Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 59 min
Buscando: "Socket" — 76 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Hace 17 horas
[CVE-2026-75348] An out-of-bounds read vulnerability exists in EIPStackGroup OpENer v2.3 and master up to commit 76b9…
An out-of-bounds read vulnerability exists in EIPStackGroup OpENer v2.3 and master up to commit 76b95cf in the EtherNet/IP TCP SendRRData Common Packet Format parser. The issue occurs in CreateCommonPacketFormatStructure() when it parses recognized optional socket address information items of type 0x8000 or 0x8001 without first validating that the remaining CPF buffer contains the complete fixed s…
M Alto vulnerabilidad Nuevo
Hace 17 horas
[CVE-2026-107807] Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, Nginx UI accepts …
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, Nginx UI accepts the Node.Secret master credential through the node_secret query parameter in HTTP and WebSocket authentication paths instead of requiring the X-Node-Secret header. The credential can consequently appear in access logs, proxy logs, browser history, Referer headers, configuration URLs, and deployment …
M Crítico vulnerabilidad Nuevo
Hace 23 horas
[CVE-2026-107935] A path traversal vulnerability was found in gvproxy, the network forwarder provided by the gvisor-ta…
A path traversal vulnerability was found in gvproxy, the network forwarder provided by the gvisor-tap-vsock package. The unauthenticated /services/forwarder/expose endpoint does not validate the caller-supplied socket path, allowing an attacker to delete arbitrary files on the host system.
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-107909] A heap-based out-of-bounds write in the ws_read_frame function (src/bolt/ws.c) and the buffer_apply_…
A heap-based out-of-bounds write in the ws_read_frame function (src/bolt/ws.c) and the buffer_apply_mask function (src/bolt/buffer.c) in FalkorDB before 4.20.0 allows a remote unauthenticated attacker to cause a denial of service and possibly corrupt heap memory by sending a WebSocket frame with a 64-bit extended payload length to the Bolt port. The payload length is not bounded, and the only boun…
M Alto vulnerabilidad
Hace 1 día
Vulnerabilidad de denegación de servicio en hMailServer 6.3.0-6.3.5 en Linux por falta de timeouts
Progressive Robot hMailServer versiones 6.3.0 a 6.3.5 en Linux presenta un defecto alta donde falta configuración de timeouts en conexiones de red, permitiendo a atacantes remotos bloquear threads del servidor e interrumpir la entrega de correo saliente. Este problema afecta directamente a servidores de correo empresariales en México y Latinoamérica que utilizan estas versiones en infraestructura Linux, causando degradación severa del servicio de comunicaciones.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-107227] The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and async…
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.2.0 until 3.0.14, WebSocket permessage-deflate decompression is unbounded when compression is enabled. The inbound pipeline aggregates compressed frames before WebSocketClientCompressionHandler inflates them, so webSocketMaxFrameSize and webSocketMaxBufferSiz…
M Crítico vulnerabilidad
Hace 2 días
[CVE-2025-70516] The websocket handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce proper authenticati…
The websocket handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce proper authentication restrictions against sessionless users. The lack of restrictions grants anyone the ability to view any device resources such as operational logs or perform diagnostic requests.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
Hace 2 días
Vulnerabilidad crítica en LMCache: ejecución remota de código en modo distribuido
LMCache en modo distribuido expone un socket ZeroMQ ROUTER sin autenticación que permite a atacantes remotos ejecutar código arbitrario mediante deserialización insegura con pickle. La vulnerabilidad afecta infraestructuras de procesamiento de caché distribuido en centros de datos y servicios en la nube utilizados por empresas en LATAM. Un atacante no autenticado puede registrar procesos maliciosos y comprometer toda la arquitectura de caché compartida.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105223] maclof kubernetes-client 0.17.0 before 0.32.0 disables TLS certificate verification in parseKubeconf…
maclof kubernetes-client 0.17.0 before 0.32.0 disables TLS certificate verification in parseKubeconfig() and parseKubeconfigFile() when a kubeconfig lacks certificate-authority-data, ignoring insecure-skip-tls-verify. On-path attackers can impersonate the Kubernetes API server to capture Bearer tokens or Basic credentials and tamper with WebSocket or REST API traffic.
