Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1016
Esta semana
RSS
M Alto vulnerabilidad
08/09/2026
[CVE-2026-82071] Insufficient validation of storage engine configuration options in MongoDB Server allows an authenti…
Insufficient validation of storage engine configuration options in MongoDB Server allows an authenticated user with write privileges to supply crafted parameters during collection creation that override internal storage metadata. This results in an out-of-bounds memory write in the server process, causing a denial of service via server crash, with potential for further impact including arbitrary c…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-62648] A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The length of the URL c…
A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The length of the URL component contained in pre-authenticated HTTP messages is not properly validated before appending additional data to it, resulting in an out-of-bounds write condition in memory. This could allow an unauthenticated remote attacker to crash the affected device, causing a reboot and resulting in a denia…
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-86510] A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params …
A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86313] Out-of-bounds write vulnerability in Samsung Opensource Walrus allows Overflow Buffers. This issue …
Out-of-bounds write vulnerability in Samsung Opensource Walrus allows Overflow Buffers. This issue affects Walrus: af80e665ea49d9003695a66502f841ed1d8397e7.
M Alto vulnerabilidad
05/09/2026
[CVE-2026-0799] In BPF instructions that load/store a value from/to a scratch memory register the register index is …
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit…
M Alto vulnerabilidad
04/09/2026
[CVE-2026-86095] Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in NC4_HDF5_inq_attnam…
Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in NC4_HDF5_inq_attname() that copies HDF5 attribute names into a fixed 256-byte buffer without length validation. Attackers can craft HDF5 files with oversized attribute names to overflow the destination buffer, causing memory corruption and crashes when applications enumerate attribute names.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-86098] ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerability in the ndpi_json_string_e…
ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerability in the ndpi_json_string_escape function that writes beyond caller-supplied buffer boundaries. Attackers can trigger the overflow by supplying crafted network packet data including TLS SNI, HTTP headers, or DNS names that reach the vulnerable function, causing heap corruption.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
04/09/2026
[CVE-2026-80113] PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics …
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to clear arbitrary bits at any physical memory address due to missing validation of the physical address parameter in an exposed IOCTL handler. Attackers can obtain a device handle and suppl…
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85452] MOOS ui-moos through 50b9c6c contains a buffer overflow vulnerability in ScopeTabPane.cpp and ScopeG…
MOOS ui-moos through 50b9c6c contains a buffer overflow vulnerability in ScopeTabPane.cpp and ScopeGrid.cpp where client and variable names are formatted into fixed 1024-byte buffers using sprintf without length validation. Attackers can supply arbitrarily long MOOS identifiers that overflow the buffers when an operator selects process list entries or pokes variables, enabling code execution.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85437] MOOS-IvP through 24.8.1 contains multiple buffer overflow vulnerabilities in IvP function string dec…
MOOS-IvP through 24.8.1 contains multiple buffer overflow vulnerabilities in IvP function string decoders that trust attacker-controlled length fields without validation. Attackers can craft malicious encoded strings with mismatched declared and actual field lengths to overflow heap and stack buffers, potentially achieving remote code execution through MOOS variables or alog files.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85440] MOOS core-moos through 10.4.0 contains a pre-authentication heap overflow vulnerability in MOOSCommP…
MOOS core-moos through 10.4.0 contains a pre-authentication heap overflow vulnerability in MOOSCommPkt packet handling that allows remote attackers to write arbitrary data by declaring a negative packet length. Attackers can exploit the signed integer check in InflateTo() and negative size conversion in recv() to overflow a four-byte heap buffer during the HandShake phase before authentication.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-64197] There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied…
There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated data structure. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-64195] There is an out-of-bounds write vulnerability in DASYLab due to lack of proper validation of user-su…
There is an out-of-bounds write vulnerability in DASYLab due to lack of proper validation of user-supplied data. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-64196] There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied…
There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated heap. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85050] Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote …
Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85091] zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() …
zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-71220] A stack out-of-bounds write vulnerability was found in gfs2-utils. In gfs2_edit, the di_height field…
A stack out-of-bounds write vulnerability was found in gfs2-utils. In gfs2_edit, the di_height field from on-disk inode metadata is used as an array index without bounds checking, causing a stack buffer overflow that may lead to arbitrary code execution when processing crafted GFS2 filesystem images.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-71221] A stack out-of-bounds write vulnerability was found in gfs2-utils. In savemeta, the height value fro…
A stack out-of-bounds write vulnerability was found in gfs2-utils. In savemeta, the height value from on-disk inode metadata is used as a loop bound without bounds checking, causing a stack buffer overflow that may lead to arbitrary code execution when processing crafted GFS2 filesystem images.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-13732] A flaw was found in GDB's STABS debug format parser. The read_member_functions() function in gdb/sta…
A flaw was found in GDB's STABS debug format parser. The read_member_functions() function in gdb/stabsread.c contains a linked list removal bug in the code that separates destructor and non-destructor member functions of C++ classes. The bug causes the destructor entries to remain in the main function list while the list length counter is decremented, resulting in an out-of-bounds write when the f…
M Alto vulnerabilidad
31/08/2026
Vulnerabilidad alta en D-Link DSM-G600 1.01 permite escritura fuera de límites
Se ha identificado una debilidad en el manejador multiparte del archivo /load_file.cgi en dispositivos D-Link DSM-G600 versión 1.01, que permite escritura fuera de límites (out-of-bounds write) explotable remotamente. Con CVSS 8.8, esta vulnerabilidad afecta directamente a empresas en LATAM que utilizan estos dispositivos en infraestructuras de almacenamiento NAS, permitiendo a atacantes comprometer sistemas sin autenticación. El exploit está disponible públicamente, elevando significativamente el riesgo de explotación inmediata.