Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1013
Esta semana
RSS
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-107214] Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 t…
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, the decryption dispatch performs insufficient structural and parameter validation before standard and agile decryptors slice, index, allocate, and divide using attacker-controlled values. Decrypt passes attacker-controlled EncryptionInfo and EncryptedPackage data into standardDecrypt or ag…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-58859] In multiple places, there is a possible denial of service due to an uncaught exception. This could …
In multiple places, there is a possible denial of service due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-96274] In Baicells Nova 430H, an unauthenticated device within radio range can send a malformed uplink mess…
In Baicells Nova 430H, an unauthenticated device within radio range can send a malformed uplink message during connection setup that contains an invalid NAS payload. Because the eNodeB does not properly validate this payload, it forwards the message to the core network, which can trigger a shutdown of the signaling association for the cell. This results in a temporary service disruption until the …
M Alto vulnerabilidad
28/09/2026
[CVE-2026-102281] Nest is a framework for building scalable Node.js server-side applications. Prior to 11.2.4 and 12.0…
Nest is a framework for building scalable Node.js server-side applications. Prior to 11.2.4 and 12.0.2, a single message with a deeply nested object in its pattern can terminate a NestJS microservice using the TCP or RabbitMQ transport. ServerTCP#handleMessage and ServerRMQ#handleMessage pass a client-controlled non-string pattern to JSON.stringify to derive the handler lookup key; sufficiently de…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-92608] Improper handling of property-encoding exceptions in AMQP 1.0-to-AMQP 0-10 message conversion allows…
Improper handling of property-encoding exceptions in AMQP 1.0-to-AMQP 0-10 message conversion allows authenticated message producers to disrupt delivery to AMQP 0-10 consumers via message properties that the target encoder does not handle correctly. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-62985] request-filtering-agent is an http(s).Agent implementation that blocks requests to Private/Reserved …
request-filtering-agent is an http(s).Agent implementation that blocks requests to Private/Reserved IP addresses. Prior to 3.2.1, RequestFilteringHttpAgent and RequestFilteringHttpsAgent synchronously threw from createConnection when rejecting a literal private-IP host such as 169.254.169.254 or 127.0.0.1. Because Node.js http.request and http.get expect connection failures to be delivered asynchr…
M Alto vulnerabilidad
21/09/2026
[CVE-2026-94622] vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metad…
vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metadata handling for prefill/decode disaggregated deployments. Attackers can send requests with incomplete kv_transfer_params dictionary entries to trigger an uncaught KeyError in EngineCore scheduling, causing the decode engine to terminate and making all routed requests fail until manual restart.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
18/09/2026
[CVE-2026-32641] Parseable is a log analytics platform built for high-volume data ingestion and analysis. Prior to 3.…
Parseable is a log analytics platform built for high-volume data ingestion and analysis. Prior to 3.0.0, src/handlers/http/middleware.rs uses unwrap() while parsing the x-amz-firehose-common-attributes header before authentication. A remote unauthenticated attacker can supply non-UTF-8 header data, malformed JSON, or invalid derived header values that trigger a Rust panic and interrupt request han…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-92954] vm2 is a sandbox library for running untrusted JavaScript in Node.js. In versions >= 3.10.0 and <= 3…
vm2 is a sandbox library for running untrusted JavaScript in Node.js. In versions >= 3.10.0 and
M Alto vulnerabilidad
06/09/2026
Vulnerabilidad alta en PocketMine-MP anterior a 4.7.2 permite negación de servicio
PocketMine-MP versiones anteriores a 4.7.2 no maneja adecuadamente excepciones de la librería adhocore/json-comment al procesar datos de geometría de skins. Atacantes pueden enviar paquetes de inicio de sesión o skin malformados para provocar una excepción no controlada que causa el colapso del servidor. Este fallo afecta directamente a servidores de juego en México y Latinoamérica que dependen de PocketMine-MP para Minecraft Pocket Edition.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-19534] undici's WebSocket client crashes the whole Node.js process during the opening handshake when a serv…
undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A default WebSocket connection sends no subprotocol, but if the server's 101 response includes a Sec-WebSocket-Protocol header, undici dereferences a null value while checking it against the requested list and throws an uncaught TypeErr…
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad alta en MongoDB Connector for BI permite denegación de servicio remota
Una parte no autenticada que acceda al puerto del conector MongoDB para BI (mongosqld) puede generar actividad masiva de registros de conexión que agoten el almacenamiento del directorio de logs configurado. Cuando la escritura o rotación de logs falla, el proceso compartido de mongosqld se interrumpe abruptamente, causando denegación de servicio para todos los clientes SQL conectados. Este impacto afecta directamente plataformas de análisis e inteligencia empresarial que dependen de este conector en infraestructuras LATAM.
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad alta en multer permite denegación de servicio en aplicaciones Node.js
multer, middleware estándar para procesar datos multipart/form-data en Node.js, contiene una vulnerabilidad que causa RangeError no controlado al recibir solicitudes especialmente crafteadas con nombres de campos numéricos malformados. Un atacante puede terminar abruptamente el proceso Node.js, afectando disponibilidad de plataformas digitales en empresas mexicanas y latinoamericanas que usan este componente en APIs de carga de archivos.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-55484] ALOS HTTP is a Linux-first Go web framework and application server built around a custom networking …
ALOS HTTP is a Linux-first Go web framework and application server built around a custom networking stack. Prior to 0.0.0-20260617230736-314b6783e196, core/utils.go::sanitizeRequestPath calls splitPathQuery on a request path beginning with a question mark and then performs the unchecked p[0] access without checking whether the resulting path is empty. An unauthenticated client can send a malformed…
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad alta en gitoxide anterior a 0.69.0 permite ataques de denegación de servicio
gitoxide versiones anteriores a 0.69.0 presentan indexación de matriz sin validación y asignación de memoria sin límite en el componente gix-pack. Atacantes pueden enviar datos de pack manipulados durante operaciones de clonación o descarga para provocar pánico del proceso o agotamiento de memoria. Esta vulnerabilidad afecta principalmente a desarrolladores y plataformas que usan gitoxide para operaciones Git automatizadas en infraestructuras de CI/CD.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
12/08/2026
[CVE-2026-73418] NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 an…
NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the exported getToken() helper in the next-auth/jwt and @auth/core/jwt modules can throw an uncaught exception when it reads a malformed Authorization: Bearer header. When no session cookie is present, getToken() URL-decodes the bearer value before validating it, and malformed perce…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-73088] Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-…
Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, normalizeStats() in node.js, reached unconditionally through getStat() and loadStat() on every browserslist() call, processes untrusted browserslist-stats.json, opts.stats, and CLI --stats data with an unguarded for...in loop and plain-object bracket access and assignment…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-62909] Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.
Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
31/07/2026
[CVE-2026-52856] Wings is the server control plane for Pterodactyl, a free, open-source game server management panel.…
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received during the SFTP connection handshake causes a Go panic. This issue is fixed in version 1.13.0.
M Alto vulnerabilidad
29/07/2026
[CVE-2026-13697] undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up…
undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 and 8.0.0 up to before 8.9.0, a response carrying a degenerate qualified private directive, such as private set to an empty value, can be stored in the default shared cache and later served to a different caller with the same cache key, disclosing private response bodies and header…