Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1003
Esta semana
RSS
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-58095] mp_Enddisc() used incorrect length calculations when formatting endpoint discriminator addresses for…
mp_Enddisc() used incorrect length calculations when formatting endpoint discriminator addresses for display, allowing a received endpoint option to overflow a global result buffer. A malicious PPP peer can crash ppp(8) or potentially execute arbitrary code as root.
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-79130] Buffer overflow in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execut…
Buffer overflow in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
G Crítico vulnerabilidad
25/08/2026
[CVE-2026-78948] Buffer overflow in WebGL in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execut…
Buffer overflow in WebGL in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-19874] A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online 3, originating from …
A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online 3, originating from improper validation of lobby data fields related to kicked players. The affected function processes a list of kicked player identifiers using the lobby data key "kick_num" to determine the number of entries, and individual kicked player IDs supplied via keys in the format "kicked_id_%i". The functio…
M Crítico vulnerabilidad
19/08/2026
[CVE-2026-75143] FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavforma…
FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). librist_read() ignored its size argument and copied the full received payload length into the caller-provided destination buffer, overflowing it when the payload exceeds the destination size. This is reachable via the async:rist:// URL scheme, where the async wrapper supplies a smaller…
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-65791] Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execut…
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-67873] A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding…
A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occurs because FileSegment_encode() validates only the standalone segment length via FileSegment_GetMaxDataSize() and does not verify the residual capacity of the current ASDU frame before encoding object fields and segment data

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
04/08/2026
[CVE-2017-20241] Keysight IxChariot Endpoint before 9.5.102 contains a heap-based buffer overflow. An unauthenticated…
Keysight IxChariot Endpoint before 9.5.102 contains a heap-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpoint or potentially execute arbitrary code.
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17758] Heap buffer overflow in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to po…
Heap buffer overflow in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17680] Heap buffer overflow in Color in Google Chrome on ChromeOS prior to 151.0.7922.72 allowed a remote a…
Heap buffer overflow in Color in Google Chrome on ChromeOS prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-67191] Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that…
Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unauthenticated attackers to write past the end of a heap buffer by sending a malformed SSH client identification string. A logic error in the recv loop's termination condition uses an incorrect OR operator where an AND operator is required, enabling exploitation on any SSH or SFTP co…
A Crítico vulnerabilidad
27/07/2026
[CVE-2026-55971] Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache T…
Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-56165] Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over…
Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.
N Crítico vulnerabilidad
20/07/2026
[CVE-2026-41252] xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds check in xrdp,…
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds check in xrdp, which allows a heap-based buffer overflow when operating in vnc-any mode. The issue occurs during the handling of RFB protocol color map messages from a VNC server, where incoming color indices are not properly validated. A malicious VNC server can exploit this flaw by sending crafted messages with…
F Crítico vulnerabilidad
20/07/2026
[CVE-2026-64620] FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common…
FreeRDP before 3.28.0 (affected

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-56159] Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code ov…
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-55010] Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to …
Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-50518] Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code ov…
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-50447] Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute cod…
Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-50380] Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a ne…
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.