Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1003
Esta semana
RSS
M Alto vulnerabilidad
03/09/2026
[CVE-2026-64197] There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied…
There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated data structure. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-64195] There is an out-of-bounds write vulnerability in DASYLab due to lack of proper validation of user-su…
There is an out-of-bounds write vulnerability in DASYLab due to lack of proper validation of user-supplied data. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-64196] There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied…
There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated heap. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85091] zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() …
zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-71220] A stack out-of-bounds write vulnerability was found in gfs2-utils. In gfs2_edit, the di_height field…
A stack out-of-bounds write vulnerability was found in gfs2-utils. In gfs2_edit, the di_height field from on-disk inode metadata is used as an array index without bounds checking, causing a stack buffer overflow that may lead to arbitrary code execution when processing crafted GFS2 filesystem images.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-71221] A stack out-of-bounds write vulnerability was found in gfs2-utils. In savemeta, the height value fro…
A stack out-of-bounds write vulnerability was found in gfs2-utils. In savemeta, the height value from on-disk inode metadata is used as a loop bound without bounds checking, causing a stack buffer overflow that may lead to arbitrary code execution when processing crafted GFS2 filesystem images.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-13732] A flaw was found in GDB's STABS debug format parser. The read_member_functions() function in gdb/sta…
A flaw was found in GDB's STABS debug format parser. The read_member_functions() function in gdb/stabsread.c contains a linked list removal bug in the code that separates destructor and non-destructor member functions of C++ classes. The bug causes the destructor entries to remain in the main function list while the list length counter is decremented, resulting in an out-of-bounds write when the f…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
31/08/2026
Vulnerabilidad alta en D-Link DSM-G600 1.01 permite escritura fuera de límites
Se ha identificado una debilidad en el manejador multiparte del archivo /load_file.cgi en dispositivos D-Link DSM-G600 versión 1.01, que permite escritura fuera de límites (out-of-bounds write) explotable remotamente. Con CVSS 8.8, esta vulnerabilidad afecta directamente a empresas en LATAM que utilizan estos dispositivos en infraestructuras de almacenamiento NAS, permitiendo a atacantes comprometer sistemas sin autenticación. El exploit está disponible públicamente, elevando significativamente el riesgo de explotación inmediata.
M Alto vulnerabilidad
27/08/2026
[CVE-2026-76640] Unitree G1 EDU firmware through 1.5.2 contains multiple chained vulnerabilities in the BLE GATT serv…
Unitree G1 EDU firmware through 1.5.2 contains multiple chained vulnerabilities in the BLE GATT server and WiFi provisioning stack that allow unauthenticated proximate attackers to achieve root code execution without pairing or credentials by exploiting an unquoted heredoc variable in the WiFi provisioning script and a buffer overflow in the SSID chunk accumulator. Attackers can send crafted BLE w…
M Alto vulnerabilidad
27/08/2026
Desbordamiento de búfer en pruebas NASL permite acceso completo al sistema (CVE-2026-81625)
Atacantes remotos con privilegios de usuario pueden ejecutar pruebas de vulnerabilidad NASL maliciosas o comprometidas para provocar un desbordamiento de búfer en la pila y obtener acceso total al sistema afectado. Esta vulnerabilidad de severidad alta (CVSS 8.8) afecta múltiples plataformas de escaneo de vulnerabilidades ampliamente utilizadas en centros de datos e infraestructuras altas de LATAM.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-79240] Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote …
Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
25/08/2026
[CVE-2026-79127] Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to ex…
Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Alto vulnerabilidad
25/08/2026
[CVE-2026-79048] Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote …
Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
25/08/2026
[CVE-2026-78952] Out of bounds write in Crashpad in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remo…
Out of bounds write in Crashpad in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
25/08/2026
[CVE-2026-68513] OpenEXR is the reference implementation and specification for the EXR image format, widely used in t…
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13 contain a heap buffer overflow in PyOpenEXR triggered by a channel-name key collision between literal and prefixed RGB channels. When separate_channels=false, PyOpenEXR maps each physical channel name through channelN…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
25/08/2026
[CVE-2026-68515] OpenEXR is the reference implementation and specification for the EXR image format, widely used in t…
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, exrmultiview can write past a heap allocation when it combines two attacker-supplied, individually valid scanline EXR files whose union dataWindow is not aligned to one view's channel subsampling. …
M Alto vulnerabilidad
25/08/2026
[CVE-2026-75770] Substance3D - Painter is affected by an out-of-bounds write vulnerability that could result in arbit…
Substance3D - Painter is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-75749] Substance3D - Painter is affected by an out-of-bounds write vulnerability that could result in arbit…
Substance3D - Painter is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-71564] Substance3D - Designer is affected by an out-of-bounds write vulnerability that could result in arbi…
Substance3D - Designer is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-71382] Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbit…
Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.