Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-57243

Fecha de publicación:
08/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** During the process of page opening and form formatting, a JavaScript reentrancy results in an inconsistent document status. Subsequently, with outdated page information, the application attempts to access invalid addresses, causing the application to crash.
Gravedad CVSS v3.1: MEDIA
Última modificación:
09/07/2026

CVE-2026-57241

Fecha de publicación:
08/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The application opens the PDF, and JavaScript performs operations on the page and the document, causing the page-related objects within the application to lose synchronization; however, the renderer still trusts the outdated page count, and eventually the application crashes due to out-of-bounds access.
Gravedad CVSS v3.1: MEDIA
Última modificación:
09/07/2026

CVE-2026-57237

Fecha de publicación:
08/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** When the application opens a PDF and JavaScript modifies the properties of form fields, it causes the state of the underlying objects referenced by the program to become invalid. Eventually, it reads an illegal memory address, which leads to the crash of the application.
Gravedad CVSS v3.1: ALTA
Última modificación:
09/07/2026

CVE-2026-57238

Fecha de publicación:
08/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** After the application opened the PDF, JavaScript deleted the form field object. Subsequently, it attempted to access the invalid object, which caused the application to crash.
Gravedad CVSS v3.1: ALTA
Última modificación:
09/07/2026

CVE-2026-57240

Fecha de publicación:
08/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** When the application opens a PDF file and JavaScript deletes the PDF fields, the subsequent logic still uses the old field pointers, resulting in invalid pointer references and causing the application to crash.
Gravedad CVSS v3.1: ALTA
Última modificación:
09/07/2026

CVE-2026-57239

Fecha de publicación:
08/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege users to have the opportunity to elevate their privileges to NT AUTHORITY\SYSTEM.
Gravedad CVSS v3.1: ALTA
Última modificación:
09/07/2026

CVE-2026-56001

Fecha de publicación:
08/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by attackers able to access the X Server to execute code within the X server cont
Gravedad CVSS v3.1: ALTA
Última modificación:
09/07/2026

CVE-2026-13127

Fecha de publicación:
08/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The application opens the PDF file. JavaScript then rewrites the document to modify the page structure, resulting in the invalidation of the page objects. However, the thumbnails still use the invalid page objects, ultimately causing the application to crash.
Gravedad CVSS v3.1: ALTA
Última modificación:
09/07/2026

CVE-2026-13128

Fecha de publicación:
08/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Embedding JavaScript within a PDF file will cause the page to be deleted. Subsequent scripts will continue to access the relevant properties of the document view, eventually leading to the crash of the application.
Gravedad CVSS v3.1: ALTA
Última modificación:
09/07/2026

CVE-2026-13129

Fecha de publicación:
08/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** When the application opens a PDF file, JavaScript uses the damaged field tree to trigger field traversal, resulting in the program holding an invalid form object when accessing the field property path. Eventually, the application crashes due to reading an invalid pointer.
Gravedad CVSS v3.1: ALTA
Última modificación:
09/07/2026

CVE-2026-13126

Fecha de publicación:
08/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The embedded JavaScript in the PDF deleted the pages, making the object invalid. The application attempted to perform a write operation on the invalid pop-up annotations, resulting in the program crashing.
Gravedad CVSS v3.1: ALTA
Última modificación:
09/07/2026

CVE-2026-56000

Fecha de publicación:
08/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
09/07/2026