Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1003
Esta semana
RSS
M Alto vulnerabilidad
19/08/2026
[CVE-2026-75146] FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec…
FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous value, the current sequence number is driven negative. The fragment retrieval function checked only the upper bound before indexing the fragments array, allowing a negative index to be used and causing an …
M Alto vulnerabilidad
19/08/2026
[CVE-2026-75147] FFmpeg before commit 983dae9 contains an out-of-bounds read in the AV1 RTP packetizer (libavformat/r…
FFmpeg before commit 983dae9 contains an out-of-bounds read in the AV1 RTP packetizer (libavformat/rtpenc_av1.c). The keyframe detection loop that searches for a sequence header OBU advanced its pointer and remaining-size counter by the encoded header length plus the OBU payload size without first bounding the OBU size against the remaining data. A crafted OBU size causes the remaining-size counte…
M Alto vulnerabilidad
19/08/2026
Vulnerabilidad alta en semctl(2) permite acceso no autorizado a semáforos del sistema
Una falla en los comandos GETALL y SETALL de semctl(2) permite que atacantes locales manipulen semáforos del kernel entre ciclos de creación/destrucción, explotando un desbordamiento de secuencia tras 0x8000 operaciones. Afecta sistemas Unix/Linux en producción que ejecutan aplicaciones multi-proceso con semáforos del sistema operativo, comprometiendo la integridad de sincronización en bases de datos y middleware alta.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-63409] Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.296, a malic…
Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.296, a malicious Deskflow server can send an odd-length DSOP vector to ServerProxy::setOptions() in src/lib/client/ServerProxy.cpp, causing the missing value after the final option key to be read beyond the vector during the PacketStreamFilter::filterEvent to ServerProxy::handleData() to ServerProxy::parseHands…
M Alto vulnerabilidad
17/08/2026
[CVE-2026-65832] Deskflow is a keyboard and mouse sharing app. Prior to continuous build 1.26.0.299, a remote unauthe…
Deskflow is a keyboard and mouse sharing app. Prior to continuous build 1.26.0.299, a remote unauthenticated Deskflow server can send kMsgDSetOptions (DSOP) values to ServerProxy::setOptions() in src/lib/client/ServerProxy.cpp so that the value following a modifier option poisons m_modifierTranslationTable, after which ServerProxy::translateKey() or ServerProxy::translateModifierMask() indexes the…
M Alto vulnerabilidad
17/08/2026
[CVE-2026-74238] TIER IV Nebula through 1.2.0 contains an out-of-bounds read vulnerability in the Vlp32Decoder::unpac…
TIER IV Nebula through 1.2.0 contains an out-of-bounds read vulnerability in the Vlp32Decoder::unpack() function that allows unauthenticated remote attackers to cause the decoder to read past the end of a received UDP buffer into adjacent heap memory by sending a short UDP datagram. Attackers can send a malformed datagram to the Velodyne UDP sensor port, which lacks sender-address restrictions pre…
M Alto vulnerabilidad
17/08/2026
[CVE-2026-71980] Belledonne Communications bcg729 through 1.1.2 contains an out-of-bounds read vulnerability in the d…
Belledonne Communications bcg729 through 1.1.2 contains an out-of-bounds read vulnerability in the decodeSIDframe() function in src/cng.c that allows unauthenticated network-adjacent attackers to trigger a heap read beyond buffer boundaries by sending a zero-length comfort-noise RTP payload. A zero-length payload causes an integer underflow in the uint8_t filter order calculation, which wraps to 2…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
13/08/2026
[CVE-2026-73515] PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to caus…
PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplying a malformed FlatGeobuf buffer. The FlatGeobuf property metadata decoder verifies that a string length field is present but fails to verify that the subsequent string body is contained within the supplied buffer before materializing it into a SQL-vis…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-17485] IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and obtain s…
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and obtain sensitive information due to an integer underflow.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-19654] A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module…
A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-16863] IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive informa…
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-of-bounds read.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-18694] An issue in MongoDB Server's geospatial query processing could allow an authenticated user with writ…
An issue in MongoDB Server's geospatial query processing could allow an authenticated user with write privileges to cause certain malformed geometry data to be stored and later processed without proper validation. Subsequent queries against this data could then result in the server accessing memory outside its intended bounds. This could result in a server crash (denial of service) and may expose …
M Alto vulnerabilidad
11/08/2026
[CVE-2026-18688] An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an o…
An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-bounds memory read by providing a specially formed numeric parameter in a certain aggregation pipeline stage. This could result in a server crash (denial of service) and may potentially expose a limited amount of memory contents.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-68814] Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally…
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-68793] Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally…
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
11/08/2026
[CVE-2026-65786] Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privil…
Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-65787] Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privil…
Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-64909] Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execut…
Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-63515] Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-62876] Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.