Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1045
Esta semana
RSS
M Alto vulnerabilidad
15/09/2026
[CVE-2026-11926] IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insuffi…
IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91941] Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrap…
Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrategy that allows untrusted clients to cause denial of service. Attackers can select the PDF scraping strategy in POST requests to download large remote PDFs without size or page limits, exhausting disk, CPU, and bandwidth on shared workers.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-84553] A resource exhaustion issue was addressed with improved input validation. This issue is fixed in mac…
A resource exhaustion issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A remote attacker may be able to cause a denial-of-service.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-54135] AirSane is a SANE frontend, and a scanner server that supports Apple's AirScan protocol. Versions pr…
AirSane is a SANE frontend, and a scanner server that supports Apple's AirScan protocol. Versions prior to 0.4.12 have a vulnerability in the custom HTTP server implementation of AirSane that allows a remote unauthenticated attacker to cause a Denial of Service (DoS) via memory exhaustion (OOM). In httpserver.cpp, the HttpServer::Request::content function reads the Content-Length header and direct…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-68497] jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGrego…
jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLDeserializers.Std._deserialize. These deserializers are registered by default with no opt-in, so a plain ObjectMapper or JsonMapper with no polymorphic typing and n…
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad de Negación de Servicio en Net-SNMP hasta 5.9.5.2 afecta monitoreo de infraestructura
Net-SNMP versión 5.9.5.2 y anteriores contiene una vulnerabilidad de denegación de servicio en el módulo SMUX que permite a atacantes remotos no autenticados bloquear indefinidamente el servicio snmpd mediante una conexión sin envío de datos. Afecta sistemas de monitoreo alta en centros de datos, telecomunicaciones y operaciones de TI en LATAM que dependen de SNMP para supervisión de dispositivos de red.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-87908] multiparty is a Node.js library for parsing multipart/form-data request bodies. In versions from 2.1…
multiparty is a Node.js library for parsing multipart/form-data request bodies. In versions from 2.1.0 up to but not including 4.3.1, the parser does not bound the amount of memory used while accumulating the headers of a single multipart part. An unauthenticated attacker can send a single request whose part carries a very large volume of header bytes, forcing the parser to buffer all of them and …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
10/09/2026
[CVE-2026-45765] Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M…
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, DNP3 reassembly could buffer data without sufficient parser-level bounds. Crafted DNP3 traffic may cause Suricata to consume excessive memory, potentially resulting in denial of service. Versions 7.0.16 and 8.0.5 contain a fix. As a workaround, d…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-45766] Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M…
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, certain NFS parser state structures were insufficiently bounded. Crafted NFS traffic may cause Suricata to consume excessive memory, potentially resulting in denial of service. Versions 7.0.16 and 8.0.5 contain a fix. As a workaround, disable NFS…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-45768] Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M…
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, LDAP transaction state could store an unbounded number of responses. Because LDAP can be processed over UDP, crafted traffic may cause Suricata to consume excessive memory, potentially resulting in denial of service. Version 8.0…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-45769] Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M…
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5,IKEv2 parser state could grow without bounds while storing client transforms. Repeated crafted UDP traffic may cause Suricata to consume excessive memory, potentially resulting in denial of service. Versions 7.0.16 and 8.0.5 fix the issue. Some wo…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-45759] Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M…
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, Suricata could repeatedly perform expensive parsing of large HTTP `Content-Disposition` headers during HTTP response body processing. Crafted HTTP traffic could cause excessive CPU usage and denial of service. Versions 7.0.16 and 8.0.5 contain a …
M Alto vulnerabilidad
10/09/2026
Vulnerabilidad alta en GeoVision GV-LPC2211 V1.14 permite agotamiento de recursos
La cámara de red GeoVision GV-LPC2211 versión 1.14 (260903) contiene una vulnerabilidad que permite a clientes no autenticados declarar longitudes de trama VLSVR ilimitadas, causando consumo excesivo de memoria, conexiones y recursos del servidor. Esto puede resultar en denegación de servicio en sistemas de vigilancia altas. Afecta especialmente a infraestructuras de seguridad física en Latinoamérica que dependen de estas cámaras para monitoreo perimetral y acceso.
M Alto vulnerabilidad
10/09/2026
Vulnerabilidad alta en GeoVision GV-LPC2211 V1.13 permite denegación de servicio en conexiones PTZ
GeoVision GV-LPC2211 versión 1.13 presenta una gestión inadecuada del estado de conexión PTZ (Pan-Tilt-Zoom) que permite a un atacante remoto no autenticado bloquear el bucle de aceptación y prevenir nuevas conexiones PTZ. Esta vulnerabilidad afecta sistemas de vigilancia altas en instalaciones de seguridad física en México y Latinoamérica, donde estas cámaras son ampliamente deployadas en bancos, hospitales y centros comerciales.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-22591] eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG…
eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.6.12, 2.14.6, 3.2.4, and 3.4.3, Fast DDS’s implementation of SQL‑based content filtering (DDSSQLFilter) allows any participant in a DDS domain to remotely crash other Fast DDS participants by sending a single crafted SEDP `DATA` submessage whose `PID_C…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
09/09/2026
[CVE-2026-86201] PocketMine-MP before 5.41.1 contains a denial of service vulnerability in LoginPacket processing whe…
PocketMine-MP before 5.41.1 contains a denial of service vulnerability in LoginPacket processing where large or complex structures in unknown clientData JWT properties cause excessive logging without sanitization. Attackers can send crafted LoginPackets with deeply nested or massive object structures to trigger out-of-memory conditions and crash the server.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-83968] Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges loca…
Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-72923] In Microsoft.OpenApi.YamlReader from 2.0.0-preview.11 until 2.12.0 and from 3.0.0 until 3.10.0, and …
In Microsoft.OpenApi.YamlReader from 2.0.0-preview.11 until 2.12.0 and from 3.0.0 until 3.10.0, and in Microsoft.OpenApi.Readers prior to 1.6.30, a small YAML OpenAPI document containing nested anchors and aliases can cause uncontrolled resource consumption when parsed through the public YAML reader APIs. YAML is parsed through SharpYaml, which represents aliases as shared nodes in a directed acyc…
M Alto vulnerabilidad
06/09/2026
Vulnerabilidad de denegación de servicio en h3 anteriores a 2.0.1-rc.18
h3 versiones anteriores a 2.0.1-rc.18 no validan correctamente el conteo de fragmentos en cookies controladas por el usuario, permitiendo que atacantes envíen headers de cookie malformados con conteos extremadamente grandes. Esto dispara un bucle de limpieza O(n²) que congela el proceso del servidor, causando indisponibilidad de servicios web altas en empresas LATAM. El impacto afecta principalmente a aplicaciones que procesan cookies en escala, como plataformas e-commerce y sistemas de sesión.
M Alto vulnerabilidad
04/09/2026
[CVE-2021-44320] Parrot AR.Drone version 1 and 2 does not employ a suitable mechanism to prevent denial-of-service (D…
Parrot AR.Drone version 1 and 2 does not employ a suitable mechanism to prevent denial-of-service (DoS) attacks. An attacker can harm the device availability (i.e., video streaming and control) by using tool to perform an IPv4 flood attack. Verified attacks includes SYN flooding and UDP flooding.