Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1038
Esta semana
RSS
M Alto vulnerabilidad
15/09/2026
[CVE-2026-12358] IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insuffi…
IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-53752] docx4j is an open source Java library for creating, editing, and saving OpenXML packages, including …
docx4j is an open source Java library for creating, editing, and saving OpenXML packages, including DOCX, PPTX, and XLSX files. Prior to 11.5.14, PropertyResolver and adjacent helpers recursively follow the WordprocessingML w:basedOn style inheritance chain without cycle detection. A well-formed DOCX containing mutually based styles causes unbounded recursion in PropertyResolver.fillPPrStack and r…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-22591] eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG…
eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.6.12, 2.14.6, 3.2.4, and 3.4.3, Fast DDS’s implementation of SQL‑based content filtering (DDSSQLFilter) allows any participant in a DDS domain to remotely crash other Fast DDS participants by sending a single crafted SEDP `DATA` submessage whose `PID_C…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69378] Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service …
Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-77465] toml-node is a TOML parser for Node.js and the browser. Prior to 4.2.0, toml.parse() uses a Peggy 5.…
toml-node is a TOML parser for Node.js and the browser. Prior to 4.2.0, toml.parse() uses a Peggy 5.1.0 generated recursive-descent parser in lib/parser.js whose peg$parsevalue, peg$parsearray, and peg$parseinline_table_entry functions recurse through nested arrays and inline tables without a depth limit. A remote unauthenticated application parsing an attacker-controlled TOML document containing …
M Alto vulnerabilidad
03/09/2026
Vulnerabilidad alta de recursión no controlada en Amazon Ion-C permite ataque de negación de servicio
Amazon Ion-C en versiones anteriores a 1.1.6 contiene un defecto de recursión no controlada que permite a actores remotos no autenticados enviar datos Ion malformados para agotar la pila de llamadas nativa y causar caída de aplicaciones. Afecta principalmente a infraestructuras de procesamiento de datos y servicios en la nube en LATAM que utilicen esta librería para serialización de datos. El impacto es negación de servicio con disponibilidad inmediata comprometida.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-81928] Net::DNS versions before 1.57 for Perl allow memory exhaustion via unbounded recursion in sig_data w…
Net::DNS versions before 1.57 for Perl allow memory exhaustion via unbounded recursion in sig_data when re-encoding a message with a misplaced TSIG record. sig_data signs a message by re-encoding it, and removes TSIG records only from the additional section. A TSIG decoded into the answer or authority section survives that step and is signed again, so encoding re-enters sig_data with no terminati…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
01/09/2026
[CVE-2026-52130] llama.cpp b5693 and before is vulnerable to Uncontrolled Recursion in common/json-schema-to-grammar.…
llama.cpp b5693 and before is vulnerable to Uncontrolled Recursion in common/json-schema-to-grammar.cpp, resulting in a denial of service.
M Alto vulnerabilidad
24/08/2026
[CVE-2026-76098] Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vul…
Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens from consecutive asterisk characters, and recursive rendering in HTMLRenderer.render_token() can exceed Python's recursion limit and raise RecursionError, allowing crafted Markdown to crash a parsing pr…
M Alto vulnerabilidad
23/08/2026
[CVE-2026-9769] justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial o…
justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During JustHTML() construction, TreeBuilder.finish() unconditionally calls _populate_selectedcontent(), which recursively traverses the DOM tree via _find_elements()/_find_element() without a depth bound. An attacker who can supply HTML for parsing can provide deeply nested elements (e.g.…
M Alto vulnerabilidad
22/08/2026
Vulnerabilidad de recursión no acotada en NLTK anterior a 3.9.4 permite denegación de servicio
NLTK versiones anteriores a 3.9.4 contienen una vulnerabilidad de recursión no acotada en JSONTaggedDecoder.decode_obj() que permite a atacantes causar denegación de servicio mediante estructuras JSON profundamente anidadas. Un payload malicioso que exceda el límite de recursión desencadena una excepción RecursionError no controlada que causa el fallo del proceso Python. Afecta aplicaciones de procesamiento de lenguaje natural en infraestructuras LATAM, incluyendo sistemas de análisis de datos y chatbots empresariales.
M Alto vulnerabilidad
21/08/2026
[CVE-2026-63462] Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the shared …
Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the shared OpenAPI validation error path in src/lib/error/bad-data-error.ts passes a raw request value from lodash.get to JSON.stringify in genericErrorMessage and fromOpenApiValidationErrors without guarding stack exhaustion. An unauthenticated attacker can send a roughly 10 KB JSON value nested thousands of …
M Alto vulnerabilidad
20/08/2026
[CVE-2026-54623] django CMS is an easy-to-use and developer-friendly enterprise content management system powered by …
django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, the move_plugin endpoint in cms/admin/placeholderadmin.py accepts an attacker-controlled plugin_parent value without rejecting a plugin’s own identifier or a descendant identifier. A staff user with plugin-change permission under CMS_PERMISSION can create a parent_id cycle in…
M Alto vulnerabilidad
16/08/2026
[CVE-2026-74792] Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vulnerability in nested …
Scriban before 7.0.0 (affected versions
M Alto vulnerabilidad
16/08/2026
[CVE-2026-74794] Scriban before 6.6.0 contains an infinite recursion vulnerability in object rendering when the Objec…
Scriban before 6.6.0 contains an infinite recursion vulnerability in object rendering when the ObjectRecursionLimit property defaults to unlimited. Attackers can supply circular reference objects to the template context, exhausting stack space and triggering an uncatchable StackOverflowException that terminates the hosting process.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
16/08/2026
[CVE-2026-74795] Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its recursive-descent parse…
Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its recursive-descent parser. The parser does not enforce a default expression depth limit (the ExpressionDepthLimit property in ParserOptions defaults to null/disabled), so an attacker who controls template input can supply a deeply nested template (e.g., thousands of nested parentheses or blocks) that exhausts thread stack …
M Alto vulnerabilidad
16/08/2026
[CVE-2026-74783] Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails t…
Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails to stop recursive descent parsing of deeply nested expressions. Attackers can supply templates with deeply nested parentheses, array initializers, object initializers, or unary operators to trigger an uncatchable StackOverflowException that immediately terminates the host process.
M Alto vulnerabilidad
16/08/2026
[CVE-2026-74787] Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin …
Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin function that lacks depth limits and circular reference detection. Attackers can craft templates with self-referencing objects to trigger unbounded recursion, causing a StackOverflowException that fatally terminates the hosting .NET process.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-17177] IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service du…
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to uncontrolled recursion.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-73566] node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's filesFilter …
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's filesFilter in src/list.ts uses the recursive mapHas helper to walk an archive entry path upward with path.dirname() and no segment cap when tar.t(...) or tar.x(...) receives a non-empty member-selection list. A crafted GNU L or PAX x long-path header with thousands of slash-separated segments reaches this.filt…