Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1019
Esta semana
RSS
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-16176] IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10,…
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to cause a denial of service due to improper validation of the length field during memory reallocation.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-107212] Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.1.0 t…
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.1.0 to 2.11.0, Rows.Columns accepts a look-ahead row number above TotalRows without applying the limit enforced by Rows.Next. File.GetRows relies on Rows.Next and Rows.Columns, but Rows.Columns consumes the row r attribute without the limit check in Rows.Next. When a crafted worksheet places an oversized…
M Alto vulnerabilidad
02/10/2026
[CVE-2026-104845] Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify cap…
Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.6.3, deserializeTypedArray in fromJSON and fromCrossJSON trusts a deserialized source value as an ArrayBuffer and does not bound the serialized element count. An attacker can provide a small untrusted JSON object with a large length value, causing the array-like TypedArray cons…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-103761] Mooncake transfer engine through 0.3.13.post1 contains a memory exhaustion vulnerability in Transfer…
Mooncake transfer engine through 0.3.13.post1 contains a memory exhaustion vulnerability in TransferMetadata::receivePeerNotify that allows unauthenticated attackers to grow process memory without limit. Attackers can repeatedly send notify frames up to 1 MB to the handshake RPC port, filling the uncapped notifys vector until the out-of-memory killer terminates the engine.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-68495] The CBOR parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validate…
The CBOR parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced for this format. CBORParser._decodeLongerName() decodes a definite-length property name with no length check, and CBORParser._decodeChunkedName() delegates to the value-oriented _finishChunkedText() rou…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-68496] The Smile parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validat…
The Smile parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced for this format. SmileParser._handleLongFieldName() grows its internal name buffer through an unconstrained _growArrayTo() call and performs no length validation. An attacker who can have a Smile docum…
M Alto vulnerabilidad
01/10/2026
[CVE-2023-54404] Zod schema-validation library through 4.6.5 contains an uncontrolled resource consumption vulnerabil…
Zod schema-validation library through 4.6.5 contains an uncontrolled resource consumption vulnerability that allows attackers to exhaust memory by submitting a large array to an application using an array schema without a length constraint. Attackers can exploit the handleArrayResult parse logic in $ZodArray, which accumulates every validation issue for each failing element with no cap or early te…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
30/09/2026
[CVE-2026-103471] restbed through 5.0.0 buffers HTTP request headers without enforcing a maximum size limit, allowing …
restbed through 5.0.0 buffers HTTP request headers without enforcing a maximum size limit, allowing remote unauthenticated attackers to exhaust server memory. Attackers can open TCP connections and stream bytes indefinitely without sending the header delimiter, forcing the server to allocate unbounded heap memory until the process is killed.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-103472] restbed through 5.0.0 accepts WebSocket frames with declared payload lengths up to 2^63 bytes and bu…
restbed through 5.0.0 accepts WebSocket frames with declared payload lengths up to 2^63 bytes and buffers the payload without size limits in an unbounded stream buffer. Remote unauthenticated attackers can declare large frame sizes and stream payload data to exhaust server memory, causing denial of service through process crash.
M Alto vulnerabilidad
30/09/2026
Vulnerabilidad alta en CODESYS Gateway Client permite denegación de servicio remota
El cliente CODESYS Gateway asigna memoria basándose en campos de tamaño en respuestas de gateway sin límites superiores, permitiendo a atacantes remotos no autenticados consumir recursos excesivos mediante un gateway malicioso. Esta vulnerabilidad afecta sistemas de automatización industrial (SCADA/ICS) en manufactura, servicios públicos y plantas de México y Latinoamérica, resultando en pérdida total de disponibilidad de los sistemas afectados.
M Alto vulnerabilidad
30/09/2026
Agotamiento de memoria en clientes SFTP de Apache MINA SSHD (CVE-2026-94002)
Apache MINA SSHD versiones 0.9.0 a 2.19.0 y 3.0.0-M1 a 3.0.0-M5 contienen una vulnerabilidad de agotamiento de memoria en el componente sshd-sftp. El cliente SFTP (DefaultSftpClient) no valida que las respuestas recibidas correspondan a solicitudes legítimas, permitiendo consumo excesivo de recursos. Afecta a aplicaciones Java que utilizan esta biblioteca para transferencia de archivos segura.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-103101] Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input validation in the web ser…
Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input validation in the web server that allows a malicious attacker to render a Pexip Infinity node inaccessible.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-103102] Pexip Infinity before 41.0 is affected by improper input validation in the signaling implementation …
Pexip Infinity before 41.0 is affected by improper input validation in the signaling implementation which allows a remote attacker to trigger a software abort resulting in a denial of service. Exploitation of this issue requires accessing a gateway call from a WebRTC/API client.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-103042] LightLLM through 1.2.0 contains a memory exhaustion vulnerability in the NCCL control channel when s…
LightLLM through 1.2.0 contains a memory exhaustion vulnerability in the NCCL control channel when started with --pd_trans_mode nccl, allowing unauthenticated attackers to exhaust KV-transfer worker memory. Attackers can call the exposed_set_value method to store unbounded key-value pairs without size limits, causing the worker process to crash and triggering node failure.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-84784] Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames …
Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use. Impact summary: The local QUIC stack sends a RETIRE_CONN_ID frame for every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID frame is dispatched via the Control Frame Queue (CFQ). If the remote peer also with…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100655] Netty (io.netty:netty-codec-http) versions up to and including 4.1.137.Final and from 4.2.0.Final th…
Netty (io.netty:netty-codec-http) versions up to and including 4.1.137.Final and from 4.2.0.Final through 4.2.17.Final accept an unlimited number of concurrent remote-initiated SPDY streams: SpdySessionHandler defaults localConcurrentStreams to Integer.MAX_VALUE and exposes no API to change it. A remote peer that opens a SPDY connection and sends millions of SYN_STREAM frames with FLAG_FIN=0 cause…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100656] Netty (io.netty:netty-codec-http) contains an unbounded per-connection queue growth flaw in HttpServ…
Netty (io.netty:netty-codec-http) contains an unbounded per-connection queue growth flaw in HttpServerCodec. The codec tracks the HTTP method of each still-unanswered pipelined request; the first 32 entries are bit-packed into a single long, but every additional entry is appended to methodOverflowQueue, an ArrayDeque with no size limit and no rejection path. A remote, unauthenticated attacker who …
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100660] Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.0.Final through 4.2.17.Final retains unbo…
Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.0.Final through 4.2.17.Final retains unbounded per-stream QPACK encoder state. QpackEncoder stores a queue and a dynamic-table index tracker for every encoded field section that references the QPACK dynamic table, keyed by the peer-controlled QUIC stream ID, and these entries are released only when the remote decoder sends a Section Acknow…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-92560] A pre-authentication attacker could leverage type size/count handling to cause excessive allocation …
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue.
M Alto vulnerabilidad
24/09/2026
[CVE-2026-71540] Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints an…
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. From 3.9.0 until 4.14.7, wazuh-clusterd in framework/wazuh/core/cluster/common.py allocates a payload buffer using the size declared in a 20-byte cluster protocol header before Fernet decryption validates the peer. An unauthenticated network peer can declare a payload of up to 256…