Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
14,390
Total alertas
3275
Críticas
10807
Altas
8
Ransomware
1049
Esta semana
RSS
M Alto vulnerabilidad
25/07/2026
[CVE-2026-64286] In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Clear __hyp_running…
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU flush_hyp_vcpu() copies the host vCPU context into the hyp's private vCPU on every run. ctxt_to_vcpu() expects a guest context to have a NULL __hyp_running_vcpu, which is only ever set on the host context, so that it resolves the vCPU via container_of(). While …
M Alto vulnerabilidad
25/07/2026
[CVE-2026-64287] In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Bound used_lrs when…
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU flush_hyp_vcpu() copies the host vGIC state into the hyp's private vCPU on every run. The vGIC list register save and restore use used_lrs as their loop bound and expect it to stay within the number of implemented list registers. While this is generally the case, flush_h…
M Alto vulnerabilidad
25/07/2026
[CVE-2026-64276] In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - bound t…
In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count rmi_f30_map_gpios() allocates gpioled_key_map with min(gpioled_count, TRACKSTICK_RANGE_END) == at most 6 entries, but rmi_f30_attention() iterates the full f30->gpioled_count (device query register, range 0..31) and dereferences gpioled_key_map[i], and input->key…
M Alto vulnerabilidad
25/07/2026
[CVE-2026-64277] In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - bound t…
In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count rmi_f3a_initialize() takes the GPIO count from the device query register (f3a->gpio_count = buf & RMI_F3A_GPIO_COUNT, range 0..127). rmi_f3a_map_gpios() then allocates gpio_key_map with min(gpio_count, TRACKSTICK_RANGE_END) == at most 6 entries, but rmi_f3a_attention…
M Alto vulnerabilidad
25/07/2026
[CVE-2026-64279] In the Linux kernel, the following vulnerability has been resolved: i2c: core: fix adapter deregist…
In the Linux kernel, the following vulnerability has been resolved: i2c: core: fix adapter deregistration race Adapters can be looked up by their id using i2c_get_adapter() which takes a reference to the embedded struct device. Remove the adapter from the IDR before tearing it down during deregistration (and on registration failure) to make sure its resources are not accessed after having been …
M Alto vulnerabilidad
25/07/2026
[CVE-2026-64280] In the Linux kernel, the following vulnerability has been resolved: fpga: dfl-afu: validate DMA map…
In the Linux kernel, the following vulnerability has been resolved: fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region() afu_ioctl_dma_map() accepts a 64-bit length from userspace via DFL_FPGA_PORT_DMA_MAP ioctl without an upper bound check. The value is passed to afu_dma_pin_pages() where npages is derived as length >> PAGE_SHIFT and passed to pin_user_pages_fast() which takes int…
M Alto vulnerabilidad
25/07/2026
[CVE-2026-64281] In the Linux kernel, the following vulnerability has been resolved: svcrdma: wake sq waiters when t…
In the Linux kernel, the following vulnerability has been resolved: svcrdma: wake sq waiters when the transport closes Threads parked in svc_rdma_sq_wait() on sc_sq_ticket_wait or sc_send_wait can hang indefinitely in TASK_UNINTERRUPTIBLE state across transport teardown, pinning svc_xprt references and blocking svc_rdma_free(). The close path sets XPT_CLOSE before invoking xpo_detach and both w…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
25/07/2026
[CVE-2026-64259] In the Linux kernel, the following vulnerability has been resolved: fuse-uring: make a fuse_req on …
In the Linux kernel, the following vulnerability has been resolved: fuse-uring: make a fuse_req on SQE commit only findable after memcpy Bad userspace might try to trick us and send commit SQEs request unique / commit-id of requests that are not even send to fuse-server (io_uring_cmd_done() not called) yet. fuse_uring_commit_fetch() ends the fuse request when the ring entry has a wrong state, b…
M Alto vulnerabilidad
25/07/2026
[CVE-2026-64260] In the Linux kernel, the following vulnerability has been resolved: fuse-uring: Avoid queue->stoppe…
In the Linux kernel, the following vulnerability has been resolved: fuse-uring: Avoid queue->stopped races and set/read that value under lock There are several readers of queue->stopped that check the value under lock, but fuse_uring_commit_fetch() did not and actually the value was not set under the lock in fuse_uring_abort_end_requests() either. Especially in fuse_uring_commit_fetch it is impo…
M Alto vulnerabilidad
25/07/2026
[CVE-2026-64261] In the Linux kernel, the following vulnerability has been resolved: fuse-uring: Avoid use-after-fre…
In the Linux kernel, the following vulnerability has been resolved: fuse-uring: Avoid use-after-free in fuse_uring_async_stop_queues fuse_uring_async_stop_queues() might run when the last reference on ring->queue_refs was already dropped. In order to avoid an early destruction a reference on struct fuse_conn is now taken before starting fuse_uring_async_stop_queues() and that reference is only …
M Alto vulnerabilidad
25/07/2026
[CVE-2026-64265] In the Linux kernel, the following vulnerability has been resolved: fuse: clear intr_entry in fuse_…
In the Linux kernel, the following vulnerability has been resolved: fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req When fuse_resend() moves a request from fpq->processing back to fiq->pending, it sets FR_PENDING and clears FR_SENT but does not remove the requests intr_entry from fiq->interrupts. If the request had FR_INTERRUPTED set from a prior signal, intr_entry remains dan…
M Alto vulnerabilidad
25/07/2026
[CVE-2026-64266] In the Linux kernel, the following vulnerability has been resolved: fuse: re-lock request before re…
In the Linux kernel, the following vulnerability has been resolved: fuse: re-lock request before returning from fuse_ref_folio() fuse_ref_folio() unlocks the request but does not re-lock it before returning. fuse_chan_abort() can end the request and the async end callback (eg fuse_writepage_free()) can free the args while the subsequent copy chain logic after fuse_ref_folio() accesses them, lead…
M Alto vulnerabilidad
25/07/2026
[CVE-2026-10818] The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, a…
The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_finalize function. This is due to the file type validation occurring after chunk metadata and file contents have already been written to disk, and the assembled file not being deleted upon validation failure. This makes it possible for unauthenticated…
M Alto vulnerabilidad
25/07/2026
[CVE-2026-66373] Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows …
Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.
M Alto vulnerabilidad
25/07/2026
[CVE-2026-66374] Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ …
Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
24/07/2026
[CVE-2026-61892] Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.
Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.
M Alto vulnerabilidad
24/07/2026
[CVE-2026-60134] Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.
Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.
M Alto vulnerabilidad
24/07/2026
[CVE-2025-71408] NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the…
NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations.py is invoked directly, the __main__ block passes command-line arguments directly to eval() as suffixes of BigramAssocMeasures without allowlist validation or san…
M Alto vulnerabilidad
24/07/2026
[CVE-2026-66040] FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in …
FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output…
M Alto vulnerabilidad
24/07/2026
[CVE-2026-66041] FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability…
FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/SUP subtitle file with mismatched frame dimensions. Attackers can provide a subtitle file whose second presentation has larger dimensions than its first, causing av_image_copy_plane() to copy data excee…