Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 4 min
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1012
Esta semana
RSS
M Alto vulnerabilidad
30/08/2026
Vulnerabilidad alta de desbordamiento de búfer en NASA Trick 19.6.0 (CVE-2026-82478)
Se identificó una vulnerabilidad de desbordamiento de búfer en pila en NASA Trick 19.6.0, específicamente en la función JSONVariableServerThread::parse_request del manejador de sockets TCP. Esta falla permite ejecución remota de código sin autenticación previa. Afecta principalmente a instituciones de investigación, universidades y centros aeroespaciales en Latinoamérica que utilizan esta herramienta de simulación científica.
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad alta en MongoDB Connector for BI ODBC: desbordamiento de búfer por inyección SQL
Un atacante puede enviar consultas SQL malformadas a través del controlador ODBC de MongoDB Connector for BI, especificando nombres de cursor que exceden los límites internos del búfer. Esto provoca sobrescritura de memoria adyacente, potencialmente causando denial of service (DoS) o ejecución de código arbitrario en aplicaciones que integren este conector. Afecta directamente a plataformas de análisis y Business Intelligence que dependan de este driver en entornos LATAM.
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad de memoria en MongoDB BI Connector ODBC Driver (CVE-2026-81533)
El controlador ODBC de MongoDB BI Connector presenta un fallo de seguridad de memoria (CVSS 7.1) cuando procesa sentencias SQL con secuencias de dígitos inusualmente largas en cláusulas LIMIT, afectando solo conexiones con la opción de prefetch habilitada. La vulnerabilidad se origina por copia insegura de datos a un búfer interno de tamaño fijo sin validación de límites. Empresas en LATAM que utilizan este driver para consultas analíticas en MongoDB deben revisar inmediatamente su configuración de prefetch y aplicar los parches disponibles del fabricante.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-67560] Bendix EC80 Brake ECU is vulnerable to a stack-based buffer overflow, which may allow an attacker …
Bendix EC80 Brake ECU is vulnerable to a stack-based buffer overflow, which may allow an attacker to crash the ECU. A crafted payload can then be used to remotely execute arbitrary code or inject arbitrary CAN bus traffic. This could cause the loss of the ABS function, steering assist, speedometer, and shifting.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-68863] Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow vulnerabil…
Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-77658] A stack-based buffer overflow vulnerability exists in the Dia diagram editor when processing Network…
A stack-based buffer overflow vulnerability exists in the Dia diagram editor when processing Network Bus objects from Dia XML project files. In objects/network/bus.c, bus_load() reads the number of bus handles from the file attribute "bus_handles" using attribute_num_data() without validating an upper bound: bus->num_handles = attribute_num_data(attr); When a bus handle is subsequently move…
G Alto vulnerabilidad
25/08/2026
[CVE-2026-78910] Buffer overflow in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute a…
Buffer overflow in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
25/08/2026
[CVE-2026-48417] Substance3D - Sampler is affected by a Stack-based Buffer Overflow vulnerability that could result i…
Substance3D - Sampler is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-68960] A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If t…
A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected product installed and can receive UDP packets from that system.
M Alto vulnerabilidad
20/08/2026
[CVE-2026-17138] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.
M Alto vulnerabilidad
20/08/2026
[CVE-2026-16945] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a stack-based buffer overflow.
M Alto vulnerabilidad
20/08/2026
[CVE-2026-63387] Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an off-by-o…
Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an off-by-one stack buffer overflow in evdns.c when dnsname_to_labels formats a name-bearing DNS record at the end of the 64 KB stack buffer allocated by evdns_server_request_format_response. The final-label check permits j plus label_len plus one to equal buf_len, after which the terminating null byte is writ…
M Alto vulnerabilidad
20/08/2026
[CVE-2026-18303] GIMP TIF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerab…
GIMP TIF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TIF files. The issue results …
M Alto vulnerabilidad
20/08/2026
[CVE-2026-18297] GStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vul…
GStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of OGG files. The issu…
M Alto vulnerabilidad
19/08/2026
[CVE-2026-76879] C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
19/08/2026
[CVE-2026-18871] IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is af…
IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in host firmware configuration parsing. An attacker with authenticated service-level access to the service processor can write specially crafted configuration data, causing the host firmware boot stack to crash with possible memory corruption during system initialisation, r…
M Alto vulnerabilidad
19/08/2026
[CVE-2026-16911] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary code due to a stack buffer overflow.
M Alto vulnerabilidad
19/08/2026
[CVE-2026-16877] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary code due to a stack-based buffer overflow.
M Alto vulnerabilidad
19/08/2026
[CVE-2026-17093] IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW95…
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 - OP940.81 (Power HMC) is affected by a vulnerability in host firmware configuration parsing. An attacker with service-level access to the BMC/FSP can supply specially crafted configuration data, compromising the host firmware b…
M Alto vulnerabilidad
19/08/2026
[CVE-2026-17494] IBM Power Systems Firmware FW1120.00, and FW1110.00 through FW1110.30 is affected by a vulnerability…
IBM Power Systems Firmware FW1120.00, and FW1110.00 through FW1110.30 is affected by a vulnerability in the interface between the BMC and the host system. An attacker with service access to the BMC can send a specially crafted command, allowing arbitrary code to be executed on the host system, giving full control over the host system and all hosted partitions, resulting in a confidentiality, integ…