Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1014
Esta semana
RSS
M Crítico vulnerabilidad
20/09/2026
Vulnerabilidad crítica de desbordamiento de búfer en Comfast CF-N1-S 2.6.0.1
Se ha identificado una vulnerabilidad crítica (CVSS 10.0) en los routers Comfast CF-N1-S versión 2.6.0.1 que afecta la interfaz web de gestión. Un desbordamiento de búfer en la función get_css_path_from_uri del archivo /cgi-bin/mbox-config permite a atacantes remotos ejecutar código arbitrario sin autenticación. La vulnerabilidad ha sido divulgada públicamente y explotada activamente.
M Alto vulnerabilidad
20/09/2026
[CVE-2026-93962] A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element …
A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP Diameter Receiver. Executing a manipulation can lead to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. Up…
M Crítico vulnerabilidad
19/09/2026
Vulnerabilidad crítica de desbordamiento de búfer en router Totolink A3002MU
Se ha descubierto una falla de seguridad crítica (CVSS 10.0) en el router Totolik A3002MU versión Hh-B20211125.1046 que permite desbordamiento de búfer remoto a través del parámetro submit-url en la función formWlWds. El exploit está disponible públicamente, aumentando significativamente el riesgo de compromiso en infraestructuras de pequeñas y medianas empresas en Latinoamérica que utilizan este dispositivo como gateway de red.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-93739] A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function form…
A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation of the argument submit-url can lead to buffer overflow. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-93740] A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formW…
A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-93738] A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSched…
A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boafrm/formSchedule. Performing a manipulation of the argument webpage results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93331] A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_par…
A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file src/ietf/rtp_depacketizer.c of the component RTP Depacketizer. Such manipulation of the argument size leads to out-of-bounds read. It is possible to launch the attack remotely. Upgrading to version abi-16.26 is able to resolve this issue. The name of the patch is 6bb0f64b4d1039c0…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
16/09/2026
[CVE-2026-20352] A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthe…
A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain RADIUS requests. An attacker could exploit this vulnerability by sending a crafted RADIUS request directly to an affected device. A successful ex…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92399] A vulnerability was determined in GPAC 26.07.0. This affects the function rmt_client_handle_ws_frame…
A vulnerability was determined in GPAC 26.07.0. This affects the function rmt_client_handle_ws_frame of the file src/utils/rmt_ws.c of the component WebSocket Handler. Executing a manipulation of the argument payload_size can lead to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version abi-16.26 …
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92178] pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This …
pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-19886] OriginLab Origin Viewer OGM File Parsing Memory Corruption Remote Code Execution Vulnerability. This…
OriginLab Origin Viewer OGM File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of O…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92054] Privilege escalation in the Memory component. This vulnerability was fixed in Firefox 156 and Firefo…
Privilege escalation in the Memory component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91087] A flaw has been found in GPAC up to f1219cde. This vulnerability affects the function gf_mo_get_od_i…
A flaw has been found in GPAC up to f1219cde. This vulnerability affects the function gf_mo_get_od_id of the file compositor/media_object.c of the component Compositor. Executing a manipulation can lead to use after free. The attack may be performed from remote. The exploit has been published and may be used. Upgrading to version abi-16.24 is able to resolve this issue. This patch is called e34f4b…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-91003] A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the …
A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the file /rzgl.asp of the component CGI Service. This manipulation of the argument redirct_url causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-91001] A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of t…
A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the component DDNS Configuration. Performing a manipulation of the argument serv/user/host/wild/mx/bmx/cust/ip results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
15/09/2026
[CVE-2026-90852] A vulnerability has been found in luben zstd-jni up to 1.5.7-13. This vulnerability affects the func…
A vulnerability has been found in luben zstd-jni up to 1.5.7-13. This vulnerability affects the function ZstdCompressCtx.loadDict of the file ZstdCompressCtx.java of the component Dictionary Sharing. Such manipulation leads to use after free. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.7-14 is able to resolve this issu…
M Alto vulnerabilidad
14/09/2026
Vulnerabilidad alta de Use After Free en Open5GS 2.7.x y anteriores
Se descubrió un fallo de seguridad (CVE-2026-90707, CVSS 8.3) en Open5GS que afecta la función amf_nnrf_try_old_amf_discovery_fallback, permitiendo ataques remotos de Use After Free mediante manipulación del parámetro discovery_option. Este componente es alta en infraestructuras 5G, poniendo en riesgo operadores de telecomunicaciones y proveedores de servicios móviles en LATAM que dependan de esta solución open source.
M Crítico vulnerabilidad
14/09/2026
Vulnerabilidad crítica en D-Link DIR-878 120B05 permite desbordamiento de búfer remoto
Se ha identificado un fallo de seguridad crítico (CVSS 9.9) en el enrutador D-Link DIR-878 versión 120B05 que afecta la función SetWan3Settings. Un atacante remoto puede explotar un desbordamiento de búfer en la pila manipulando los parámetros de DNS primario/secundario, comprometiendo completamente dispositivos expuestos en redes corporativas y pequeña empresa de México y LATAM.
M Crítico vulnerabilidad
14/09/2026
Vulnerabilidad crítica en router D-Link DIR-878 120B05 permite desbordamiento de pila remoto
Se detectó una vulnerabilidad crítica (CVSS 9.9) en el router D-Link DIR-878 versión 120B05 que afecta la función SetDynamicDNSIPv6Settings. Un atacante remoto puede explotar esta falla manipulando los parámetros IPv6Address/Hostname para provocar un desbordamiento de pila (stack-based buffer overflow), potencialmente logrando ejecución remota de código. Este router es ampliamente utilizado en pequeñas y medianas empresas (PyMES) en México y LATAM para conectividad WAN.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-90689] A security flaw has been discovered in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. Impacted is the fun…
A security flaw has been discovered in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. Impacted is the function formDelWebAuthWhiteUser. Performing a manipulation of the argument webAuthWhiteUserIndex results in stack-based buffer overflow. The attack can be initiated remotely.