Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
10/08/2026
[CVE-2026-11810] The UpdateHub firmware-update agent's probe handler (z_impl_updatehub_probe() in subsys/mgmt/updateh…
The UpdateHub firmware-update agent's probe handler (z_impl_updatehub_probe() in subsys/mgmt/updatehub/updatehub.c) parses the JSON metadata returned by the update server into a fixed two-level nested-array struct. After parsing it validates only the outer array length (objects_len != 2) and then dereferences objects[1].objects[0].objects.sha256sum via strlen() without checking that the inner obje…
M Alto vulnerabilidad
10/08/2026
Vulnerabilidad alta de denegación de servicio en FastSchema v0.15.1 permite caída del servidor
Una vulnerabilidad de desreferencia de puntero NULL en FastSchema hasta la versión 0.15.1 permite que atacantes no autenticados derriben el servidor con una única solicitud HTTP. El defecto se encuentra en la función sendOTPEmail (pkg/auth/local.go) que procesa solicitudes de recuperación de contraseña sin validar correctamente el manejo de errores, causando un pánico fatal que interrumpe toda la aplicación. Afecta particularmente a empresas en LATAM que usan FastSchema en entornos de producción para autenticación de usuarios.
M Alto vulnerabilidad
07/08/2026
Vulnerabilidad alta en Klever-Go causa denegación de servicio en nodos blockchain
Klever-Go versiones 1.7.14 a 1.7.17 son vulnerables a un pánico por null-pointer desencadenado cuando una transacción protobuf omite el sub-mensaje RawData incrustado. Un atacante puede enviar transacciones malformadas a través de la red P2P de Klever-Go para causar caída inmediata de nodos validadores. Esto afecta principalmente a operadores de nodos blockchain, exchanges cripto y plataformas DeFi en México y LATAM que ejecuten estas versiones.
M Alto vulnerabilidad
07/08/2026
[CVE-2026-48097] NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a use…
NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 have a command execution vulnerability due to unsafe use of `shell=True` with commands that rely on executable resolution through the `PATH` environment variable. An attacker controlling the execution environment can place malicious executables such as sudo ea…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-70640] llama.cpp builds b1886 through b7445 contain a race condition use-after-free vulnerability in the LL…
llama.cpp builds b1886 through b7445 contain a race condition use-after-free vulnerability in the LLaMA-Android JNI wrapper where bench_1model() and free_1context() lack synchronization, allowing Thread A to operate on freed memory while Thread B concurrently frees the llama_context. Attackers can exploit this by performing heap spray with attacker-controlled data containing a fake vtable to hijac…
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-67870] In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation …
In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with an empty targetServerUri and a non-zero targetNodeId.serverIndex, causing the target node pointer to remain NULL while execution continues.
M Alto vulnerabilidad
01/08/2026
Vulnerabilidad alta de desreferencia nula en FreeRDP 3.28.x y anteriores
FreeRDP versiones anteriores a 3.29.0 contiene una vulnerabilidad de desreferencia de puntero nulo en el manejo de solicitudes de control de dispositivos smartcard. Un atacante puede enviar peticiones IRP malformadas con datos de estado de lector truncados para causar el bloqueo del proceso. Esta vulnerabilidad afecta servidores de acceso remoto y clientes RDP en infraestructuras de LATAM que dependen de autenticación por tarjeta inteligente.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
01/08/2026
[CVE-2026-67288] FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request d…
FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. When smartcard emulation is enabled, attackers can send crafted smartcard cache requests with NULL lookup-name pointers to trigger strlen() on a null pointer, causing client process…
M Alto vulnerabilidad
30/07/2026
[CVE-2026-18064] An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) ap…
An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a separate NULL pointer dereference reachable in versions through 7.0.1. An attacker who can trigger the affected command under specific conditions could cause the HS application to crash, resulting in a denial-of-service condition and processor reset.
