Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1014
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Hace 19 horas
[CVE-2026-84875] IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary…
IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
M Alto vulnerabilidad Nuevo
Hace 19 horas
[CVE-2026-84058] IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a buffer overrun in the TDS (Micr…
IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a buffer overrun in the TDS (Microsoft SQL Server) PRELOGIN packet decoder. A remote attacker who can send a specially crafted TDS PRELOGIN packet to a network monitored by an IBM Guardium Collector may cause a denial of service or potentially execute arbitrary code on the Collector appliance.
M Alto vulnerabilidad Nuevo
Hace 21 horas
[CVE-2026-82344] IBM Guardium Data Protection 12.0, 12.1 is vulnerable to a heap-based buffer overflow in the S-TAP T…
IBM Guardium Data Protection 12.0, 12.1 is vulnerable to a heap-based buffer overflow in the S-TAP TrafficTap TDS login reassembly functionality. An unauthenticated remote attacker can send crafted TDS login fragments that exceed the fixed-size reassembly buffer, potentially resulting in denial of service or arbitrary code execution on the affected system.
M Alto vulnerabilidad Nuevo
Hace 21 horas
[CVE-2026-82335] IBM Guardium Data Protection 12.0, 12.1, 12.2 is vulnerable to a heap-based buffer overflow in the M…
IBM Guardium Data Protection 12.0, 12.1, 12.2 is vulnerable to a heap-based buffer overflow in the MongoDB protocol parser. A remote attacker could send a specially crafted MongoDB SCRAM username containing an excessive length and cause memory corruption, potentially resulting in denial of service or arbitrary code execution.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-106062] A heap-based buffer overflow was found in GIMP’s DirectDraw Surface (DDS) loader. When loading a cra…
A heap-based buffer overflow was found in GIMP’s DirectDraw Surface (DDS) loader. When loading a crafted DDS image, buffer sizes derived from width, height, and pitch can be computed using 32-bit arithmetic that overflows. The allocated buffer is too small for the amount of pixel data written through GEGL (CWE-787), following integer overflow in size calculations (CWE-190). This may allow heap cor…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-58865] In multiple functions of PduParser.java, there is a possible persistent denial of service due to a m…
In multiple functions of PduParser.java, there is a possible persistent denial of service due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-55286] In stpropnci_process of stpropnci.cc, there is a possible out of bounds write due to an incorrect bo…
In stpropnci_process of stpropnci.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-58815] In multiple locations, there is a possible out of bounds write due to an incorrect bounds check. Thi…
In multiple locations, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-49937] In multiple functions of MessageQueueBase.h, there is a possible out of bounds read due to an incorr…
In multiple functions of MessageQueueBase.h, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-47602] NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode driver w…
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode driver where a local user can cause the driver to dereference an untrusted pointer. A successful exploit of this vulnerability might lead to denial of service and information disclosure.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-47550] NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer where an unp…
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer where an unprivileged local user can supply an untrusted pointer that the driver dereferences without validation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-100814] Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed …
Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-100782] Privilege escalation due to incorrect boundary conditions in the Graphics component. This vulnerabil…
Privilege escalation due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-100764] Privilege escalation due to incorrect boundary conditions in the Graphics: WebGPU component. This vu…
Privilege escalation due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157.
M Alto vulnerabilidad
28/09/2026
[CVE-2026-100908] A vulnerability has been found in Eyeplus 57.0.0.0308. This affects an unknown function of the compo…
A vulnerability has been found in Eyeplus 57.0.0.0308. This affects an unknown function of the component p2pcam HTTP Parser. Such manipulation leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
28/09/2026
[CVE-2026-100888] A weakness has been identified in Trusted Domain Project OpenDKIM up to 2.11.0. This affects the fun…
A weakness has been identified in Trusted Domain Project OpenDKIM up to 2.11.0. This affects the function dkim_canon_selecthdrs of the file libopendkim/dkim-canon.c of the component DKIM Signature Header Selection. Executing a manipulation of the argument h can lead to out-of-bounds write. The attack can be executed remotely. The exploit has been made available to the public and could be used for …
M Alto vulnerabilidad
24/09/2026
[CVE-2026-58005] Out-of-bounds read vulnerability in Altera Trusted Firmware on HPS allows Privilege Escalation and O…
Out-of-bounds read vulnerability in Altera Trusted Firmware on HPS allows Privilege Escalation and Overflow Buffers. This issue affects Trusted Firmware: through socfpga_v2.14.0.
M Alto vulnerabilidad
21/09/2026
[CVE-2026-94424] A vulnerability has been found in Moore Threads MTT S80 Driver Package up to 340.150. Impacted is th…
A vulnerability has been found in Moore Threads MTT S80 Driver Package up to 340.150. Impacted is the function sub_140001000 in the library mtdispkm64.sys of the component IOCTL Handler. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The vendor was contacted early about this disclosure but did not respond in any way.
M Alto vulnerabilidad
21/09/2026
Vulnerabilidad alta en BioStar BIOS Update Utility 1.9.7.3 permite escritura arbitraria de memoria
Se encontró una vulnerabilidad de severidad alta (CVSS 8.8) en el componente IOCTL Handler del archivo BSMEM64_W10.sys de BioStar BIOS Update Utility versión 1.9.7.3. La falla permite a un atacante local ejecutar una condición de escritura arbitraria en memoria física, comprometiendo la integridad del firmware. El exploit ha sido publicado, incrementando significativamente el riesgo para empresas con sistemas legacy que ejecutan esta utilidad en máquinas de acceso alta.
M Alto vulnerabilidad
21/09/2026
Vulnerabilidad alta en BioStar Temperature Monitor Utility 1.2.1806.2200 permite ejecución de código local
Se ha detectado una vulnerabilidad de severidad alta (CVSS 8.8) en el controlador BS_HWMIO64_W10.sys de BioStar Temperature Monitor Utility 1.2.1806.2200. La falla en el manejador IOCTL permite a un atacante local ejecutar una condición write-what-where, comprometiendo la integridad del sistema. El exploit ha sido divulgado públicamente, aumentando el riesgo en entornos empresariales de México y Latinoamérica que utilicen esta herramienta de monitoreo.