Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1002
Esta semana
RSS
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-87078] Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the output buffer on every rejecte…
Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the output buffer on every rejected label in decode_punycode. The XS backend allocates the scalar it returns before it validates the input, sizing the buffer at twice the input length. The scalar is released only on the success path, so each of the three croaks that reject a label leaves the scalar and its buffer allocated. Nothing…
M Alto vulnerabilidad
21/09/2026
[CVE-2026-94627] vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when co…
vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when concurrent child requests share a single transfer ID in prefill/decode disaggregated deployments. Attackers can trigger GPU memory exhaustion by submitting completion requests with multiple prompts, causing orphaned KV cache blocks to accumulate until process restart and eventually preventing legitima…
M Alto vulnerabilidad
21/09/2026
[CVE-2026-73550] Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36…
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy copies every decoded HTTP/2 Host header value before discarding it when :authority is already present. The discarded value bypasses saveHeader, so its bytes and count are not charged against request header limits. An unauthenticated client can use HPACK indexin…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-63446] Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M…
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, AppLayerParserSetTransactionInspectId() in src/app-layer-parser.c uses an inverted guard and marks only already-inspected transactions as inspected. On flows passed by a pass rule or pass-the-flow exception policy, detection is skipped, so completed transact…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-93436] vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests …
vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests in prefill/decode disaggregated deployments. Remote attackers can submit requests with max_tokens=0 to exhaust decode-worker memory without bound until the worker restarts.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-86040] libp2p is a JavaScript implementation of the libp2p networking stack. Prior to 11.0.26, @libp2p/floo…
libp2p is a JavaScript implementation of the libp2p networking stack. Prior to 11.0.26, @libp2p/floodsub accepts unauthenticated RPC frames on /floodsub/1.0.0 through PeerStreams.attachInboundStream in packages/floodsub/src/peer-streams.ts without protobuf element limits, then processRpc and processRpcSubOpt in packages/floodsub/src/floodsub.ts synchronously process the subscriptions array without…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-20222] A vulnerability in the EIGRP implementation in Cisco Secure Firewall Adaptive Security Appliance (AS…
A vulnerability in the EIGRP implementation in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper resource management when handling EIGRP update …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
16/09/2026
[CVE-2026-63128] RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's statef…
RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's stateful Streamable HTTP server in crates/rmcp/src/transport/streamable_http_server/tower.rs allows an unauthenticated client to send a well-formed JSON-RPC POST that is not an initialization request, or an initialization request with a mismatched protocol header, causing StreamableHttpService::handle_pos…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-18212] A flaw was found in the SAML Redirect Binding implementation of Keycloak, an open-source identity an…
A flaw was found in the SAML Redirect Binding implementation of Keycloak, an open-source identity and access management solution. The issue occurs because the custom DEFLATE compression and decompression helpers fail to release native zlib memory after use. An unauthenticated attacker can exploit this by sending repeated malformed SAML requests, leading to native memory exhaustion and a denial of …
M Alto vulnerabilidad
16/09/2026
[CVE-2026-81563] A BIND resolver encountering an SVCB/HTTPS AliasMode record referencing 14 or more SVCB/HTTPS Servic…
A BIND resolver encountering an SVCB/HTTPS AliasMode record referencing 14 or more SVCB/HTTPS ServiceMode records may fail to properly deallocate internal resources. If this happens repeatedly, resource exhaustion will eventually prevent the resolver from performing new recursive lookups. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.1…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-69208] Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, the DigestAuth server…
Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, the DigestAuth server middleware removes fresh nonces and stops eviction at the first stale nonce because its stale-nonce comparison is inverted. On an application that protects at least one route with DigestAuth, an unauthenticated attacker can repeatedly trigger authentication challenges, causing the persistent nonce …
M Alto vulnerabilidad
11/09/2026
Fuga de memoria en middleware compression de Node.js y Express (CVE-2026-87776)
El middleware compression para Node.js y Express en versiones anteriores a 1.8.2 presenta una vulnerabilidad que causa fuga de memoria nativa de zlib cuando clientes abortan conexiones durante respuestas comprimidas. Un atacante remoto puede agotar recursos del servidor mediante desconexiones repetidas y prematuras, impactando la disponibilidad de aplicaciones web y API REST en entornos de producción de LATAM.