Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 41 min
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1009
Esta semana
RSS
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-16165] IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10,…
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to cause a denial of service due to a null pointer dereference.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-63686] A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.…
A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose conversion partially succeeds then fails. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-46729] NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener…
NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-47563] NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user c…
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could cause a NULL pointer dereference. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-92871] A NULL pointer dereference vulnerability exists in Pgpool-II, which may allow an unauthenticated att…
A NULL pointer dereference vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal termination of the watchdog process.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-19888] Missing validation of a mandatory attribute in the SCRAM client-final-message parser in PgBouncer th…
Missing validation of a mandatory attribute in the SCRAM client-final-message parser in PgBouncer through 1.25.2 allows an unauthenticated remote attacker to crash the process. A malformed message can make the parser report success while leaving a required value unset, which is then dereferenced as a NULL pointer. The crash occurs before any credential is verified, so no valid account is required.…
M Alto vulnerabilidad
23/09/2026
Vulnerabilidad alta de desreferencia NULL en ASR Crane/Falcon (módulo as_rrc) en Linux
Se identificó una vulnerabilidad de desreferencia de puntero NULL en ASR Crane y ASR Falcon para sistemas Linux, específicamente en el módulo as_rrc ubicado en 3g.mod/lib/src/urrsir.c. Esta falla permite manipulación de punteros que podría resultar en ejecución de código no autorizado o denegación de servicio en servidores de telecomunicaciones y infraestructura de red alta. El CVSS de 7.4 indica severidad alta que afecta directamente servicios de conectividad en empresas LATAM.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
21/09/2026
[CVE-2026-73547] Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36…
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's ext_authz filter assumes that a request contains a :path pseudoheader when applying query_parameters_to_set or query_parameters_to_remove from an authorization response. A path-less CONNECT request makes request_headers_->Path() return null, and Filter::onCom…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92626] Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. …
Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/dguardintegration/dguardVersion endpoint dereferences DGuard integration login state that may be unset, raising an unhandled null reference exception. The exception is thrown from an asynchronous method that returns void, so it is not observed by a caller and can terminate the iDSecure pr…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-77692] An attacker can cause `named` to abort by sending a crafted DNS-over-HTTPS request with a cryptograp…
An attacker can cause `named` to abort by sending a crafted DNS-over-HTTPS request with a cryptographically invalid SIG(0) record, and then closing the transport connection prematurely. This issue affects BIND 9 versions 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, and 9.20.9-S1 through 9.20.27-S1.
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-55209] resdata is software for reading and writing result files from the Eclipse reservoir simulator. Prior…
resdata is software for reading and writing result files from the Eclipse reservoir simulator. Prior to 6.2.9, resdata insufficiently validates numeric fields, grid dimensions, keyword sizes, and array indexes while parsing untrusted GRDECL files in lib/resdata/rd_kw_grdecl.cpp and lib/resdata/rd_grid.cpp. Malformed COORD, ZCORN, CORSNUM, ACTNUM, or MAPAXES data can reach rd_grid_alloc_GRDECL_kw__…
M Alto vulnerabilidad
13/09/2026
[CVE-2026-15891] The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mqtt_sn.c removes the …
The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mqtt_sn.c removes the gateway record after PINGREQ retries are exhausted. It invoked SYS_SLIST_PEEK_HEAD_CONTAINER(&client->gateways, gw, next) but discarded the result. That macro is a pure expression that does not assign to gw, so gw retained its NULL initializer regardless of the list contents. The code then derefere…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-78130] strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certifi…
strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-45747] Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M…
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.16, the Lua TLS certificate information helper could dereference NULL certificate fields when a Lua script requested certificate information for TLS traffic where some certificate fields were absent. Crafted TLS traffic processed by a deployment using affected …