Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1018
Esta semana
RSS
M Alto vulnerabilidad
27/09/2026
[CVE-2026-96280] The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functio…
The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functions expecting gsize (32 bits on 32-bit systems), causing undersized allocations while subsequent operations use the original 64-bit size, leading to heap buffer overflows. An attacker controlling an OCI registry can craft a delta stream that triggers this during flatpak install/update, potentially ac…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-19667] If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 b…
If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in `named` results in a negative cache entry of 0 bytes. When this entry is subsequently read, `named` aborts. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-78512] Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code ov…
Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69822] Numeric truncation error in Windows Kerberos allows an authorized attacker to elevate privileges loc…
Numeric truncation error in Windows Kerberos allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69578] Numeric truncation error in Windows Kernel allows an authorized attacker to elevate privileges local…
Numeric truncation error in Windows Kernel allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69535] Numeric truncation error in Windows Spaceport.sys allows an authorized attacker to elevate privilege…
Numeric truncation error in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69512] Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privile…
Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges over a network.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
08/09/2026
[CVE-2026-68880] Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges ove…
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-73523] COVESA Open1722 through 0.9.2 contains an integer truncation vulnerability in acf-can-listener.c tha…
COVESA Open1722 through 0.9.2 contains an integer truncation vulnerability in acf-can-listener.c that allows unauthenticated remote attackers to cause the CAN listener to transmit process stack memory onto the CAN bus by sending a rejected UDP datagram with a matching AVTP stream ID. The num_can_msgs variable declared as uint8_t truncates the -1 error return value from avtp_to_can() to 255, causin…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-68804] Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code l…
Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-63525] Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code lo…
Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-62739] Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges l…
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-62698] Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate…
Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-56650] Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate p…
Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-50357] Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to ex…
Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
14/07/2026
[CVE-2026-50332] Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc…
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-49792] Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to ex…
Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
W Alto vulnerabilidad
25/06/2026
[CVE-2026-6679] A heap buffer overflow could occur in the DTLS 1.3 ACK serialization path before the connecting peer…
A heap buffer overflow could occur in the DTLS 1.3 ACK serialization path before the connecting peer is authenticated. The buffer overflow was due to an integer truncation when computing the length of the ACK record-number list, causing an undersized buffer to be allocated and then overrun. This affects builds using DTLS 1.3 and wolfSSL version 5.9.0 and earlier. A fix was added to the 5.9.1 relea…
M Alto vulnerabilidad
09/06/2026
[CVE-2026-44823] Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code l…
Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-40404] Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability