introduction of Grant Table v2 came the requirement to be able to<br /> switch between versions. Switching from v1 to v2 reduces the number of<br /> valid grant references, as a bigger shared entry structure is then needed<br /> while the shared table doesn&amp;#39;t change size. Switching from v2 back to v1<br /> the status frames, which are separate in v2, go away.<br /> <br /> Code holding, but intermediately dropping and then re-acquiring the grant<br /> table lock, sometimes wrongly assumes that said properties wouldn&amp;#39;t change<br /> across the window in time where the lock is not being held.<br /> <br /> The v1 -&gt; v2 issue is CVE-2026-62435.<br /> <br /> The v2 -&gt; v1 issue is CVE-2026-62436.
Gravedad: Pendiente de análisis
Última modificación:
28/07/2026

CVE-2026-62431

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The logic to handle periodic Viridian STIMERs performs a division with an<br /> unchecked user-controlled divisor value, that can be set to zero to cause a #DE<br /> fault.
Gravedad: Pendiente de análisis
Última modificación:
28/07/2026

CVE-2026-62432

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The EVTCHNOP_expand_array hypercall checks for whether FIFO event<br /> channels are enabled, but without holding the correct lock. It can race<br /> with EVTCHNOP_reset, resulting in dereferencing a NULL pointer.
Gravedad: Pendiente de análisis
Última modificación:
28/07/2026

CVE-2026-62433

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Parts of the DM_OP handling code assumes the caller has provided the<br /> required number of buffers for the given operation without any checking<br /> being done. As a result, certain operations might access stack<br /> rubble as structures are possibly uninitialized.
Gravedad: Pendiente de análisis
Última modificación:
28/07/2026

CVE-2026-62434

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A guest started with Populated on Demand enabled (PoD) can attempt to<br /> reclaim pages which aren&amp;#39;t regular guest RAM. This can cause corruption<br /> of memory management state in Xen.
Gravedad: Pendiente de análisis
Última modificación:
28/07/2026

CVE-2026-62423

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** [This CNA information record relates to multiple CVEs; the<br /> text explains which aspects/vulnerabilities correspond to which CVE.]<br /> <br /> The directory and Rock Ridge / SUSP walk in libfsimage&amp;#39;s iso9660 driver<br /> derives several lengths directly from attacker-controlled on-disk fields<br /> without validating them:<br /> <br /> * The directory loop itself assumes a good record length. This is<br /> CVE-2026-42494.<br /> <br /> * The calculation of the System Use area may underflow. This is<br /> CVE-2026-42495.<br /> <br /> * The Rock Ridge extension loop assumes a good (inner) record length.<br /> This is CVE-2026-62423.<br /> <br /> * The Rock Ridge NM record processing assumes a good entry length.<br /> This is CVE-2026-62424.<br /> <br /> * The Rock Ridge CE record processing assumes a good size and offset.<br /> This is CVE-2026-62425.
Gravedad: Pendiente de análisis
Última modificación:
28/07/2026

CVE-2026-62424

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** [This CNA information record relates to multiple CVEs; the<br /> text explains which aspects/vulnerabilities correspond to which CVE.]<br /> <br /> The directory and Rock Ridge / SUSP walk in libfsimage&amp;#39;s iso9660 driver<br /> derives several lengths directly from attacker-controlled on-disk fields<br /> without validating them:<br /> <br /> * The directory loop itself assumes a good record length. This is<br /> CVE-2026-42494.<br /> <br /> * The calculation of the System Use area may underflow. This is<br /> CVE-2026-42495.<br /> <br /> * The Rock Ridge extension loop assumes a good (inner) record length.<br /> This is CVE-2026-62423.<br /> <br /> * The Rock Ridge NM record processing assumes a good entry length.<br /> This is CVE-2026-62424.<br /> <br /> * The Rock Ridge CE record processing assumes a good size and offset.<br /> This is CVE-2026-62425.
Gravedad: Pendiente de análisis
Última modificación:
28/07/2026

CVE-2026-62425

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** [This CNA information record relates to multiple CVEs; the<br /> text explains which aspects/vulnerabilities correspond to which CVE.]<br /> <br /> The directory and Rock Ridge / SUSP walk in libfsimage&amp;#39;s iso9660 driver<br /> derives several lengths directly from attacker-controlled on-disk fields<br /> without validating them:<br /> <br /> * The directory loop itself assumes a good record length. This is<br /> CVE-2026-42494.<br /> <br /> * The calculation of the System Use area may underflow. This is<br /> CVE-2026-42495.<br /> <br /> * The Rock Ridge extension loop assumes a good (inner) record length.<br /> This is CVE-2026-62423.<br /> <br /> * The Rock Ridge NM record processing assumes a good entry length.<br /> This is CVE-2026-62424.<br /> <br /> * The Rock Ridge CE record processing assumes a good size and offset.<br /> This is CVE-2026-62425.
Gravedad: Pendiente de análisis
Última modificación:
28/07/2026

CVE-2026-62426

Fecha de publicación:
28/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** [This CNA information record relates to multiple CVEs; the<br /> text explains which aspects/vulnerabilities correspond to which CVE.]<br /> <br /> To manage the system, sysctl and platform operations are used by the<br /> control domain or a possible Xenstore domain. Some of these operations<br /> may not be executed in parallel, so a system-wide lock each is used.<br /> The way those locks are acquired is, however, not providing any fairness.<br /> Furthermore, with XSM/Flask in use, the lock acquire will, for some<br /> operations, occur ahead of any permission checking.<br /> <br /> The sysctl issue is CVE-2026-62426.<br /> <br /> The platform-op issue is CVE-2026-62427.
Gravedad: Pendiente de análisis
Última modificación:
28/07/2026