Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1002
Esta semana
RSS
M Alto vulnerabilidad
28/09/2026
[CVE-2026-86950] An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS…
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions o…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-102004] Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in memory corruption …
Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in memory corruption within the memory management subsystem. Fixed in Version 26.09
M Alto vulnerabilidad
28/09/2026
[CVE-2026-100888] A weakness has been identified in Trusted Domain Project OpenDKIM up to 2.11.0. This affects the fun…
A weakness has been identified in Trusted Domain Project OpenDKIM up to 2.11.0. This affects the function dkim_canon_selecthdrs of the file libopendkim/dkim-canon.c of the component DKIM Signature Header Selection. Executing a manipulation of the argument h can lead to out-of-bounds write. The attack can be executed remotely. The exploit has been made available to the public and could be used for …
M Crítico vulnerabilidad
27/09/2026
[CVE-2026-100740] A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_param…
A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_params of the file tunnel.c of the component L2TP Control Channel Parser. Performing a manipulation results in out-of-bounds write. The attack may be initiated remotely. The exploit is now public and may be used.
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100504] Ghidra versions through 12.1.4 contain a stack-based out-of-bounds write vulnerability in the decomp…
Ghidra versions through 12.1.4 contain a stack-based out-of-bounds write vulnerability in the decompiler's leftshift128 function when processing negative shift amounts from p-code. Attackers can craft malicious binaries with specific instruction sequences that trigger the overflow when decompiled, corrupting memory and potentially achieving code execution.
M Alto vulnerabilidad
24/09/2026
[CVE-2026-88390] An out-of-bounds write vulnerability in jslGetTokenValueAsString() in Espruino 2v29 (commit bffc6d0)…
An out-of-bounds write vulnerability in jslGetTokenValueAsString() in Espruino 2v29 (commit bffc6d0) allows crafted JavaScript input containing an overlong token to trigger a one-byte write beyond the JsLex.token buffer in RELEASE/NO_ASSERT builds. The out-of-bounds write corrupts the adjacent tokenValue pointer, resulting in memory corruption and potentially causing application crashes or denial …
M Alto vulnerabilidad
24/09/2026
[CVE-2026-13467] Out-of-bounds write vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperl…
Out-of-bounds write vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through socfpga_v2.14.0.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
24/09/2026
Vulnerabilidad alta en GIMP: ejecución de código remoto mediante archivos GIMPressionist
Se identificó una falla en el procesamiento de archivos de preajustes GIMPressionist en GIMP que permite escritura fuera de límites de memoria. Un atacante podría distribuir archivos maliciosos disfrazados de preajustes legítimos, logrando corrupción de memoria, bloqueos del sistema o ejecución de código arbitrario en equipos de diseñadores y desarrolladores en empresas LATAM. El CVSS 7.8 indica riesgo alto con exposición práctica.
M Crítico vulnerabilidad
24/09/2026
Vulnerabilidad crítica en D-Link DIR-825 permite escritura fuera de límites
Se identificó una vulnerabilidad de severidad crítica (CVSS 9.8) en el enrutador D-Link DIR-825 versión 3.00b32, específicamente en la función tunnel_set_params del componente rp-l2tp. Un atacante remoto puede explotar el parámetro peer_hostname para ejecutar escritura fuera de límites de memoria, comprometiendo la integridad del dispositivo. Esta vulnerabilidad afecta principalmente infraestructuras de pequeñas y medianas empresas en LATAM que utilizan este modelo como gateway de acceso.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-88832] BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a hea…
BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow when processing crafted filesystem images.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-91811] A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s PRC parser due to…
A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s PRC parser due to insufficient validation of vertex indices in triangular fan texture meshes. Successful exploitation could result in memory corruption and an application crash.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-91815] Foxit PDF Editor/Reader does not perform sufficient verification of the JPEG2000 image metadata in t…
Foxit PDF Editor/Reader does not perform sufficient verification of the JPEG2000 image metadata in the PDF file, which leads to out-of-bounds write in the heap buffer during decoding, potentially causing the program to crash and introducing the risk of arbitrary code execution.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-91802] A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s WebP image decodi…
A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s WebP image decoding due to improper handling of bitmap stride and target buffer formats. Successful exploitation could result in an application crash.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-91804] A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s rendering of Circ…
A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s rendering of Circle annotations with malformed Cloudy appearance streams in specially crafted PDF files. Insufficient validation of the appearance geometry can result in memory corruption and application crashes.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-91794] An out-of-bounds write vulnerability exists in the PDF rendering process of Foxit PDF Editor/Reader …
An out-of-bounds write vulnerability exists in the PDF rendering process of Foxit PDF Editor/Reader due to insufficient consistency and boundary validation when processing malformed color space data, which may cause the program to crash and potentially lead to remote code execution.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
23/09/2026
[CVE-2026-91789] Foxit PDF Editor/Reader’s U3D/GIF texture decoding path contained insufficient validation of image d…
Foxit PDF Editor/Reader’s U3D/GIF texture decoding path contained insufficient validation of image dimensions and related size information. Under certain conditions, this could lead to an incorrectly sized memory allocation and a subsequent out-of-bounds write during pixel processing, potentially resulting in remote code execution.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-18095] IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated atta…
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to execute arbitrary code due to a buffer overflow.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-17636] IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated atta…
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to execute arbitrary code due to improper validation of a specified quantity.
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-87121] lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow an attacker to gain …
lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution on the device.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-95862] A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability foun…
A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.