Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1003
Esta semana
RSS
M Alto vulnerabilidad
18/09/2026
[CVE-2026-61714] FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6…
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6, configuring synth.midi-channels above 16 allows the MIDI player to index _fluid_player_t::channel_isplaying outside its fixed-size heap allocation while tracking active channels. The resulting out-of-bounds reads and writes invoke undefined behavior and may compromise confidentiality, integrity, o…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-61721] FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6…
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS loader assigns file-controlled wsmp.loop_start and wsmp.loop_length values to samples without calling fluid_sample_validate() or fluid_sample_sanitize_loop(). A crafted DLS file can place sample loop points beyond the sample buffer, causing out-of-bounds reads during audio rendering…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-11727] IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remote attacker to cause…
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of queue manager responses when requesting AMS policy data.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-11716] IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denia…
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code during queue manager startup due to improper validation of cluster migration data.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-46655] virtio-win provides Windows paravirtualized drivers for QEMU and KVM. From mm210 until mm320, the Vi…
virtio-win provides Windows paravirtualized drivers for QEMU and KVM. From mm210 until mm320, the Viosock driver permits a low-privilege local process to submit an IOCTL_SELECT request with attacker-controlled VIRTIO_VSOCK_SELECT.Fdss[*].fd_count values that overflow the 32-bit sum used by VIOSockSelect for bounds checking. The wrapped sum can pass the FD_SETSIZE check even though an individual de…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-67549] OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format…
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.1.16.0, A crafted 1-bit contiguous cmyk tiff is exposed through a native uint1 imagespec, so callers allocate a bit-packed buffer. tiffinput::read_native_scanline_locked() nevertheless invokes tiffinput::bit_convert() with 8-bit output and writes one expanded…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-63422] OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format…
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A valid tiled openexr image whose width is not a multiple of its tile width can trigger an overflow when a caller reads a partial edge-tile rectangle. openexrinput::read_native_tiles() copies each row into the caller buffe…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
18/09/2026
[CVE-2026-11375] IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arb…
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a stack buffer overflow when processing XA transaction identifiers.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-11381] IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arb…
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of message distribution list structures.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-10575] IBM MQ could allow an authenticated attacker to cause a denial of service or potentially escalate pr…
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to a heap buffer overflow when processing MQPUT operations with malformed distribution headers.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-10744] IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denia…
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to an integer overflow in MQINQ request validation.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-44236] rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP serve…
rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an undersized connection.tune.frame_max value during amqp_login(), and rabbitmq-c accepts the value in amqp_login_inner() in librabbitmq/amqp_socket.c. amqp_tune_connection() in librabbitmq/amqp_connection.c uses frame_max to reallocate the outbound buffer without enforcing AMQP_FRAME_MIN…
M Alto vulnerabilidad
17/09/2026
Vulnerabilidad alta de desbordamiento de búfer en Dell OpenManage Server Administrator
Dell OpenManage Server Administrator versiones anteriores a 11.1.0.3 contiene una vulnerabilidad de desbordamiento de búfer en el montículo (heap) que permite a atacantes con privilegios elevados ejecutar código remoto. Esta herramienta es ampliamente utilizada en centros de datos y entornos empresariales de LATAM para gestión de servidores Dell, representando un riesgo significativo si está expuesta en redes internas o accesibles remotamente.
M Alto vulnerabilidad
17/09/2026
Vulnerabilidad alta de desbordamiento de búfer en Dell OpenManage Server Administrator
Dell OpenManage Server Administrator en versiones anteriores a 11.1.0.3 contiene una vulnerabilidad de desbordamiento de búfer en el montículo (heap-based buffer overflow) con puntuación CVSS 7.8. Un atacante con acceso local y privilegios bajos podría explotarla para elevar sus permisos en sistemas de gestión de servidores. Empresas en México y LATAM que usen esta solución para administración de infraestructura Dell requieren actualizar inmediatamente.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92399] A vulnerability was determined in GPAC 26.07.0. This affects the function rmt_client_handle_ws_frame…
A vulnerability was determined in GPAC 26.07.0. This affects the function rmt_client_handle_ws_frame of the file src/utils/rmt_ws.c of the component WebSocket Handler. Executing a manipulation of the argument payload_size can lead to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version abi-16.26 …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
16/09/2026
[CVE-2026-89028] MikroTik RouterOS before 7.24 contains a heap memory corruption vulnerability in the userspace SMB d…
MikroTik RouterOS before 7.24 contains a heap memory corruption vulnerability in the userspace SMB daemon that allows remote attackers to corrupt adjacent heap memory by supplying a crafted uniPwdLen value in the SMB1 SessionSetupAndX handler. An attacker can send a malformed SMB1 request with a uniPwdLen field that triggers an integer underflow, causing the resulting value to be used as the copy …
M Alto vulnerabilidad
16/09/2026
Vulnerabilidad alta en NLnet Labs Unbound: desbordamiento de búfer por consultas DNS malformadas
NLnet Labs Unbound versiones hasta 1.26.0 es vulnerable a desbordamiento de búfer en memoria durante el procesamiento de respuestas TCP con nombres de consulta de 255 caracteres. Un atacante controlando un servidor DNS malicioso puede explotar esta falla para ejecutar código arbitrario o causar negación de servicio en recursores DNS de empresas. El impacto es alta en infraestructuras de LATAM que dependen de Unbound para resolución DNS.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-69486] Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to exe…
Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-56967] In Cellular Modem, there is a possible out-of-bounds write due to a heap buffer overflow. This could…
In Cellular Modem, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-55323] In gf_base_update_finger_base of gf_base.c, there is a possible out-of-bounds write due to a heap bu…
In gf_base_update_finger_base of gf_base.c, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.