M Alto vulnerabilidad
29/07/2026
[CVE-2026-58161] Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handli…
Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
M Alto vulnerabilidad
28/07/2026
[CVE-2026-67184] TinyWeb through 0.0.8 contains a null pointer dereference vulnerability that allows unauthenticated …
TinyWeb through 0.0.8 contains a null pointer dereference vulnerability that allows unauthenticated remote attackers to crash worker processes by sending a malformed HTTP request line with an invalid version string. The HttpParser::execute() function fails to allocate the Url object when version parsing fails, leaving the url pointer NULL, and buildResponse() subsequently dereferences this NULL po…
M Alto vulnerabilidad
28/07/2026
[CVE-2026-47427] GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the CompletionsHandler function i…
GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the CompletionsHandler function in pkg/github/server.go accesses params.Ref without first checking whether it is nil, so a completion/complete request with a missing or empty ref field triggers a nil pointer dereference and a Go runtime panic; because the crash occurs before any authentication or token validation, any unauthenticat…
A Alto vulnerabilidad
24/07/2026
[CVE-2026-45816] NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event. This req…
NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event. This requires disabled asserts (otherwise assert would trigger before NULL dereference) and bogus (or misbehaving) controller, thus severity is low. This issue affects Apache NimBLE: through 1.9.0. Users are recommended to upgrade to version 1.10.0, which fixes the issue.
M Alto vulnerabilidad
23/07/2026
[CVE-2026-50032] A NULL pointer dereference in the MMS Write Named Variable List handler, which may allow a network a…
A NULL pointer dereference in the MMS Write Named Variable List handler, which may allow a network adjacent attacker to crash the server by sending a WriteRequest with an empty listOfData field.
Z Alto vulnerabilidad
21/07/2026
[CVE-2026-10678] The MCTP-over-I2C+GPIO target binding in Zephyr (subsys/pmci/mctp/mctp_i2c_gpio_target.c) processes …
The MCTP-over-I2C+GPIO target binding in Zephyr (subsys/pmci/mctp/mctp_i2c_gpio_target.c) processes pseudo-register writes from an I2C bus master byte-by-byte in mctp_i2c_gpio_target_write_received() without validating the order or the receive buffer. In the affected versions the MCTP_I2C_GPIO_RX_MSG_ADDR (data) handler dereferences and writes through b->rx_pkt without checking that the receive bu…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-16353] Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153…
Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
L Crítico vulnerabilidad
19/07/2026
[CVE-2026-53399] In the Linux kernel, the following vulnerability has been resolved: nfsd: release layout stid on se…
In the Linux kernel, the following vulnerability has been resolved: nfsd: release layout stid on setlease failure nfs4_alloc_stid() publishes the new stid into cl->cl_stateids via idr_alloc_cyclic() under cl_lock before returning to nfsd4_alloc_layout_stateid(). When nfsd4_layout_setlease() then fails, the error path frees the layout stateid directly with kmem_cache_free() without ever calling i…
L Alto vulnerabilidad
19/07/2026
[CVE-2026-53391] In the Linux kernel, the following vulnerability has been resolved: NFSv4/pNFS: reject zero-length …
In the Linux kernel, the following vulnerability has been resolved: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr nfs4_decode_mp_ds_addr() decodes the r_netid and r_addr opaques of a netaddr4 from a GETDEVICEINFO multipath-DS body, then immediately calls strrchr(buf, '.') to locate the port separator. Both decodes use xdr_stream_decode_string_dup(), and the current code checks …
L Alto vulnerabilidad
19/07/2026
[CVE-2026-53392] In the Linux kernel, the following vulnerability has been resolved: NFSv4/flexfiles: reject zero fi…
In the Linux kernel, the following vulnerability has been resolved: NFSv4/flexfiles: reject zero filehandle version count ff_layout_alloc_lseg() decodes the filehandle-version array count from the flexfiles layout body. The value is used as the count for kzalloc_objs(), and the current code only rejects NULL. A zero count yields ZERO_SIZE_PTR, which can be stored in dss_info->fh_versions even t…
L Alto vulnerabilidad
19/07/2026
[CVE-2026-53383] In the Linux kernel, the following vulnerability has been resolved: ksmbd: reject non-VALID session…
In the Linux kernel, the following vulnerability has been resolved: ksmbd: reject non-VALID session in compound request branch smb2_check_user_session() takes a shortcut for any operation that is not the first in a COMPOUND request: it reuses work->sess (the session bound by the first operation) and validates only the SessionId, then returns "valid". It never re-checks work->sess->state == SMB2_…