Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 8 min
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
996
Esta semana
RSS
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85447] MOOS-IvP pRealm through version 24.8.1 accepts unbounded REALMCAST_REQ subscriptions without validat…
MOOS-IvP pRealm through version 24.8.1 accepts unbounded REALMCAST_REQ subscriptions without validating duration or variable list limits. Attackers can register long-lived pipeways with many variables to cause pRealm to generate excessive output indefinitely, exhausting system resources.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85448] MOOS-IvP uFldShoreBroker through 24.8.1 fails to limit the number of claimed communities stored in p…
MOOS-IvP uFldShoreBroker through 24.8.1 fails to limit the number of claimed communities stored in parallel vectors within ShoreBroker::handleMailNodePing(). A single publisher can supply unbounded distinct community names to grow retained state and per-pass work without limit, causing memory exhaustion and performance degradation.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85449] MOOS-IvP pMarineViewer through 24.8.1 fails to limit the number of tracked node identities from NODE…
MOOS-IvP pMarineViewer through 24.8.1 fails to limit the number of tracked node identities from NODE_REPORT messages, allowing attackers to exhaust memory by supplying unbounded distinct node names. Attackers can publish crafted NODE_REPORT data to cause memory exhaustion and stall the operator display without authentication.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-84776] Unauthenticated Denial of Service Attack in MalCare Security <= 6.69 versions.
Unauthenticated Denial of Service Attack in MalCare Security
M Alto vulnerabilidad
03/09/2026
[CVE-2026-84778] Unauthenticated Denial of Service Attack in Migrate Guru – Site Migration &amp; Cloning <= 6.65 vers…
Unauthenticated Denial of Service Attack in Migrate Guru – Site Migration &amp; Cloning
M Alto vulnerabilidad
31/08/2026
[CVE-2026-19873] HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count …
HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the query string in Repeatable elements. When a Repeatable element has counter_name set, its process method reads the repeat count from the named query string parameter, checks only that it is a positive integer, and passes it to repeat, which deep-clones the element's child subtree once per i…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-81624] Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how …
Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow handles WebSocket connections. Specifically, certain configuration limits like message buffer sizes and session timeouts cannot be adjusted and default to being unlimited. This allows a remote attacker to send large amounts of data or maintain connections indefinitely, potentially crashing …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
28/08/2026
[CVE-2026-54788] dd-trace-rs provides Datadog application performance monitoring for Rust. From 0.1.0 until 0.3.3, da…
dd-trace-rs provides Datadog application performance monitoring for Rust. From 0.1.0 until 0.3.3, datadog-opentelemetry/src/propagation/tracecontext.rs parses the W3C tracestate header and collects every semicolon-separated key and value pair in the Datadog dd=... vendor entry into a HashMap without enforcing a pair count or entry size limit. Because tracecontext extraction is enabled by default, …
M Alto vulnerabilidad
28/08/2026
[CVE-2026-81285] Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization <= 4.2.0 versio…
Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization
M Alto vulnerabilidad
28/08/2026
[CVE-2026-37736] An issue in the JsonSanitizer.sanitize() component of OWASP json-sanitizer v1.2.3 allows attackers t…
An issue in the JsonSanitizer.sanitize() component of OWASP json-sanitizer v1.2.3 allows attackers to cause a Denial of Service (DoS) via a crafted input.
M Alto vulnerabilidad
27/08/2026
[CVE-2026-81699] openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in cra…
openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files, allowing attackers to trigger unbounded memory and CPU exhaustion during pre-authentication processing. Attackers can supply malicious files with excessive KDF parameters to exhaust system resources and crash or wedge the process before password verification occurs.
M Alto vulnerabilidad
27/08/2026
[CVE-2026-80212] An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resolv::DNS::Resource.get_class, Re…
An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resolv::DNS::Resource.get_class, Resolv::DNS::Resource::Generic.create, and Resolv::DNS::SvcParam::Generic.create generate a new class for each unknown DNS resource record (type, class) pair, or each unknown SvcParamKey, encountered while decoding a response. Each generated class was permanently registered both as a constant on Resou…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-5680] A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending speciall…
A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDeflateFunction.largerBuffer() method using exponential doubling, resulting in a Denial of Service (DoS) for the affected application.
M Alto vulnerabilidad
27/08/2026
[CVE-2026-30062] An issue in the NGAP handler of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) v…
An issue in the NGAP handler of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted NAS PDU.
M Alto vulnerabilidad
27/08/2026
[CVE-2026-30050] An issue in the ModifyAMFEventSubscriptionProcedure function (processor/event_exposure.go) of free5g…
An issue in the ModifyAMFEventSubscriptionProcedure function (processor/event_exposure.go) of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted PATCH request.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
27/08/2026
[CVE-2026-30057] An issue in the CreateUEContext handler component of free5gc v4.1.0 allows attackers to cause a Deni…
An issue in the CreateUEContext handler component of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted request.
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-47891] A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not corr…
A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
M Alto vulnerabilidad
27/08/2026
[CVE-2026-47885] The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMe…
The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -1. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28
M Alto vulnerabilidad
26/08/2026
[CVE-2026-61617] Wings is the server control plane for the Pterodactyl game-server management panel. In versions up t…
Wings is the server control plane for the Pterodactyl game-server management panel. In versions up to and including 1.13.2, the SFTP write path does not enforce a server's disk quota during a transfer, allowing a tenant with SFTP write access to a single server to exhaust the host node's physical disk and take down every server on it. Wings checks available space only once, as a boolean, when the …
M Alto vulnerabilidad
26/08/2026
[CVE-2026-73108] RustDesk versions before 1.4.7 contain an uncontrolled speculative memory allocation vulnerability i…
RustDesk versions before 1.4.7 contain an uncontrolled speculative memory allocation vulnerability in BytesCodec. Before authentication, the decoder trusts the payload length encoded in a four-byte frame header and reserves that amount before receiving the payload. A crafted header can request up to 1,073,741,823 bytes of capacity, allowing unauthenticated attackers to use concurrent TCP connectio…