Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
14,575
Total alertas
3310
Críticas
10878
Altas
8
Ransomware
1137
Esta semana
RSS
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-64216] In the Linux kernel, the following vulnerability has been resolved: netfs: Fix potential UAF in net…
In the Linux kernel, the following vulnerability has been resolved: netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages() netfs_unlock_abandoned_read_pages(rreq) accesses the index of the folios it is wanting to unlock and compares that to rreq->no_unlock_folio so that it doesn't unlock a folio being read for netfs_perform_write() or netfs_write_begin(). However, given that netfs_unlo…
M Alto vulnerabilidad
24/07/2026
[CVE-2026-64217] In the Linux kernel, the following vulnerability has been resolved: netfs: Fix overrun check in net…
In the Linux kernel, the following vulnerability has been resolved: netfs: Fix overrun check in netfs_extract_user_iter() Fix netfs_extract_user_iter() so that if iov_iter_extract_pages() overfills pages[], then those pages don't get included in the iterator constructed at the end of the function. If there was an overfill, memory corruption has already happened.
M Alto vulnerabilidad
24/07/2026
[CVE-2026-64218] In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: fix report_wor…
In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: fix report_work leak on backbone_gw purge batadv_bla_purge_backbone_gw() removes stale backbone gateway entries, but fails to properly handle their associated report_work: - If report_work is running, the purge must wait for it to finish before freeing the backbone_gw, otherwise the worker may access freed me…
M Alto vulnerabilidad
24/07/2026
[CVE-2026-64219] In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Validate paylo…
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async [Why&How] dc_process_dmub_aux_transfer_async() copies payload->length bytes into a 16-byte stack buffer (dpaux.data[16]) guarded only by an ASSERT(), which is a no-op in release builds. If a caller ever passes length > 16 this results i…
M Alto vulnerabilidad
24/07/2026
[CVE-2026-64221] In the Linux kernel, the following vulnerability has been resolved: spi: ti-qspi: fix use-after-fre…
In the Linux kernel, the following vulnerability has been resolved: spi: ti-qspi: fix use-after-free after DMA setup failure The driver falls back to PIO mode if DMA setup fails during probe. Make sure to clear the DMA channel pointer also if buffer allocation fails to avoid passing a pointer to the released channel to the DMA engine (or trying to free the channel a second time on late probe er…
M Alto vulnerabilidad
24/07/2026
[CVE-2026-64208] In the Linux kernel, the following vulnerability has been resolved: crypto/krb5, rxrpc: Fix lack of…
In the Linux kernel, the following vulnerability has been resolved: crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks Change the krb5 crypto library to provide facilities to precheck the length of the message about to be decrypted or verified. Fix AF_RXRPC to make use of this to validate DATA packets secured with RxGK.
M Alto vulnerabilidad
24/07/2026
[CVE-2026-64210] In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: xsk: Fix unlocked wr…
In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: xsk: Fix unlocked writing to ICOSQ During napi poll, when the affinity changes and there's still XSK work to be done, we trigger an ICOSQ interrupt on the new CPU. However, this triggering on the ICOSQ is done unprotected. There are 2 such races: A) mlx5e_trigger_irq() is called while mlx5e_xsk_alloc_rx_mpwqe() is r…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
24/07/2026
[CVE-2026-8789] The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to…
The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the `ea_delete_multiple_connections` AJAX action in all versions up to, and including, 3.12.27. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary connection records from the `…
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-58630] Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges o…
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-58586] Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp. Image::WebP does…
Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp. Image::WebP does not link to the system libwebp. Instead, it uses a bundled copy of libwebp 0.3.0 (released 2013-03-20). That version has multiple known vulnerabilities, including CVE-2023-4863. Any caller that decodes an untrusted WebP image reaches the bundled decoder. Because the library is compiled into the mo…
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-57106] Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privil…
Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-56163] Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unautho…
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
D Alto vulnerabilidad
24/07/2026
[CVE-2026-16801] Improper control of generation of code ('Code Injection') in the variables feature in Devolutions Po…
Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with variable write permission to execute arbitrary PowerShell code via a crafted variable value that is not properly escaped when written to the variables configuration file.
D Alto vulnerabilidad
24/07/2026
[CVE-2026-16800] Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions Pow…
Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with schedule creation permission to execute arbitrary PowerShell code via crafted schedule parameter names concatenated into a script invocation.
M Alto vulnerabilidad
24/07/2026
[CVE-2026-9765] Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue. …
Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue. Access Controls are “Broken” when a user can access resources they are not authorized to access. An attacker can bypass any access control mechanisms in a web application, and gain unauthorized access to resources that are not available with their permissions. Broken access control can allow attac…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
A Alto vulnerabilidad
24/07/2026
[CVE-2026-66142] Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or …
Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to a denial of service attack when parsing policies due to runtime memory exhaustion. Users are recommended to upgrade to version 3.2.3, which fixes this issue.
A Alto vulnerabilidad
24/07/2026
[CVE-2026-66143] It is possible to bypass the maximum number of normalized policy alternatives that was introduced in…
It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies, which may lead to a denial of service attack via resource consumption. Users are recommended to upgrade to version 3.2.3, which fixes this issue.
A Alto vulnerabilidad
24/07/2026
[CVE-2026-66144] Although remote policy references are not retrieved during policy normalization, if they are manuall…
Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API it can cause a denial of service attack if a huge policy is retrieved. Users are recommended to upgrade to version 3.2.3, which fixes this issue by imposing a default maximum size on data read from remote policy references.
A Alto vulnerabilidad
24/07/2026
[CVE-2026-45813] Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS serv…
Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service. Improper validation when parsing BASS service  "Add Source" and "Modify Source" operation PDU could results in stack buffer overflow or arbitrary out-of-bound read. This can be triggered by nearby devices over Bluetooth connection, however pairing is required prior to accessing BASS service, …
A Alto vulnerabilidad
24/07/2026
[CVE-2026-45815] Reachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read Multiple Variable R…
Reachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_READ_MULT_VAR_RSP) may trigger assert in ATT parser. Severity is medium as this requires DUT to first send ATT Read Multiple Variable Request. This issue affects Apache NimBLE: through 1.9.0. Users are recommended to upgrade to version 1.10.0, which fixes the issue.