Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 4 min
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1012
Esta semana
RSS
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106110] ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, the TIFF CCITT Group 3 encoder allocate…
ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, the TIFF CCITT Group 3 encoder allocates an undersized compressed-data buffer for narrow 1-bit images. TiffCcittCompressor.Initialize does not reserve enough space for the row data and T4 end-of-line codes, and T4BitCompressor.CompressStrip reaches unchecked writes when TiffCompression.CcittGroup3Fax is selected directly or inherited fro…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106112] ImageSharp is a 2D graphics library. From 4.0.0 until 4.1.2, ICC LUT16 conversion accepts more than …
ImageSharp is a 2D graphics library. From 4.0.0 until 4.1.2, ICC LUT16 conversion accepts more than four output channels even though ClutCalculator.Calculate and LutEntryCalculator.CalculateLut store intermediate and output values in Vector4. When DecoderOptions.ColorProfileHandling is set to Convert, a malformed embedded profile can direct interpolation and output-LUT operations to write one floa…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106113] ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, decoding an attacker-supplied 32-bit fl…
ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, decoding an attacker-supplied 32-bit floating-point TIFF as Image and applying HistogramEqualization can produce a non-finite or out-of-range luminance in ColorNumerics.GetBT709Luminance. GrayscaleLevelsRowOperation.Invoke uses the resulting value as an unchecked histogram offset, causing an unsafe out-of-range access and pr…
M Alto vulnerabilidad
Hace 3 días
Vulnerabilidad alta en controlador WibuKey para Windows permite modificación de memoria del kernel
El controlador WibuKey para Windows en versiones anteriores a 6.72 contiene validación insuficiente de entrada de usuario al calcular el tamaño de búfer del kernel, permitiendo escritura de datos fuera de los límites asignados. Esto puede causar caída del sistema y, en circunstancias desfavorables, modificación no autorizada de memoria adyacente del kernel. Afecta a empresas en LATAM que utilizan soluciones de licenciamiento basadas en WibuKey.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-49878] In wpas_handle_robust_av_scs_recv_action of robust_av.c, there is a possible out-of-bounds write due…
In wpas_handle_robust_av_scs_recv_action of robust_av.c, there is a possible out-of-bounds write due to a logic error in the code. This could lead to remote code execution with System execution privileges needed. User interaction is not needed for exploitation.
M Alto vulnerabilidad
Hace 4 días
Vulnerabilidad alta en controlador NXP GAU ADC permite desbordamiento de búfer
El controlador ADC (conversor analógico-digital) GAU de NXP contiene un defecto de validación en la gestión de tamaño de búfer que puede permitir desbordamientos de memoria. La vulnerabilidad afecta sistemas embebidos y dispositivos IoT que utilicen este controlador, siendo especialmente relevante en infraestructura industrial y de automatización en LATAM. Con CVSS 8.4, representa un riesgo alto para integridad y disponibilidad de sistemas altas.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-20586] In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to r…
In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS11383899; Issue ID: MSV-9614.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-20526] In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to …
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01898195; Issue ID: MSV-8906.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-20519] In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to …
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01778993; Issue ID: MSV-8898.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-20520] In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to …
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01778988; Issue ID: MSV-8897.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-20522] In neuropilot, there is a possible out of bounds write due to a missing bounds check. This could lea…
In neuropilot, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249050; Issue ID: MSV-9172.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-20523] In neuropilot, there is a possible out of bounds write due to a missing bounds check. This could lea…
In neuropilot, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249062; Issue ID: MSV-9171.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-103484] IVFFlat index build in pgvector before 0.8.7 allows a database user to write data out-of-bounds, whi…
IVFFlat index build in pgvector before 0.8.7 allows a database user to write data out-of-bounds, which can lead to arbitrary code execution.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-59685] Out-of-bounds Write vulnerability in Apache HTTP Server on Windows while processing paths with 8.3 n…
Out-of-bounds Write vulnerability in Apache HTTP Server on Windows while processing paths with 8.3 names that may grow when expanded. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-56153] Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite. This issue affects Ap…
Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
01/10/2026
[CVE-2026-56449] Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response …
Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-47601] NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the open-source kernel m…
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the open-source kernel module DMA-BUF import path where an unprivileged local user could cause improper preservation of memory access permissions when importing a read-only buffer from another device's DMA-BUF exporter. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denia…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-47582] NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacke…
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-47573] NVIDIA NVAPI for Windows contains a vulnerability where an attacker could cause an out-of-bounds wri…
NVIDIA NVAPI for Windows contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-47575] NVIDIA GPU Display Driver for Windows contains a vulnerability in the display driver DIAG escape han…
NVIDIA GPU Display Driver for Windows contains a vulnerability in the display driver DIAG escape handler where a local unprivileged attacker may cause an integer overflow and out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service, and code execution.