Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1741
Esta semana
RSS
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-16924] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an improper calculation of a memory offset during IPsec decapsulation.
M Alto vulnerabilidad
Hace 5 días
Vulnerabilidad alta en semctl(2) permite acceso no autorizado a semáforos del sistema
Una falla en los comandos GETALL y SETALL de semctl(2) permite que atacantes locales manipulen semáforos del kernel entre ciclos de creación/destrucción, explotando un desbordamiento de secuencia tras 0x8000 operaciones. Afecta sistemas Unix/Linux en producción que ejecutan aplicaciones multi-proceso con semáforos del sistema operativo, comprometiendo la integridad de sincronización en bases de datos y middleware alta.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-45698] Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.…
Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.1.19 through 4.4.2, a stack-based buffer overflow exists in the deletedir() function of Netatalk's afpd daemon due to an integer underflow in the calculation of the remaining buffer size used for path construction. deletedir() is a utility function called when a file operation crosses a device bound…
M Alto vulnerabilidad
14/08/2026
[CVE-2026-45699] Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.…
Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.1.19 through 4.4.2, a stack-based buffer overflow exists in the copydir() function of Netatalk's afpd daemon due to an integer underflow in the calculation of the remaining buffer size used for path construction. copydir() is a utility function called when a file operation crosses a device boundary…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-18687] MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate …
MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the collection's encrypted field configuration before use. An authenticated user with readWrite privileges could submit a specially formed request that leads to a server crash or excessive internal writes, resulting in resource exhaustion and corruption of encrypte…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-64909] Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execut…
Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-63515] Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
11/08/2026
[CVE-2026-62741] Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate …
Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-62696] Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an …
Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
10/08/2026
[CVE-2026-59090] A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow…
A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens a specially crafted `.psd` image file. The underflow leads to parser confusion, enabling an attacker to inject arbitrary data as layer resource blocks. This can ultimately result in arbitrary code execution, allowing the attacker to run maliciou…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-43628] llama.cpp builds b3978 through b9058 contain an integer underflow and out-of-bounds read vulnerabili…
llama.cpp builds b3978 through b9058 contain an integer underflow and out-of-bounds read vulnerability in the DRY sampler that allows unauthenticated attackers to trigger a heap buffer underflow by sending a crafted HTTP request with dry_allowed_length set to INT32_MIN to the /v1/completions or /v1/chat/completions endpoints. Attackers can exploit this vulnerability to crash the server with SIGSEG…
M Alto vulnerabilidad
05/08/2026
[CVE-2026-71202] The raster Rust crate's crop() function (src/editor.rs) clamps the crop width/height against source …
The raster Rust crate's crop() function (src/editor.rs) clamps the crop width/height against source dimensions but only clamps the offset_x/offset_y parameters against 0, never against the source width/height. When an offset exceeds the corresponding source dimension, `width2 - offset_x` (or the height equivalent) underflows to a negative i32, which release builds do not trap; the negative value i…
M Alto vulnerabilidad
01/08/2026
Desbordamiento de buffer en FreeRDP 3.28.0 y anteriores afecta canal RAIL
FreeRDP versiones 3.28.0 e inferiores contienen un desbordamiento de heap en el manejador del canal RAIL del lado del servidor. Un atacante remoto puede explotar esta vulnerabilidad mediante un mensaje RAIL malformado enviado a servidores RDP expuestos, causando corrupción de memoria y potencial ejecución de código arbitrario. El impacto es alta en infraestructuras de acceso remoto comunes en empresas latinoamericanas que utilizan FreeRDP como servidor de escritorio remoto.