Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1023
Esta semana
RSS
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69876] Use after free in Windows DHCP Server allows an authorized attacker to execute code over an adjacent…
Use after free in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69725] Double free in Windows Hello allows an authorized attacker to elevate privileges locally.
Double free in Windows Hello allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69398] Concurrent execution using shared resource with improper synchronization ('race condition') in Windo…
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69337] Double free in Windows Registry allows an authorized attacker to elevate privileges over a network.
Double free in Windows Registry allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69322] Double free in Microsoft Windows Search Component allows an authorized attacker to elevate privilege…
Double free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69309] Double free in Windows Print Spooler Components allows an authorized attacker to elevate privileges …
Double free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69292] Double free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges lo…
Double free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges locally.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
08/09/2026
[CVE-2026-55007] Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a netw…
Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-33630] c-ares is an asynchronous resolver library. From ver 1.32.3 until 1.34.7, a use-after-free / double-…
c-ares is an asynchronous resolver library. From ver 1.32.3 until 1.34.7, a use-after-free / double-free in c-ares' query-completion handling. The same flaw — a query's callback being invoked while the query is still linked in the channel's internal lookup structures — is present at multiple points in the resend/finish path (timeout handling, response handling, and query dispatch). If the query, o…
M Alto vulnerabilidad
25/08/2026
[CVE-2026-18798] Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation f…
Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation fails for initial packet. Impact summary: Double free leads to heap corruption, which typically results in termination of QUIC server process, leading to Denial of Service. There is so far no evidence that this double free is exploitable for remote code execution, thus it is considered highly impro…
M Alto vulnerabilidad
22/08/2026
Vulnerabilidad alta en strongSwan anterior a 6.0.7: doble liberación de memoria en análisis de identidades EAP
strongSwan antes de la versión 6.0.7 presenta un defecto en el manejo de análisis y clonación de identidades EAP que genera una condición de doble liberación de memoria (double-free). Esto afecta principalmente a servidores VPN y de autenticación en infraestructuras corporativas de LATAM que utilizan este software de código abierto para IPsec. Un atacante remoto autenticado podría explotar esta vulnerabilidad para causar denegación de servicio o potencialmente ejecutar código arbitrario.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-65780] Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-62889] Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to ex…
Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-62766] Double free in Windows Kerberos allows an authorized attacker to elevate privileges locally.
Double free in Windows Kerberos allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-61366] Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges…
Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
07/08/2026
[CVE-2026-20338] A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker …
A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in zip files during scanning. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to …
M Alto vulnerabilidad
06/08/2026
[CVE-2026-43622] llama.cpp builds b1886 through b7445 contain a double free vulnerability in the LLaMA-Android JNI wr…
llama.cpp builds b1886 through b7445 contain a double free vulnerability in the LLaMA-Android JNI wrapper where new_1batch() allocates memory using malloc() while free_1batch() deallocates it using the C++ delete operator, causing heap metadata corruption. Attackers can trigger this memory management mismatch to cause denial of service through process crashes or potentially achieve arbitrary code …
M Alto vulnerabilidad
25/07/2026
[CVE-2026-66373] Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows …
Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.
M Alto vulnerabilidad
24/07/2026
[CVE-2026-66032] libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_op…
libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call retur…
M Alto vulnerabilidad
23/07/2026
[CVE-2026-43823] When initializing an RSA public key from DER or PEM bytes throws an error, the EVP_PKEY* is double-f…
When initializing an RSA public key from DER or PEM bytes throws an error, the EVP_PKEY* is double-freed: first in the catch block, then in the deinit. This can lead to a crash on future memory allocations. This double-free manifests when BoringSSL cannot decode the public key from the bytes provided. This vulnerability is addressed in swift-crypto version 4.5.1.