Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,696
Total alertas
3097
Críticas
10327
Altas
8
Ransomware
1751
Esta semana
RSS
M Crítico vulnerabilidad
25/07/2026
[CVE-2026-64386] In the Linux kernel, the following vulnerability has been resolved: smb: client: fix query_info() r…
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix query_info() replay double-free A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_query_info_init() fails before the next send, cleanup retains the previous buffer type and frees that response again. Reset response bookkeeping before each attempt to prevent the stale…
M Crítico vulnerabilidad
25/07/2026
[CVE-2026-64355] In the Linux kernel, the following vulnerability has been resolved: bpf: Reject fragmented frames i…
In the Linux kernel, the following vulnerability has been resolved: bpf: Reject fragmented frames in devmap Devmap broadcast redirects clone the packet for all but the last destination. For native XDP, that clone path copies only the linear xdp_frame data, while fragmented frames keep skb_shared_info in tailroom outside the linear area. Cloning such a frame leaves XDP_FLAGS_HAS_FRAGS set but wi…
M Crítico vulnerabilidad
25/07/2026
[CVE-2026-64319] In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: validate reply mess…
In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: validate reply message payload bounds against transfer length nvmet_auth_reply() accesses the variable-length rval[] array using attacker-controlled hl (hash length) and dhvlen (DH value length) fields without verifying they fit within the allocated buffer of tl bytes. A malicious NVMe-oF initiator can craft a DHCHA…
M Crítico vulnerabilidad
25/07/2026
[CVE-2026-64320] In the Linux kernel, the following vulnerability has been resolved: nvmet: fix pre-auth out-of-boun…
In the Linux kernel, the following vulnerability has been resolved: nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page nvmet_execute_disc_get_log_page() validates only the dword alignment of the host-supplied Log Page Offset (lpo). The 64-bit offset is then added to a small kzalloc'd buffer that holds the discovery log page and the result is passed straight to nvmet_copy_to_s…
M Crítico vulnerabilidad
25/07/2026
[CVE-2026-64303] In the Linux kernel, the following vulnerability has been resolved: spi: fsl-lpspi: terminate the R…
In the Linux kernel, the following vulnerability has been resolved: spi: fsl-lpspi: terminate the RX channel on TX prepare failure path When dmaengine_prep_slave_sg() fails for the TX channel, the error path terminates the TX DMA channel but leaves the RX channel running. Since the RX channel was already submitted and issued prior to preparing the TX descriptor, returning -EINVAL causes the SPI …
M Crítico vulnerabilidad
25/07/2026
[CVE-2026-64268] In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: bound Read Response p…
In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: bound Read Response placement to the RREAD length In drivers/infiniband/sw/siw/siw_qp_rx.c, siw_proc_rresp() places each inbound Read Response DDP segment at sge->laddr + wqe->processed and then accumulates wqe->processed, but it never checks the running total against the sink buffer length on continuation segments. si…
M Crítico vulnerabilidad
25/07/2026
[CVE-2026-64269] In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Bound RDMA-Write…
In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg When the server answers an RTRS READ, rdma_write_sg() builds the source scatter/gather entry for the IB_WR_RDMA_WRITE that returns data to the peer. Its length is taken directly from the wire descriptor: plist->length = le32_to_cpu(id->rd_msg->desc[0].len);…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
25/07/2026
[CVE-2026-64257] In the Linux kernel, the following vulnerability has been resolved: smb: client: reject overlapping…
In the Linux kernel, the following vulnerability has been resolved: smb: client: reject overlapping data areas in SMB2 responses Commit 53b7c271f06b ("smb: client: restrict implied bcc[0] exemption to responses without data area") restricted the implied bcc[0] length exception to responses without a data area. However, the overlap handling in __smb2_calc_size() clears data_length, which can make…
M Crítico vulnerabilidad
25/07/2026
[CVE-2026-16766] Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via P…
Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options. Options are passed directly to the wkhtmltopdf command without sanitization. Any web application that passes user-controlled options such as the page_size, orientation or margins without validation allows shell command injection. Version 0.6.0 was released with an incomplete fi…
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-16280] An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncatio…
An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computations for PMRs larger than 4 GB. This can lead to incorrect GPU MMU mappings and may allow a non-privileged user to trigger access to unintended physical memory, resulting in memory corruption or information disclosure.
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-61884] The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perform server-side vali…
The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker can bypass the authentication check and establish a valid administrative session. This grants full access to device controls including power relay management, dev…
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-62835] Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over …
Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-48021] In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between ep…
In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controlled keys and obtain the session encryption keys. All inner HTTP traffic (patient consent decisions, medication data, document operations, authorization tokens, and entitlement queries) becomes readable and modifiable. The …
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-64232] In the Linux kernel, the following vulnerability has been resolved: block: recompute nr_integrity_s…
In the Linux kernel, the following vulnerability has been resolved: block: recompute nr_integrity_segments in blk_insert_cloned_request blk_insert_cloned_request() already recomputes nr_phys_segments against the bottom queue, because "the queue settings related to segment counting may differ from the original queue." The exact same reasoning applies to integrity segments: a stacked driver's unde…
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-64216] In the Linux kernel, the following vulnerability has been resolved: netfs: Fix potential UAF in net…
In the Linux kernel, the following vulnerability has been resolved: netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages() netfs_unlock_abandoned_read_pages(rreq) accesses the index of the folios it is wanting to unlock and compares that to rreq->no_unlock_folio so that it doesn't unlock a folio being read for netfs_perform_write() or netfs_write_begin(). However, given that netfs_unlo…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-58630] Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges o…
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-58586] Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp. Image::WebP does…
Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp. Image::WebP does not link to the system libwebp. Instead, it uses a bundled copy of libwebp 0.3.0 (released 2013-03-20). That version has multiple known vulnerabilities, including CVE-2023-4863. Any caller that decodes an untrusted WebP image reaches the bundled decoder. Because the library is compiled into the mo…
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-57106] Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privil…
Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-56163] Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unautho…
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-16634] TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99. The…
TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99. The tomlc99 library is no longer maintained, and has an uncontrolled recursion vulnerability publicly reported in the issue tracker. Any caller that passes untrusted TOML to from_toml risks a stack overflow from a deeply-nested document. TOML::XS version 0.06 or later uses the successor tomlc17 libra…