Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1003
Esta semana
RSS
M Alto vulnerabilidad
24/09/2026
[CVE-2026-94613] authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an unauthe…
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an unauthenticated attacker can submit a malformed SAML message to an authentik deployment using SAML in either the identity-provider or SAML source role. The message can stop the worker handling /application/saml/* or /source/saml/*, causing the requests assigned to that worker to fail. Worker process termin…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-88382] hiredis commit 29ea279 (post-v1.5.0) contains an uncontrolled memory allocation vulnerability in its…
hiredis commit 29ea279 (post-v1.5.0) contains an uncontrolled memory allocation vulnerability in its RESP aggregate parser.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-86065] Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-o…
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /subscribe endpoint in network/api/websocket/routes.go accepts unauthenticated WebSocket clients with permissive origin handling, does not call SetReadLimit to bound message size, and has no live-connection cap. SocketHub.HandleClientInsertion also accepts an unbounded address list that grow…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-59990] Jawn is an open source JSON parser. Prior to 1.7.0, Jawn parse methods accept arbitrarily deep JSON …
Jawn is an open source JSON parser. Prior to 1.7.0, Jawn parse methods accept arbitrarily deep JSON array and object nesting without a depth limit, allowing a remote attacker who can submit untrusted JSON to grow parser contexts until the JVM heap is exhausted. The resulting java.lang.OutOfMemoryError is a fatal Scala error that is not ordinarily handled by scala.util.Try or cats.effect.IO, causin…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-78383] Allocation of resources without limits or throttling vulnerability in Apache Tomcat allows an unauth…
Allocation of resources without limits or throttling vulnerability in Apache Tomcat allows an unauthenticated AJP request to pin an AJP processing thread leading to denial of service. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M1 through 9.0.121. The following versions were EOL at the time the CVE was created but are known to …
M Alto vulnerabilidad
23/09/2026
[CVE-2026-89425] UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token t…
UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed toke…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-94455] An HTTP endpoint intended for provisioning enterprise and reseller organisations is reachable withou…
An HTTP endpoint intended for provisioning enterprise and reseller organisations is reachable without any session. The authentication middleware is bound only to an explicit list of controllers, and the enterprise controller is not on that list, so no authentication runs for these routes. The endpoint's only check is that the request body carries a token bearing a valid signature from the instanc…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
22/09/2026
[CVE-2026-77633] Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, PrepareUpload in pkg…
Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, PrepareUpload in pkg/filemanager/fs/dbfs/upload.go checks a stale in-memory user storage value through validateUserCapacity and later applies an unconditional storage charge outside the same quota-enforcing transaction. An authenticated user with Files.Write permission can issue concurrent upload-session requests that …
M Alto vulnerabilidad
21/09/2026
[CVE-2026-94624] vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingC…
vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec and a peer-to-peer secondary tier. Attackers can supply arbitrary remote host and port values in kv_transfer_params to create unreachable peer sessions that retain ZeroMQ sockets until the context quota is exhausted, causing an uncaught ZMQError that…
M Alto vulnerabilidad
21/09/2026
[CVE-2026-61629] nginx ignition is a user interface for the nginx web server. In versions 2.29.0 through 2.40.0, the …
nginx ignition is a user interface for the nginx web server. In versions 2.29.0 through 2.40.0, the gin i18n middleware in nginx-ignition's API server runs in front of every HTTP request and calls `golang.org/x/text/language.ParseAcceptLanguage` on the raw `Accept-Language` header without imposing any size or shape filter. The underlying parser has quadratic-time behaviour on long lists of malform…
M Alto vulnerabilidad
21/09/2026
[CVE-2026-91866] A specially crafted pair of WS-Policy documents can force Neethi's policy-intersection to do exponen…
A specially crafted pair of WS-Policy documents can force Neethi's policy-intersection to do exponential amounts of work, pinning the CPU for a long time (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue.
M Alto vulnerabilidad
21/09/2026
[CVE-2026-91864] A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which N…
A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which Neethi copies into memory without counting it against its size limits, exhausting the heap (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue.
M Alto vulnerabilidad
21/09/2026
[CVE-2026-91865] A small WS-Policy document using repeated policy references can force Neethi to re-expand the same r…
A small WS-Policy document using repeated policy references can force Neethi to re-expand the same references exponentially during normalization, consuming huge amounts of CPU and memory (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-57227] Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M…
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.0 until 7.0.17 and 8.0.6, the MQTT parser in rust/src/mqtt/mqtt.rs permits repeated PUBREC or PUBREL messages to be appended to one transaction without a limit. Crafted MQTT traffic can grow transaction state indefinitely, consuming CPU and memory and causing slowdown or d…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-91149] A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by in…
A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustaining numerous simultaneous connections to the `cockpit-tls` service. This forces the service to create an unbounded number of detached threads, consuming system resources such as memory and file descriptors. The primary consequence is a denial of service (DoS), leading to degradat…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93688] SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails …
SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstrap_room values, allowing unbounded transfer state allocation. Unauthenticated attackers can reach the decode engine's POST /generate endpoint and submit arbitrary bootstrap_room values to exhaust prefill process memory until out-of-memory termination.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-84447] libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.1 and earlier, crafted grid, iov…
libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.1 and earlier, crafted grid, iovl, and iden reference graphs can repeatedly decode the same base image because processed_ids is copied per branch and ImageItem::decode_image() has no shared operation budget. This vulnerability is fixed in 1.23.2.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93491] A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vul…
A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1 requests on a single connection and withholding reads. This action causes the methodOverflowQueue to grow without limit, leading to unbounded heap memory consumption and a denial of service due to memory exhaustion.
M Alto vulnerabilidad
18/09/2026
Vulnerabilidad alta en Netty permite agotamiento de memoria por streams SPDY ilimitados
Se identificó una flaw en Netty donde SpdySessionHandler acepta un número ilimitado de streams SPDY concurrentes iniciados remotamente, permitiendo a atacantes enviar múltiples frames SYN_STREAM y causar agotamiento de memoria heap y directa en la JVM. Esto afecta aplicaciones Java que utilizan Netty para comunicaciones HTTP/2 y SPDY, siendo alta en servidores de aplicaciones, gateways y proxies desplegados en infraestructuras cloud y on-premise en LATAM.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93572] ## Summary `RedisArrayAggregator` recently added `maxElements` and `maxNestedArrayDepth` limits t…
## Summary `RedisArrayAggregator` recently added `maxElements` and `maxNestedArrayDepth` limits to fix public Redis resource-exhaustion advisories. The limits are independent, but the allocator remains eager: every positive nested RESP array header creates `new ArrayList(length)` before any child element exists. With the default constructor, an attacker can send nested array he…