Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1045
Esta semana
RSS
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-57545] Memory corruption when processing draw objects of incorrect type during graphics command list execut…
Memory corruption when processing draw objects of incorrect type during graphics command list execution.
M Alto vulnerabilidad
Hace 4 días
Vulnerabilidad alta en controlador i3c afecta validación de memoria del sistema
Se ha identificado una vulnerabilidad en el verificador de llamadas al sistema para i3c_do_ccc() en drivers/i3c/i3c_handlers.c que no valida correctamente los búferes de datos por destino en la estructura i3c_ccc_target_payload. Un atacante local podría explotar esta deficiencia para acceder o modificar memoria del kernel, afectando sistemas embebidos e IoT industriales comúnmente desplegados en infraestructura alta de LATAM.
M Alto vulnerabilidad
24/09/2026
[CVE-2026-58007] Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of…
Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through socfpga_v2.14.0.
M Alto vulnerabilidad
24/09/2026
[CVE-2026-58006] Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of…
Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through socfpga_v2.14.0.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-91795] Foxit PDF Editor/Reader's FileOpen plugin did not adequately validate certain encryption metadata in…
Foxit PDF Editor/Reader's FileOpen plugin did not adequately validate certain encryption metadata in specially crafted PDF files. This could leave an internal pointer in an invalid state, resulting in chained read and write access violations and potentially enabling arbitrary code execution.
M Alto vulnerabilidad
21/09/2026
[CVE-2026-94403] A weakness has been identified in ColorFul iGameCenter 1.0.3.4. This impacts the function sub_140001…
A weakness has been identified in ColorFul iGameCenter 1.0.3.4. This impacts the function sub_140001AF0 in the library ene.sys of the component IOCTL Handler. This manipulation causes untrusted pointer dereference. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did no…
M Alto vulnerabilidad
17/09/2026
[CVE-2025-59607] Memory Corruption when copying large input data exceeds normal allocation limits.
Memory Corruption when copying large input data exceeds normal allocation limits.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
08/09/2026
[CVE-2026-83498] Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an autho…
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-83939] Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate…
Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-80083] Untrusted pointer dereference in Windows Hyper-V allows an authorized attacker to execute code local…
Untrusted pointer dereference in Windows Hyper-V allows an authorized attacker to execute code locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-78444] Untrusted pointer dereference in Windows Failover Cluster allows an unauthorized attacker to execute…
Untrusted pointer dereference in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69900] Untrusted pointer dereference in Kernel Streaming WOW Thunk Service Driver allows an authorized atta…
Untrusted pointer dereference in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69874] Untrusted pointer dereference in Windows ALPC allows an authorized attacker to elevate privileges lo…
Untrusted pointer dereference in Windows ALPC allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69717] Untrusted pointer dereference in Windows Group Policy allows an authorized attacker to elevate privi…
Untrusted pointer dereference in Windows Group Policy allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69501] Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate…
Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69475] Untrusted pointer dereference in Windows Remote Desktop Services allows an authorized attacker to el…
Untrusted pointer dereference in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-67378] Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a net…
Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
20/08/2026
[CVE-2026-19442] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtua…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtual SCSI (vSCSI) initiator driver. Successful exploitation may result in denial of service, privilege escalation, or full compromise of the client LPAR kernel.
M Alto vulnerabilidad
20/08/2026
[CVE-2026-18840] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to improper validation of an attacker-controlled pointer.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-9771] The flash_copy() system call is verified by z_vrfy_flash_copy() in drivers/flash/flash_util.c. On bu…
The flash_copy() system call is verified by z_vrfy_flash_copy() in drivers/flash/flash_util.c. On builds with CONFIG_USERSPACE enabled, this handler is the kernel-side trust boundary for a user-mode caller. Prior to the fix it validated only the output buffer (K_SYSCALL_MEMORY_WRITE) and passed the two struct device * arguments, src_dev and dst_dev, directly into the implementation without any obj…