Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1052
Esta semana
RSS
M Alto vulnerabilidad
05/06/2026
[CVE-2026-50234] Lyrion Music Server 9.2.0 contains a path traversal vulnerability that allows unauthenticated attack…
Lyrion Music Server 9.2.0 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting directory traversal in the web server context. Attackers can manipulate file path parameters to access sensitive files outside the intended directory structure.
X Alto vulnerabilidad
05/06/2026
[CVE-2026-50264] An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuff…
An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger an out-of-bounds heap write. This may be used to crash the server, or for privilege escalation if the X server runs as root.
X Alto vulnerabilidad
05/06/2026
[CVE-2026-50258] A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has mu…
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes() does not verify or clamp non-canonical key types to XkbMaxShiftLevel. A client can change key types to excessive shift levels and trigger stack overflows. This is caused by an incomplete fix of CVE-2025-26597. This may…
X Alto vulnerabilidad
05/06/2026
[CVE-2026-50259] A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() …
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer mapWidths[256] indexed by key type index. The helper function CheckKeyTypes() writes to this buffer at a client-controlled offset, allowing a stack buffer overflow. This may be used to crash the server, or for privilege escalation if the X server runs as root.
X Alto vulnerabilidad
05/06/2026
[CVE-2026-50260] A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that s…
A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-after-free when destroying those counters via a second client connection. This may be used to crash the server, or for privilege escalation if the X server runs as root.
X Alto vulnerabilidad
05/06/2026
[CVE-2026-50261] A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client …
A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via a second client connection while changing those counters. This may be used to crash the server, or for privilege escalation if the X server runs as root.
X Alto vulnerabilidad
05/06/2026
[CVE-2026-50256] A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between …
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum font name length can cause a stack buffer overflow during font alias resolution. The server allocates a 256 byte stack buffer but libXfont2's alias target name length is 1024 bytes. A font alias name between 257 and 1023 bytes causes the X server to c…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
X Alto vulnerabilidad
05/06/2026
[CVE-2026-50257] A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client…
A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a use-after-free function pointer call. An attacker would connect to the X server to set up a fence and await that fence, then a second X connection destroys the fence, causing the use-after-free. This may be used to crash the server, or for privileg…
S Alto vulnerabilidad
05/06/2026
[CVE-2026-21035] Improper input validation in Samsung Plus TV prior to version 1.0.28.6 allows remote attackers to ac…
Improper input validation in Samsung Plus TV prior to version 1.0.28.6 allows remote attackers to access sensitive information.
S Alto vulnerabilidad
05/06/2026
[CVE-2026-21037] Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to acc…
Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to access arbitrary URL and launch arbitrary activity with Samsung Members privilege.
S Alto vulnerabilidad
05/06/2026
[CVE-2026-21030] Improper access control in MediaTek Audio HAL prior to SMR Jun-2026 Release 1 allows local attackers…
Improper access control in MediaTek Audio HAL prior to SMR Jun-2026 Release 1 allows local attackers to trigger privileged functions.
S Alto vulnerabilidad
05/06/2026
[CVE-2026-21031] Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch a…
Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activity. User interaction is required for triggering this vulnerability.
S Alto vulnerabilidad
05/06/2026
[CVE-2026-21032] Improper export of android application components in SmartHomeWidgetReceiver of Samsung Assistant pr…
Improper export of android application components in SmartHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script.
S Alto vulnerabilidad
05/06/2026
[CVE-2026-21033] Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant …
Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script.
M Alto vulnerabilidad
05/06/2026
[CVE-2026-11332] A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency speci…
A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galax…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
05/06/2026
[CVE-2026-49777] Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider…
Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce allows Malicious Software Implanted. This issue affects Product Slider Pro for WooCommerce: from n/a before 3.5.4.
M Crítico vulnerabilidad
05/06/2026
[CVE-2026-6274] Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerabi…
Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electronics Industry and Trade Ltd. Co. Redline WR3200 allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Redline WR3200: from 7.1.3 before 7.1.8.
H Alto vulnerabilidad
05/06/2026
[CVE-2026-21837] HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Man…
HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API.  An attacker may execute arbitrary operating system commands, typically inheriting the privileges of the vulnerable application, which could possibly lead to a complete system takeover and data compromise.
M Alto vulnerabilidad
05/06/2026
[CVE-2026-50593] Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actio…
Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset is within the allowed slot-map range.
M Crítico vulnerabilidad
05/06/2026
[CVE-2026-7762] A heap-based buffer overflow vulnerability in the dot11ah.ko HaLow Wi-Fi kernel driver in Morse Micr…
A heap-based buffer overflow vulnerability in the dot11ah.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attacker within radio range to cause a Denial of Service (kernel panic) or potentially achieve Remote Code Execution via a crafted 802.11ah beacon or probe response frame containing a malformed S1G Capabilities Information El…