Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 40 min
Buscando: "Linux" — 1392 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
22/09/2026
[CVE-2026-13087] A heap out-of-bounds write vulnerability was found in the Linux kernel's RPC-over-RDMA server reply …
A heap out-of-bounds write vulnerability was found in the Linux kernel's RPC-over-RDMA server reply path in net/sunrpc/xprtrdma/svc_rdma_sendto.c. When a crafted RPC-over-RDMA client sends a large NFS READ request with an empty Write list and no Reply chunk, the server linearizes the entire multi-page reply into a fixed-size 4096-byte heap buffer without bounds checking, resulting in a kernel heap…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-65128] NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause SQ…
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause SQL injection. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-65130] NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause OS…
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-65118] NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause im…
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-65121] NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause a…
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an improper authentication issue. A successful exploit of this vulnerability might lead to escalation of privileges, information disclosure, and data tampering.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-65114] NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause mi…
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure.
M Alto vulnerabilidad
21/09/2026
[CVE-2026-63330] Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, api_get_rec…
Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, api_get_recording_stream in warpgate-admin/src/api/recordings_detail.rs protects /@warpgate/admin/api/recordings/{uuid}/stream only with session authentication and omits require_admin_permission for AdminPermission::RecordingsView. Any authenticated regular user who identifies an active recording can subscribe…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
21/09/2026
Vulnerabilidad alta en CRI-O permite eludir contexto de seguridad en Kubernetes
Una falla en la restauración de puntos de control de CRI-O permite a usuarios con capacidad de crear pods eludir el contexto de seguridad de Kubernetes, reteniendo credenciales, capacidades Linux y configuraciones seccomp del contenedor comprometido. Esto expone infraestructuras containerizadas en México y LATAM a ejecución con privilegios elevados, afectando principalmente plataformas que utilizan Kubernetes en producción con múltiples usuarios o entornos multi-tenant.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-87886] Local privilege escalation due to insecure file permissions. The following products are affected: Ac…
Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-52727] lxc-ci contains continuous integration and image-build scripts for LXC. Prior to the 2026-05-28 Arch…
lxc-ci contains continuous integration and image-build scripts for LXC. Prior to the 2026-05-28 Arch Linux image publication, images built from images/archlinux.yaml retain the same pacman local-signing private key in /etc/pacman.d/gnupg and redistribute it to every container or virtual machine created from that image. An attacker who controls an HTTP package mirror or can intercept mirror traffic…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-19477] There is stack-based buffer overflow vulnerability recently discovered in MCC Universal Library for …
There is stack-based buffer overflow vulnerability recently discovered in MCC Universal Library for Linux (uldaq).  This may result in information disclosure or arbitrary code execution. This vulnerability affects MCC Universal Library for Linux (uldaq) v1.2.1 and prior versions.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-90041] In the Linux kernel, the following vulnerability has been resolved: HID: sony: clean up device list…
In the Linux kernel, the following vulnerability has been resolved: HID: sony: clean up device list on probe failure sony_input_configured() adds some controllers to sony_device_list before HID core registers their input devices. input_register_device() can fail after the callback returns successfully. sony_probe() then observes that HID_CLAIMED_INPUT is clear and unwinds, but only stops the HID…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-90043] In the Linux kernel, the following vulnerability has been resolved: zram: fix slot lock bit positio…
In the Linux kernel, the following vulnerability has been resolved: zram: fix slot lock bit position on big-endian 64-bit The slot lock is a bit operation on the whole __lock word, which flags and ac_time alias as two u32s. On little-endian the lock bit lands in the position ZRAM_ENTRY_LOCK reserves in flags, so the aliasing works out. On 64-bit big-endian it lands in ac_time instead: with ZRA…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-90044] In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Fix Use-Afte…
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Fix Use-After-Free in AIO error path In ffs_epfile_write_iter() and ffs_epfile_read_iter(), when ffs_epfile_io() fails with an error other than -EIOCBQUEUED, the io_data structure (`p`) is freed. However, for AIO operations, the kiocb cancel function was already armed and kiocb->private was set to `p`. If a c…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-90045] In the Linux kernel, the following vulnerability has been resolved: USB: gadget: ffs: fix mm lifeti…
In the Linux kernel, the following vulnerability has been resolved: USB: gadget: ffs: fix mm lifetime handling io_data stores a pointer to the submitting task's mm_struct, but does not currently hold a reference to it while async requests are pending. This can result in a use-after-free if the task exits before completion handling finishes. Take a reference with mmgrab() when queuing the read …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
16/09/2026
[CVE-2026-90046] In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: don't spin_trylo…
In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: don't spin_trylock() in NMI on UP Patch series "mm/page_alloc: fixes for free_pages_nolock() on RT/UP". Pre-existing bugs found by Sashiko during review of this other series: https://lore.kernel.org/all/20260703-alloc-trylock-v5-0-c87b714e19d3@google.com/ I have not reproduced these bugs, and I suspect there is …
M Alto vulnerabilidad
16/09/2026
[CVE-2026-90047] In the Linux kernel, the following vulnerability has been resolved: drm/xe: Don't hand out the flat…
In the Linux kernel, the following vulnerability has been resolved: drm/xe: Don't hand out the flat CCS storage as usable VRAM get_flat_ccs_offset() reads the base of the flat CCS storage from the hardware, scales it by the number of enabled L3 nodes, and rounds the result up to 128K. Everything below that offset is then handed to the VRAM allocator as usable memory. Rounding a limit that mean…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-90030] In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: clear forceRM when i…
In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: clear forceRM when issuing EndTransfer The forceRM bit of the DEPCMD register controls the behavior of the EndTransfer command used to stop an active transfer. Older DWC3 programming guide revisions recommended setting forceRM=1 when issuing EndTransfer. Newer programming guide revisions recommend issuing EndTransfer …
M Alto vulnerabilidad
16/09/2026
[CVE-2026-90032] In the Linux kernel, the following vulnerability has been resolved: media: usbtv: keep device alive…
In the Linux kernel, the following vulnerability has been resolved: media: usbtv: keep device alive while ALSA card exists The ALSA PCM callbacks store the driver state in pcm->private_data. An open PCM file can outlive USB disconnect because usbtv_audio_free() uses snd_card_free_when_closed(). The disconnect path can then drop the V4L2 device reference and free struct usbtv before ALSA releases…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-90022] In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi2: fix use-a…
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi2: fix use-after-free in string attribute show path f_midi2_opts_str_show() takes the string lock internally, but its callers dereference the opts->info. pointer before calling it, outside the lock. This races with f_midi2_opts_str_store(), which frees the old string under opts->lock when the attribute …