Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1003
Esta semana
RSS
M Alto vulnerabilidad
Hace 6 días
Vulnerabilidad de validación de entrada en Kirki permite eludir controles de acceso
Una vulnerabilidad de validación impropia en Themeum Kirki (versiones hasta 6.3.1) permite a usuarios no autorizados acceder a funcionalidades que deberían estar restringidas por listas de control de acceso (ACLs). Afecta sitios WordPress en México y Latinoamérica que utilizan este framework de personalización de temas. El CVSS 8.2 refleja riesgo alto para integridad y disponibilidad.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-103484] IVFFlat index build in pgvector before 0.8.7 allows a database user to write data out-of-bounds, whi…
IVFFlat index build in pgvector before 0.8.7 allows a database user to write data out-of-bounds, which can lead to arbitrary code execution.
M Alto vulnerabilidad
24/09/2026
[CVE-2026-97057] redis-parser through 3.0.0 fails to validate the multi-bulk length value in RESP protocol parsing, a…
redis-parser through 3.0.0 fails to validate the multi-bulk length value in RESP protocol parsing, allowing attackers to trigger an uncaught RangeError by supplying an excessively large declared length. A malicious or compromised Redis endpoint can deliver a crafted RESP header with a length above 2^32-1 to crash the Node.js client process.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-94450] Improper validation of the Destination Connection ID length in s2n-quic 1.88.0 and earlier may allow…
Improper validation of the Destination Connection ID length in s2n-quic 1.88.0 and earlier may allow an unauthenticated remote user to cause a denial of service by shutting down a server endpoint via a single crafted UDP datagram. Only server endpoints specifically configured to send Retry packets are affected. To remediate this issue, users should upgrade to version v1.89.0 or later.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-93345] MikroTik RouterOS before 7.25beta4 contains an improper input validation vulnerability in the labell…
MikroTik RouterOS before 7.25beta4 contains an improper input validation vulnerability in the labelled-VPN NLRI iterators of the routing service that allows an unauthenticated on-path attacker to crash the BGP service by sending a malformed MP_REACH_NLRI UPDATE message with a prefix-length value below the minimum valid for a labelled-VPN NLRI, which passes validation while describing a route with …
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93749] source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source ma…
source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attackers to specify arbitrary numeric values. Attackers can supply extremely large offset line values that cause synchronous event loop blocking for extended periods, preventing the service from handling other requests.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-50285] Pomerium is an identity and context-aware access proxy. Prior to 0.32.8, decodeQueryStringV2 in pkg/…
Pomerium is an identity and context-aware access proxy. Prior to 0.32.8, decodeQueryStringV2 in pkg/hpke/url.go performs zstd decompression of attacker-controlled data without an output-memory limit when DecryptURLValues processes HPKE V2 values for Stateless.Callback in internal/authenticateflow/stateless.go. In hosted or stateless authentication deployments, an unauthenticated attacker can obtai…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
15/09/2026
[CVE-2026-69210] Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, WebSocket FrameTransc…
Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, WebSocket FrameTranscoder.bodyLength rejects extended payload lengths above Integer.MAX_VALUE but permits negative 64-bit lengths. A remote client that completes a WebSocket handshake through an Ember server can send such a frame, causing the decoder to return an empty frame without advancing its input. The decode loop …
M Alto vulnerabilidad
14/09/2026
[CVE-2026-76442] As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Em…
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76442 are related to…
M Alto vulnerabilidad
10/09/2026
Vulnerabilidad de denegación de servicio en t-digest 3.1-3.3 (CVE-2026-87962)
t-digest versiones 3.1 a 3.3 contienen una vulnerabilidad de denegación de servicio en MergingDigest.fromBytes que no valida campos de longitud y capacidad en datos serializados. Atacantes pueden enviar digests serializados manipulados para provocar excepciones ArrayIndexOutOfBoundsException o NegativeArraySizeException, abortando el hilo de procesamiento. Afecta aplicaciones que usan t-digest para compresión de datos o análisis de distribuciones en sistemas altas.