Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "X" — 3572 resultados ✕ Limpiar búsqueda
22,417
Total alertas
4761
Críticas
17025
Altas
8
Ransomware
1261
Esta semana
RSS
M Crítico vulnerabilidad
25/07/2026
[CVE-2026-64383] In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in…
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_flush() replay SMB2_flush() keeps its response buffer bookkeeping across replay attempts. If a replayable flush response is received and the retry then fails before cifs_send_recv() stores a replacement response, flush_exit will free the stale response pointer a second time. Reinitialize res…
M Crítico vulnerabilidad
25/07/2026
[CVE-2026-64384] In the Linux kernel, the following vulnerability has been resolved: smb: client: fix change notify …
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix change notify replay double-free A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_notify_init() fails before the next send, cleanup retains the previous buffer type and frees that response again. Reset response bookkeeping before each attempt to prevent the stale fr…
M Crítico vulnerabilidad
25/07/2026
[CVE-2026-64385] In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in…
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_ioctl() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_ioctl_init() fails before the next send, cleanup retains the previous buffer type and frees that response again. Reset response bookkeeping before each attempt to prevent the stale f…
M Crítico vulnerabilidad
25/07/2026
[CVE-2026-64386] In the Linux kernel, the following vulnerability has been resolved: smb: client: fix query_info() r…
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix query_info() replay double-free A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_query_info_init() fails before the next send, cleanup retains the previous buffer type and frees that response again. Reset response bookkeeping before each attempt to prevent the stale…
M Crítico vulnerabilidad
25/07/2026
[CVE-2026-64355] In the Linux kernel, the following vulnerability has been resolved: bpf: Reject fragmented frames i…
In the Linux kernel, the following vulnerability has been resolved: bpf: Reject fragmented frames in devmap Devmap broadcast redirects clone the packet for all but the last destination. For native XDP, that clone path copies only the linear xdp_frame data, while fragmented frames keep skb_shared_info in tailroom outside the linear area. Cloning such a frame leaves XDP_FLAGS_HAS_FRAGS set but wi…
M Crítico vulnerabilidad
25/07/2026
[CVE-2026-64319] In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: validate reply mess…
In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: validate reply message payload bounds against transfer length nvmet_auth_reply() accesses the variable-length rval[] array using attacker-controlled hl (hash length) and dhvlen (DH value length) fields without verifying they fit within the allocated buffer of tl bytes. A malicious NVMe-oF initiator can craft a DHCHA…
M Crítico vulnerabilidad
25/07/2026
[CVE-2026-64320] In the Linux kernel, the following vulnerability has been resolved: nvmet: fix pre-auth out-of-boun…
In the Linux kernel, the following vulnerability has been resolved: nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page nvmet_execute_disc_get_log_page() validates only the dword alignment of the host-supplied Log Page Offset (lpo). The 64-bit offset is then added to a small kzalloc'd buffer that holds the discovery log page and the result is passed straight to nvmet_copy_to_s…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
25/07/2026
[CVE-2026-64303] In the Linux kernel, the following vulnerability has been resolved: spi: fsl-lpspi: terminate the R…
In the Linux kernel, the following vulnerability has been resolved: spi: fsl-lpspi: terminate the RX channel on TX prepare failure path When dmaengine_prep_slave_sg() fails for the TX channel, the error path terminates the TX DMA channel but leaves the RX channel running. Since the RX channel was already submitted and issued prior to preparing the TX descriptor, returning -EINVAL causes the SPI …
M Crítico vulnerabilidad
25/07/2026
[CVE-2026-64268] In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: bound Read Response p…
In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: bound Read Response placement to the RREAD length In drivers/infiniband/sw/siw/siw_qp_rx.c, siw_proc_rresp() places each inbound Read Response DDP segment at sge->laddr + wqe->processed and then accumulates wqe->processed, but it never checks the running total against the sink buffer length on continuation segments. si…
M Crítico vulnerabilidad
25/07/2026
[CVE-2026-64269] In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Bound RDMA-Write…
In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg When the server answers an RTRS READ, rdma_write_sg() builds the source scatter/gather entry for the IB_WR_RDMA_WRITE that returns data to the peer. Its length is taken directly from the wire descriptor: plist->length = le32_to_cpu(id->rd_msg->desc[0].len);…
M Crítico vulnerabilidad
25/07/2026
[CVE-2026-64257] In the Linux kernel, the following vulnerability has been resolved: smb: client: reject overlapping…
In the Linux kernel, the following vulnerability has been resolved: smb: client: reject overlapping data areas in SMB2 responses Commit 53b7c271f06b ("smb: client: restrict implied bcc[0] exemption to responses without data area") restricted the implied bcc[0] length exception to responses without a data area. However, the overlap handling in __smb2_calc_size() clears data_length, which can make…
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-64232] In the Linux kernel, the following vulnerability has been resolved: block: recompute nr_integrity_s…
In the Linux kernel, the following vulnerability has been resolved: block: recompute nr_integrity_segments in blk_insert_cloned_request blk_insert_cloned_request() already recomputes nr_phys_segments against the bottom queue, because "the queue settings related to segment counting may differ from the original queue." The exact same reasoning applies to integrity segments: a stacked driver's unde…
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-64216] In the Linux kernel, the following vulnerability has been resolved: netfs: Fix potential UAF in net…
In the Linux kernel, the following vulnerability has been resolved: netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages() netfs_unlock_abandoned_read_pages(rreq) accesses the index of the folios it is wanting to unlock and compares that to rreq->no_unlock_folio so that it doesn't unlock a folio being read for netfs_perform_write() or netfs_write_begin(). However, given that netfs_unlo…
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-16634] TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99. The…
TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99. The tomlc99 library is no longer maintained, and has an uncontrolled recursion vulnerability publicly reported in the issue tracker. Any caller that passes untrusted TOML to from_toml risks a stack overflow from a deeply-nested document. TOML::XS version 0.06 or later uses the successor tomlc17 libra…
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-15704] In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vuln…
In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by inconsistent trailing-slash handling between the ABAC middleware and the HTTP router. The shared router configuration used Chi's `middleware.StripSlashes`, so a request such as `GET /shells/` was dispatched to the registered `GET /shells` route. However…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-12877] The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not saniti…
The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. This is exploitable in the Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0's standard front-end issue-tracker configuration.
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-56191] Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tamp…
Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-56165] Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over…
Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-54120] Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a …
Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-50517] Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over…
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.