Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
Buscando: "Gpac" — 7 resultados ✕ Limpiar búsqueda
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1003
Esta semana
RSS
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107302] msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the decoder rea…
msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the decoder reads the four-byte length of a map32 value before validating that the complete five-byte header is available. A truncated map32 header therefore causes a checked out-of-bounds buffer read and throws RangeError instead of IncompleteBufferError, which can unexpectedly terminate a request, stream, or wor…
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107300] msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming d…
msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder recursively invokes itself for each complete MessagePack value remaining in a chunk. A remote peer can send one chunk containing many small valid values, causing recursion proportional to the value count, exhausting the JavaScript call stack, and interrupting the process or stream. This issue…
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-93034] SGLang contains an arbitrary code execution vulnerability caused by the ZMQ message decoder uncondit…
SGLang contains an arbitrary code execution vulnerability caused by the ZMQ message decoder unconditionally deserializing PickleWrapper payloads via pickle.loads() in _maybe_unwrap_pickle without type allowlisting or authentication; this vulnerability persists via the msgpack path even when SGLANG_USE_PICKLE_IPC is disabled, and becomes remotely exploitable if data-parallel attention is enabled wi…
M Crítico vulnerabilidad
Hace 2 días
Vulnerabilidad crítica en LMCache: ejecución remota de código en modo distribuido
LMCache en modo distribuido expone un socket ZeroMQ ROUTER sin autenticación que permite a atacantes remotos ejecutar código arbitrario mediante deserialización insegura con pickle. La vulnerabilidad afecta infraestructuras de procesamiento de caché distribuido en centros de datos y servicios en la nube utilizados por empresas en LATAM. Un atacante no autenticado puede registrar procesos maliciosos y comprometer toda la arquitectura de caché compartida.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93331] A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_par…
A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file src/ietf/rtp_depacketizer.c of the component RTP Depacketizer. Such manipulation of the argument size leads to out-of-bounds read. It is possible to launch the attack remotely. Upgrading to version abi-16.26 is able to resolve this issue. The name of the patch is 6bb0f64b4d1039c0…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92399] A vulnerability was determined in GPAC 26.07.0. This affects the function rmt_client_handle_ws_frame…
A vulnerability was determined in GPAC 26.07.0. This affects the function rmt_client_handle_ws_frame of the file src/utils/rmt_ws.c of the component WebSocket Handler. Executing a manipulation of the argument payload_size can lead to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version abi-16.26 …
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91087] A flaw has been found in GPAC up to f1219cde. This vulnerability affects the function gf_mo_get_od_i…
A flaw has been found in GPAC up to f1219cde. This vulnerability affects the function gf_mo_get_od_id of the file compositor/media_object.c of the component Compositor. Executing a manipulation can lead to use after free. The attack may be performed from remote. The exploit has been published and may be used. Upgrading to version abi-16.24 is able to resolve this issue. This patch is called e34f4b…