Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1003
Esta semana
RSS
M Alto vulnerabilidad
18/09/2026
[CVE-2026-11725] IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arb…
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in MQINQ request processing.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-46655] virtio-win provides Windows paravirtualized drivers for QEMU and KVM. From mm210 until mm320, the Vi…
virtio-win provides Windows paravirtualized drivers for QEMU and KVM. From mm210 until mm320, the Viosock driver permits a low-privilege local process to submit an IOCTL_SELECT request with attacker-controlled VIRTIO_VSOCK_SELECT.Fdss[*].fd_count values that overflow the 32-bit sum used by VIOSockSelect for bounds checking. The wrapped sum can pass the FD_SETSIZE check even though an individual de…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-11378] IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arb…
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in distribution list processing.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93652] Integer overflow in µD3TN v0.15.0 TCPCLv3 handshake causes heap overflow, allowing remote attackers …
Integer overflow in µD3TN v0.15.0 TCPCLv3 handshake causes heap overflow, allowing remote attackers to reliably cause DoS
M Alto vulnerabilidad
17/09/2026
[CVE-2026-25290] Memory Corruption when validating large data buffers from external sources using addition to check b…
Memory Corruption when validating large data buffers from external sources using addition to check buffer length.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-63126] Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.5 and 7.0…
Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.5 and 7.0.0-alpha04, Wire protobuf readers do not consistently validate attacker-controlled lengths against the current logical message boundary before advancing cursors, pointers, limits, slices, or allocations. In Kotlin, ProtoAdapter.decode(ByteArray) and ProtoAdapter.decode(ByteString) use ByteArrayProto…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92248] A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially…
A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG header. This leads to an undersized heap allocation, resulting in a heap-based buffer overflow when the image data is decoded. This buffer overflow corrupts adjacent hea…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
15/09/2026
[CVE-2026-55351] In VPU, there is a possible out-of-bounds write due to an integer overflow. This could lead to local…
In VPU, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-90715] A security vulnerability has been detected in marcobambini Gravity up to 0.9.7. This affects an unkn…
A security vulnerability has been detected in marcobambini Gravity up to 0.9.7. This affects an unknown function of the file src/utils/gravity_json.c of the component udp json-parser. Such manipulation leads to integer overflow. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. Upgrading to version 0.9.8 mitigates this issue. The name of the patch is…
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90593] A vulnerability was determined in embedded-graphics up to 0.8.2. This affects the function ImageRaw:…
A vulnerability was determined in embedded-graphics up to 0.8.2. This affects the function ImageRaw::draw_sub_image of the file src/image/image_raw.rs. Executing a manipulation of the argument width can lead to integer overflow. The attack may be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad alta en libde265 permite desbordamiento de enteros en procesamiento de video HEVC
libde265 versiones anteriores a 1.1.1 contienen un fallo de desbordamiento de enteros en cálculo de desplazamientos de píxeles que permite a archivos HEVC malformados con dimensiones grandes provocar lecturas/escrituras fuera de límites en memoria heap. El impacto incluye exposición de datos sensibles, corrupción de memoria o crasheo del decodificador afectando plataformas de procesamiento de video, streaming y análisis multimedia en operaciones en LATAM.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad alta en libde265: desbordamiento de enteros en códecs H.265
libde265, biblioteca de código abierto para decodificación de vídeo H.265 (HEVC), contiene un desbordamiento de enteros en versiones anteriores a 1.1.1 que permite a atacantes mediante flujos HEVC manipulados provocar lectura fuera de límites en memoria heap, exponiendo datos sensibles o causando caída del servicio. Afecta servidores multimedia, plataformas de streaming y sistemas de videoconferencia en empresas LATAM que procesan vídeo con esta biblioteca.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-87020] An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds w…
An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc DICOM Server decodes an attacker-supplied PNG.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad alta en libp2p-rendezvous permite desbordamiento de temporizador en clientes
libp2p-rendezvous versión 0.17.1 y anteriores no valida correctamente los valores TTL en respuestas de descubrimiento, permitiendo que servidores rendezvous maliciosos causen pánico en procesos cliente mediante aritmética de temporizador no limitada. Afecta infraestructuras de red descentralizada, nodos blockchain y aplicaciones P2P en México y LATAM.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87823] zstd-jni before 1.5.7-14 performs 32-bit signed bounds checks on three direct-ByteBuffer frame-size …
zstd-jni before 1.5.7-14 performs 32-bit signed bounds checks on three direct-ByteBuffer frame-size native methods, allowing out-of-bounds memory reads via negative or overflowing offsets. Attackers can supply negative offset values near Integer.MIN_VALUE to read unmapped memory, causing JVM termination or extracting arbitrary frame size data from unintended memory locations.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
09/09/2026
[CVE-2026-56711] VLC media player computes the size of a picture buffer with 32-bit arithmetic and allocates from the…
VLC media player computes the size of a picture buffer with 32-bit arithmetic and allocates from the wrapped result. In AllocatePicture in src/misc/picture.c the running total is accumulated as i_bytes += p->i_pitch * p->i_lines, and both plane_t fields are declared int in include/vlc_picture.h, so the multiplication is evaluated at 32 bits and wraps before it is widened to the size_t accumulator.…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-81987] Acrobat Reader is affected by an Integer Overflow or Wraparound vulnerability that could result in a…
Acrobat Reader is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-82007] Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result i…
Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-75771] Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result i…
Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-75862] Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result i…
Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.