Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1014
Esta semana
RSS
M Alto vulnerabilidad
22/09/2026
[CVE-2026-75676] Bridge is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary cod…
Bridge is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-85279] Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ contains a stack b…
Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ contains a stack buffer overflow in PluginsManager::loadPluginFromPath in PowerEditor/src/MISC/PluginsManager/PluginsManager.cpp because the plugin-supplied GetLexerCount() result controls a loop that writes to containers[30] without enforcing NB_MAX_EXTERNAL_LANG. A malicious or compromised plugin that reports more …
M Alto vulnerabilidad
22/09/2026
[CVE-2026-86054] Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ contains a stack b…
Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ contains a stack buffer overflow in NppParameters::writeSession in PowerEditor/src/Parameters.cpp because it copies a session path derived from -settingsDir= into backupPathName[MAX_PATH] with unbounded wcscpy and appends SESSION_BACKUP_EXT with unbounded wcscat. A sufficiently long settings directory causes the back…
M Alto vulnerabilidad
21/09/2026
[CVE-2026-94184] A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious …
A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious or compromised mail server advertising NTLM authentication can send a crafted Type 2 challenge that causes fetchmail to write past a fixed stack buffer while building the NTLM authenticate response. This may lead to remote code execution depending on stack-frame layout, or to authentication failure …
M Alto vulnerabilidad
18/09/2026
[CVE-2026-61548] Rsyslog is a rocket-fast system for log processing. From 7.5.4 until 8.2606.0, the optional mmpstruc…
Rsyslog is a rocket-fast system for log processing. From 7.5.4 until 8.2606.0, the optional mmpstrucdata plugin's parseSD_PARAM function in plugins/mmpstrucdata/mmpstrucdata.c stores RFC5424 parameter values in a fixed pVal[32 * 1024] stack buffer and calls parsePARAM_VALUE without supplying the destination size. A remote unauthenticated attacker whose crafted RFC5424 message reaches an action usi…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-81944] PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 an…
PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain a stack-based buffer overflow in the web server. Insufficient bounds checking on data copied into a stack buffer allows a remote authenticated attacker to cause a denial of service or potentially execute arbitrary code on the underlying operating system.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-19477] There is stack-based buffer overflow vulnerability recently discovered in MCC Universal Library for …
There is stack-based buffer overflow vulnerability recently discovered in MCC Universal Library for Linux (uldaq).  This may result in information disclosure or arbitrary code execution. This vulnerability affects MCC Universal Library for Linux (uldaq) v1.2.1 and prior versions.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
17/09/2026
Vulnerabilidad alta de desbordamiento de búfer en Dell OpenManage Server Administrator
Dell OpenManage Server Administrator en versiones anteriores a 11.1.0.3 contiene una vulnerabilidad de desbordamiento de búfer en pila (CVE-2026-81480, CVSS 7.2) que permite a atacantes con privilegios elevados ejecutar código remoto. Esta herramienta de administración es común en data centers y servidores empresariales en LATAM, exponiendo infraestructura alta si no se actualiza inmediatamente.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-25283] Memory Corruption when copying unverified data from an external source exceeds the allocated buffer …
Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-81546] The Affinity by Canva application before 3.3.0 (September 2026 release) did not perform adequate bou…
The Affinity by Canva application before 3.3.0 (September 2026 release) did not perform adequate bounds checking when parsing Affinity document files leading to a stack-based buffer overflow. A threat actor could craft a Affinity document that when opened by a user in Affinity could result in arbitrary code execution.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-76869] Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in reboot_timer_set.cgi ca…
Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in reboot_timer_set.cgi caused by improper sscanf token parsing. Attackers can exploit this flaw by submitting crafted input to the affected endpoint to corrupt stack memory.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-76860] Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in wake_up_set.cgi caused …
Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in wake_up_set.cgi caused by unbounded tokenization of MAC and ID input. Attackers can supply crafted MAC and ID values to the affected endpoint to overflow the stack buffer and corrupt program memory.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-76861] Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in ntools_tcpdump_start_se…
Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in ntools_tcpdump_start_set.cgi caused by an unsized sprintf call when processing form values. An attacker can submit crafted input to this cgi endpoint to overflow the stack buffer and potentially execute arbitrary code.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-19774] BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allow…
BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability. The specific flaw exists within the handling of the stream endpoin…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-12150] IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3…
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote attacker with a trusted TLS client certificate to cause a denial of service and potentially affect memory contents due to improper validation of deeply nested certificate data during …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
14/09/2026
[CVE-2026-90689] A security flaw has been discovered in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. Impacted is the fun…
A security flaw has been discovered in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. Impacted is the function formDelWebAuthWhiteUser. Performing a manipulation of the argument webAuthWhiteUserIndex results in stack-based buffer overflow. The attack can be initiated remotely.
M Alto vulnerabilidad
14/09/2026
[CVE-2023-46273] Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has …
Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has an ah_bgd buffer overflow via ah_event_send.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-33963] An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2…
An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. A stack-based buffer overflow occurs when a malformed message is sent to the camera driver, causing a denial of service.
M Alto vulnerabilidad
13/09/2026
Vulnerabilidad alta de desbordamiento de buffer en SIPp 3.7.7 permite crash remoto
SIPp versiones hasta 3.7.7 contiene un desbordamiento de buffer en la función createAuthHeader() al procesar desafíos de autenticación SIP con parámetros de algoritmo manipulados. Un servidor SIP malicioso puede enviar una respuesta 401 o 407 fraudulenta para corromper la memoria del proceso cliente y causar su caída, afectando sistemas de telefonía empresarial y centros de contacto en la región.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-86093] IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to…
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that improperly copies user-controlled data into a fixed-size stack buffer without bounds checking.