Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1012
Esta semana
RSS
M Alto vulnerabilidad
30/09/2026
[CVE-2026-47501] NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user c…
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could cause an out-of-bounds write by supplying mismatched memory buffers during event buffer setup. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-92867] An out-of-bounds write vulnerability exists in Pgpool-II , which may allow an authenticated attacker…
An out-of-bounds write vulnerability exists in Pgpool-II , which may allow an authenticated attacker to cause abnormal process termination or arbitrary code execution.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-103111] PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usag…
PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data.
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-103110] Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation that …
Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation that allows a remote attacker to execute code remotely as an unprivileged user on a Pexip Infinity Conferencing Node.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-103109] Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in th…
Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger memory corruption or a software abort resulting in a denial of service. A crafted media stream may result in a controlled abort during processing, and has the potential to achieve memory corruption.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-74225] U-Boot before 2026.10-rc5 contains out-of-bounds memory access in dhcp6_parse_options() that fails t…
U-Boot before 2026.10-rc5 contains out-of-bounds memory access in dhcp6_parse_options() that fails to validate SERVERID and CLIENTID option lengths from DHCPv6 packets. Attackers on the local network can send crafted DHCPv6 ADVERTISE or REPLY packets during netboot to corrupt memory and crash the bootloader.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-71971] U-Boot before 2026.10-rc3 with CONFIG_IP_DEFRAG enabled contains an out-of-bounds write vulnerabilit…
U-Boot before 2026.10-rc3 with CONFIG_IP_DEFRAG enabled contains an out-of-bounds write vulnerability in the __net_defragment() function in net/net.c. Remote attackers can send a crafted IP fragment with non-zero offset and More-Fragments flag set during netboot to corrupt adjacent memory and crash the bootloader.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102301] Out of bounds write in GPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had…
Out of bounds write in GPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-95357] Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote at…
Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-95329] Out of bounds write in WebGL in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote …
Out of bounds write in WebGL in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-95331] Out of bounds write in ANGLE in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to po…
Out of bounds write in ANGLE in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Alto vulnerabilidad
29/09/2026
[CVE-2026-95322] Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote at…
Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
M Alto vulnerabilidad
29/09/2026
[CVE-2026-95304] Out of bounds write in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execu…
Out of bounds write in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
29/09/2026
[CVE-2026-72897] Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_C…
Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more provider signature algorithms than the context the connection was created from. Applications which never call SSL_set_SSL_CTX() are not affected. Impact summary: A remot…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-63209] compress provides various compression algorithms. Prior to version 1.18.7, a signed integer overflow…
compress provides various compression algorithms. Prior to version 1.18.7, a signed integer overflow vulnerability in s2.NewDict() allows an attacker to bypass repeat index validation by supplying a dictionary with a uvarint-encoded repeat value exceeding MaxInt64. When Dict.Encode() is subsequently called, the overflowed negative repeat value causes an out-of-bounds memory access via unsafe.Point…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102566] CTranslate2 before 4.8.1 contains a heap-based buffer overflow in the binary model loader that fails…
CTranslate2 before 4.8.1 contains a heap-based buffer overflow in the binary model loader that fails to validate payload length against allocated buffer size. Attackers can craft malicious model files with oversized payload lengths to write past heap allocation boundaries, causing crashes or arbitrary code execution.
M Alto vulnerabilidad
29/09/2026
Desbordamiento de búfer en RPM permite ejecución de código mediante paquetes maliciosos
Se identificó una vulnerabilidad alta en RPM que permite a atacantes ejecutar código arbitrario al procesar paquetes RPM manipulados con entradas de enlace simbólico especialmente crafteadas. La falla explota un desbordamiento de enteros en la función iterReadArchiveNext() que reduce la asignación de búfer a un byte, permitiendo escribir datos controlados más allá de los límites de memoria. Esta vulnerabilidad afecta directamente a servidores Linux en infraestructuras cloud, on-premises y repositorios de paquetes en empresas LATAM que utilizan sistemas basados en RHEL, CentOS, Fedora u otras distribuciones RPM.
M Alto vulnerabilidad
28/09/2026
[CVE-2026-18413] The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small…
The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small: the buffer_size field of struct adc_sequence in include/zephyr/drivers/adc.h documents that "the driver must ensure that samples are not written beyond the limit and it must return an error if the buffer turns out to be not large enough". The NXP MCUX LPADC driver did not honour that contract. mcu…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-18414] The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small…
The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small: the buffer_size field of struct adc_sequence in include/zephyr/drivers/adc.h documents that "the driver must ensure that samples are not written beyond the limit and it must return an error if the buffer turns out to be not large enough". The ADI MAX32 driver did not honour that contract. start_re…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-16513] The userspace verifier z_vrfy_rtio_sqe_copy_in_get_handles() in subsys/rtio/rtio_syscalls.c (subsys/…
The userspace verifier z_vrfy_rtio_sqe_copy_in_get_handles() in subsys/rtio/rtio_syscalls.c (subsys/rtio/rtio_handlers.c before v4.3.0) validated the RTIO object handle and the sqes input array, but not the handle out-parameter. On the first loop iteration it executed *handle = sqe, storing the kernel address of the newly acquired submission-queue entry through a pointer taken verbatim from user m…