Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1003
Esta semana
RSS
M Alto vulnerabilidad
12/09/2026
[CVE-2026-90556] Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing save…
Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers can craft malicious savegame files that write past the entries array into adjacent heap-allocated struct fields, potentially corrupting memory when a user or server operator loads the file.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad alta en libde265: desbordamiento de enteros en códecs H.265
libde265, biblioteca de código abierto para decodificación de vídeo H.265 (HEVC), contiene un desbordamiento de enteros en versiones anteriores a 1.1.1 que permite a atacantes mediante flujos HEVC manipulados provocar lectura fuera de límites en memoria heap, exponiendo datos sensibles o causando caída del servicio. Afecta servidores multimedia, plataformas de streaming y sistemas de videoconferencia en empresas LATAM que procesan vídeo con esta biblioteca.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-79393] A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in th…
A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote unauthenticated attackers to cause a denial of service or potentially execute arbitrary code via a crafted SOAP request containing a wsa5:Action string exceeding 128 bytes.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-42807] A heap-based buffer overflow vulnerability in the PC bridge protocol decoder of BoschSensortec COINE…
A heap-based buffer overflow vulnerability in the PC bridge protocol decoder of BoschSensortec COINES_SDK (versions 2.10 through 2.12.2) allows attackers to cause a denial of service (process crash) or potentially execute arbitrary code. The bridge decoder ({{bridge_decoder.c}}) trusts the packet length field provided by the external device and forwards it to the host response queue ({{mqueue_…
M Crítico vulnerabilidad
09/09/2026
[CVE-2026-85103] A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote a…
A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.
G Crítico vulnerabilidad
09/09/2026
[CVE-2026-87654] Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote atta…
Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
09/09/2026
[CVE-2026-87579] Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execu…
Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
G Crítico vulnerabilidad
09/09/2026
[CVE-2026-87527] Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execut…
Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
G Alto vulnerabilidad
09/09/2026
[CVE-2026-87430] Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to poten…
Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
M Alto vulnerabilidad
09/09/2026
[CVE-2026-53938] OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). Prior…
OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). Prior to version 0.6.2.5, cjose's JWE decryption path for the AES Key Wrap key-management algorithms (`alg` = `A128KW`, `A192KW`, `A256KW`) does not validate the length of the attacker-supplied `encrypted_key` (JWE Encrypted Key) before unwrapping it into a fixed-size, heap-allocated Content Encryption K…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-81992] Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitr…
Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-82006] Photoshop Desktop is affected by a Heap-based Buffer Overflow vulnerability that could result in arb…
Photoshop Desktop is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86716] A vulnerability was determined in Cesanta mJS up to 1.26. Affected is the function skip_spaces_and_c…
A vulnerability was determined in Cesanta mJS up to 1.26. Affected is the function skip_spaces_and_comments of the file src/mjs_tok.c. Executing a manipulation can lead to heap-based buffer overflow. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-55294] In ihevcd_get_tu_data_size of ihevcd_utils.c, there is a possible out of bounds write due to a heap …
In ihevcd_get_tu_data_size of ihevcd_utils.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-49921] In multiple locations, there is a possible memory safety issue due to a heap buffer overflow. This c…
In multiple locations, there is a possible memory safety issue due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
08/09/2026
[CVE-2026-49932] In parseParts of PduParser.java, there is a possible out of bounds read due to a heap buffer overflo…
In parseParts of PduParser.java, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-85880] Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges local…
Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-85877] Heap-based buffer overflow in Windows Print Spooler Components allows an unauthorized attacker to ex…
Heap-based buffer overflow in Windows Print Spooler Components allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-83995] Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges local…
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-83996] Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privi…
Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.