M Crítico vulnerabilidad
02/10/2026
[CVE-2026-95102] WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate chargin…
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system.
M Alto vulnerabilidad
02/10/2026
[CVE-2026-97212] The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows mu…
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend…
M Alto vulnerabilidad
02/10/2026
[CVE-2026-97363] The WebSocket Application Programming Interface lacks restrictions on the number of authentication r…
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks or brute-force attacks to gain unauthorized access.
M Crítico vulnerabilidad
02/10/2026
[CVE-2026-82041] UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMIncidentCommandWebsocke…
UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMIncidentCommandWebsocket.processCommand(), the handler mapped to the /command/{hostname} STOMP destination, where no role check or command allowlist is applied before forwarding supplied commands. Any authenticated user, regardless of role, can send arbitrary operating-system commands over gRPC to any connected agent, res…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-104057] Podgrab contains an unauthenticated denial-of-service vulnerability caused by unsynchronized concurr…
Podgrab contains an unauthenticated denial-of-service vulnerability caused by unsynchronized concurrent access to shared maps (activePlayers and allConnections) in its WebSocket handler, where Wshandler and HandleWebsocketMessages goroutines read and write these maps without a mutex. A remote attacker can open multiple WebSocket connections to the /ws endpoint and send messages in a loop to trigge…
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-103244] ground-station versions before 0.8.0 contain an authentication bypass vulnerability in the setup.res…
ground-station versions before 0.8.0 contain an authentication bypass vulnerability in the setup.restore command that allows unauthenticated attackers to execute arbitrary SQL during first-run setup mode. Attackers can invoke setup.restore via Socket.IO to plant admin users and forged session tokens, then authenticate as administrator without credentials for complete application takeover.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
30/09/2026
[CVE-2026-103472] restbed through 5.0.0 accepts WebSocket frames with declared payload lengths up to 2^63 bytes and bu…
restbed through 5.0.0 accepts WebSocket frames with declared payload lengths up to 2^63 bytes and buffers the payload without size limits in an unbounded stream buffer. Remote unauthenticated attackers can declare large frame sizes and stream payload data to exhaust server memory, causing denial of service through process crash.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102717] MQTT WebSocket setter ABI mismatch may disclose memory or cause a crash
MQTT WebSocket setter ABI mismatch may disclose memory or cause a crash
M Alto vulnerabilidad
30/09/2026
[CVE-2026-103055] AiSOC versions 7.5.0 before 12.0.0 use a hard-coded constant for JWT verification in the realtime We…
AiSOC versions 7.5.0 before 12.0.0 use a hard-coded constant for JWT verification in the realtime WebSocket and SSE service when the AISOC_REALTIME_JWT_SECRET environment variable is not set. Unauthenticated attackers can forge subscription tickets with arbitrary tenant identifiers to access cross-tenant live alerts, cases, agent events and graph updates through the realtime endpoints.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102558] A flaw was found in libsoup. When max-incoming-payload-size is unlimited (0), SoupWebsocketConnectio…
A flaw was found in libsoup. When max-incoming-payload-size is unlimited (0), SoupWebsocketConnection could grow its incoming GByteArray based on an attacker-controlled frame length until the length wrapped, causing a heap buffer overflow while reading frame data.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102559] A flaw was found in libsoup. When constructing a masked WebSocket client frame for a very large outg…
A flaw was found in libsoup. When constructing a masked WebSocket client frame for a very large outgoing payload, size values passed to GByteArray allocation APIs could be truncated while the masking routine still used the full length, causing a heap buffer overflow.