Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1810
Esta semana
RSS
M Alto vulnerabilidad
14/07/2026
[CVE-2026-49175] Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locall…
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-49178] Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to exec…
Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-49164] Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to ex…
Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-48564] Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over…
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-42975] Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execu…
Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-42990] Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code…
Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
12/07/2026
[CVE-2026-15506] A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. The affected elemen…
A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. The affected element is an unknown function in the library saappctl.sys of the component Driver. Such manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. Upgrading to version 10.10.0 is sufficient to fix this issue. You shou…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
F Crítico vulnerabilidad
10/07/2026
[CVE-2026-57156] FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0 on 32-bit builds, F…
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0 on 32-bit builds, FreeRDP clients contain an integer overflow in update_read_delta_points in libfreerdp/core/orders.c when multiplying an attacker-controlled point count by sizeof(DELTA_POINT), allowing a malicious RDP peer to allocate an undersized heap buffer and then write beyond it during initialization. This issu…
G Alto vulnerabilidad
08/07/2026
[CVE-2026-15123] Inappropriate implementation in DOM in Google Chrome prior to 150.0.7871.115 allowed a remote attack…
Inappropriate implementation in DOM in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
X Alto vulnerabilidad
08/07/2026
[CVE-2026-56002] A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  a…
A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers authenticated as X client to execute code within the X server.
X Alto vulnerabilidad
08/07/2026
[CVE-2026-56003] A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in…
A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfont2 before 2.0.8 could be used by attackers using authenticated X clients to execute code within the X server.
X Alto vulnerabilidad
08/07/2026
[CVE-2026-56001] A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit s…
A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by attackers able to access the X Server to execute code within the X server cont
X Alto vulnerabilidad
08/07/2026
[CVE-2026-55999] Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21…
Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks.
M Alto vulnerabilidad
07/07/2026
[CVE-2026-11610] A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). A…
A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte heap receive buffer without a bounds check in sasl_io_recv() in sasl_io.c. This allows up to approximately 2 megabytes o…
M Alto vulnerabilidad
03/07/2026
[CVE-2026-56645] Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to exe…
Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
03/07/2026
[CVE-2026-58379] A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulner…
A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulnerability allows a remote attacker to cause arbitrary code execution or a denial of service (DoS) by tricking a user into opening a specially crafted PSP image file. The vulnerability occurs because the software incorrectly calculates buffer sizes when processing low bit-depth images, leading to an ov…
G Alto vulnerabilidad
01/07/2026
[CVE-2026-14427] Heap buffer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who h…
Heap buffer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
G Alto vulnerabilidad
01/07/2026
[CVE-2026-14415] Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker…
Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)
G Alto vulnerabilidad
01/07/2026
[CVE-2026-14385] Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attack…
Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
30/06/2026
[CVE-2026-13884] Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a local attacker to e…
Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a local attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Medium)