Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 53 min
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69384] Null pointer dereference in Virtual Hard Disk (VHD) Miniport Driver allows an unauthorized attacker …
Null pointer dereference in Virtual Hard Disk (VHD) Miniport Driver allows an unauthorized attacker to deny service locally.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-18453] A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling…
A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op_shared_search allows an unauthenticated remote attacker to crash the LDAP server by sending a crafted sequence of search requests using the USE_ONE_BACKEND control, resulting in denial of service.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-80118] PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics …
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an unauthenticated physical memory disclosure in DirectIo64.sys, reachable by unprivileged local users through a single IOCTL with no caller-identity check. The handler writes a crash-dump-format (PAGEDU64) image of all physical memory to a caller-supplied file path in…
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85150] A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occ…
A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace placement around a parameter's terminator can cause an internal length calculation to underflow, leading to a crash of the process parsing the header. On an RTSP server this ca…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-78222] A vulnerability exists in NGINX JavaScript where a malformed HTTP response received by ngx.fetch() c…
A vulnerability exists in NGINX JavaScript where a malformed HTTP response received by ngx.fetch() can crash an NGINX worker when trusted JavaScript reads Response.statusText. Exploitation requires control or influence over the fetched HTTP response. Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system. There is no control plane exposure; th…
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad en MongoDB Connector for BI permite denegación de servicio en esquema
Un usuario de base de datos puede crear una vista que cause fallos en la rutina de muestreo de esquema del MongoDB Connector for BI, interrumpiendo la funcionalidad de actualización de esquema. Esta vulnerabilidad afecta directamente a empresas en LATAM que utilizan BI conectado a MongoDB para análisis de datos, impidiendo la sincronización correcta de metadatos. Con CVSS 7.7, representa un riesgo significativo para operaciones de inteligencia empresarial.
M Alto vulnerabilidad
27/08/2026
[CVE-2026-30056] A NULL pointer dereference in the AMF NGAP Dispatcher component of free5gc v4.0.1 allows attackers t…
A NULL pointer dereference in the AMF NGAP Dispatcher component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying crafted NGAP messages during the initialization of a new RAN connection.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
25/08/2026
[CVE-2026-24263] NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could …
NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause a NULL pointer dereference. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.
M Alto vulnerabilidad
25/08/2026
[CVE-2022-50998] Nokogiri before 1.13.9 (CRuby implementation using packaged libraries) bundles libxml2 v2.9.14, whic…
Nokogiri before 1.13.9 (CRuby implementation using packaged libraries) bundles libxml2 v2.9.14, which is affected by CVE-2022-40304 (data corruption / double-free from an entity reference cycle when entity content is allocated from a dict) and CVE-2022-40303 (integer overflows when parsing with XML_PARSE_HUGE). Nokogiri 1.13.9 upgrades the packaged libxml2 to v2.10.3 to address these issues. Proce…
M Alto vulnerabilidad
25/08/2026
[CVE-2023-54354] Nokogiri before 1.14.3 (CRuby implementation only, when using the packaged libxml2) bundles libxml2 …
Nokogiri before 1.14.3 (CRuby implementation only, when using the packaged libxml2) bundles libxml2 v2.10.3, which is vulnerable to NULL pointer dereferences in XML Schema processing (xmlSchemaFixupComplexType, CVE-2023-28484, and xmlSchemaCheckCOSSTDerivedOK). An attacker who supplies a crafted/malformed XML schema can cause libxml2 to dereference a NULL pointer and potentially segfault, resultin…
M Alto vulnerabilidad
25/08/2026
[CVE-2026-63076] Issue summary: OpenSSL CMP password based protection verification only checks whether the protection…
Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can contain a parameter of a different type, which is then dereferenced as an invalid pointer. Impact summary: A remote, unauthenticated attacker can crash an application acting as a CMP serve…
M Alto vulnerabilidad
25/08/2026
[CVE-2026-14457] Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and …
Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key (with no associated certificate) configured locally, a NULL pointer dereference may occur when the remote peer solicits raw public keys and also sends the typically omitted "signature_algorithms_cert" TLS extension. Impact summary: The impact is limited to a possible Denial of …
M Alto vulnerabilidad
24/08/2026
[CVE-2026-71922] Multiple DrayTek VigorSwitch models contain a pre-authentication null pointer dereference vulnerabil…
Multiple DrayTek VigorSwitch models contain a pre-authentication null pointer dereference vulnerability in the setget.cgi interface. The vulnerability is caused by missing validation when the pass field is absent. A remote attacker can trigger this vulnerability via a crafted request to crash the service and cause a denial of service.
M Alto vulnerabilidad
21/08/2026
Vulnerabilidad de referencia nula en kin-openapi afecta validación de solicitudes
kin-openapi, biblioteca Go para procesar archivos OpenAPI, presenta una vulnerabilidad (CVSS 7.5) en versiones 0.10.0 a 0.141.0 que permite un acceso a memoria nula cuando procesa campos escalares malformados en solicitudes multipart/form-data. Un atacante puede causar bloqueo de servicio contra aplicaciones que usan esta biblioteca para validación de APIs. Empresas en LATAM con servicios REST y microservicios basados en Go están en riesgo si implementan kin-openapi sin parchear.
M Alto vulnerabilidad
20/08/2026
[CVE-2026-17165] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a NULL pointer dereference.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
19/08/2026
[CVE-2026-76928] X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
M Alto vulnerabilidad
19/08/2026
[CVE-2026-16817] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a NULL pointer dereference.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-65681] Null pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny ser…
Null pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-59132] Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a ne…
Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-48438] CAI Content Credentials is affected by a NULL Pointer Dereference vulnerability that could result in…
CAI Content Credentials is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.