Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 min
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1012
Esta semana
RSS
M Crítico vulnerabilidad
18/08/2026
[CVE-2026-75783] A security vulnerability has been detected in TRENDnet TEW-WLC100P 12.07b01. Affected by this vulner…
A security vulnerability has been detected in TRENDnet TEW-WLC100P 12.07b01. Affected by this vulnerability is an unknown functionality of the file /sbin/netifd of the component DHCP blobmsg Handler. The manipulation leads to stack-based buffer overflow. The attack must be carried out from within the local network. The exploit has been disclosed publicly and may be used.
M Crítico vulnerabilidad
17/08/2026
Vulnerabilidad crítica de desbordamiento de búfer en routers Wavlink WN531P3 y WN535M1
Se identificó una vulnerabilidad de desbordamiento de búfer en la pila (stack-based buffer overflow) en los routers Wavlink WN531P3 y WN535M1 versión V250922. La falla reside en la función strcpy del componente Export Pingortrace CGI (/etc/lighttpd/www/cgi-bin/export_pingortrace.cgi) y puede ser explotada remotamente manipulando el parámetro HTTP_COOKIE. El exploit ha sido divulgado públicamente, aumentando el riesgo para infraestructuras de telecomunicaciones y empresas en LATAM que utilizan estos equipos.
M Crítico vulnerabilidad
16/08/2026
[CVE-2026-19959] A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetu…
A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetup of the file /goform/formWanTcpipSetup. This manipulation of the argument pppUserName causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclos…
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-62878] Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a ne…
Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-71267] microtar's mtar_write_file_header() and mtar_write_dir_header() functions (src/microtar.c) copy a ca…
microtar's mtar_write_file_header() and mtar_write_dir_header() functions (src/microtar.c) copy a caller-supplied entry name into the 100-byte `name` field of a stack-allocated mtar_header_t via strcpy(h.name, name), with no check that strlen(name) is less than 100 before the copy. Any application that calls these functions with an externally-influenced filename longer than 99 characters (e.g. whe…
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-61486] ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issu…
** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported …
M Crítico vulnerabilidad
04/08/2026
[CVE-2026-45538] OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions 4.0.0 and prior, …
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions 4.0.0 and prior, processing a SIP message with a header name longer than 255 bytes causes a stack buffer overflow when sip_to_json() is called in the routing script. Function sip_to_json() (modules/sipmsgops/sipmsgops.c) copies SIP header names into a fixed 255-byte stack buffer without bounds checking, performing a…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
04/08/2026
[CVE-2026-49435] Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauth…
Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet and execute arbitrary code with administrative privileges.
M Crítico vulnerabilidad
04/08/2026
[CVE-2017-20242] Keysight IxChariot Endpoint before 9.5.102 contains a stack-based buffer overflow. An unauthenticate…
Keysight IxChariot Endpoint before 9.5.102 contains a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpoint or potentially execute arbitrary code.
M Crítico vulnerabilidad
04/08/2026
[CVE-2026-25289] Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Disco…
Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.
M Crítico vulnerabilidad
03/08/2026
Vulnerabilidad crítica de desbordamiento de búfer en Wavlink WL-NU516U1 (CVE-2026-18588)
Se ha identificado una vulnerabilidad de desbordamiento de búfer en la pila (stack-based buffer overflow) en el enrutador Wavlink WL-NU516U1 versión 708c073-mt7628, específicamente en la función fgets del archivo nas.cgi. Un atacante remoto puede explotar la manipulación del parámetro CONTENT_LENGTH para ejecutar código arbitrario sin autenticación. Esta vulnerabilidad afecta principalmente a infraestructuras de PyMEs y centros de datos en LATAM que utilizan estos dispositivos como puntos de acceso o enrutadores en redes corporativas.
M Crítico vulnerabilidad
03/08/2026
Vulnerabilidad crítica de desbordamiento de búfer en Wavlink WL-NU516U1 (CVE-2026-18589)
Se identificó una vulnerabilidad de desbordamiento de búfer basado en pila en el router Wavlink WL-NU516U1 (versión 708c073-mt7628) que afecta la función de cambio de contraseña en nas.cgi. Un atacante remoto puede explotar esta falla manipulando el parámetro User1Passwd para ejecutar código arbitrario sin autenticación previa. El exploit es público y existe riesgo inmediato en infraestructuras de LATAM que utilizan este dispositivo.
M Crítico vulnerabilidad
31/07/2026
[CVE-2026-67822] Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSID…
Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer without length restriction, leading to stack overflow.
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-59144] Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalida…
Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in ring_read_seq. The attach-time validator ring_validate_header checks the capacity-overflow and total_size consistency of the header but never caps elem_size against the destination size. ring_read_seq does memcpy(out, ring_slot(h, seq), elem_size) with elem_size read raw from the m…
M Crítico vulnerabilidad
20/07/2026
[CVE-2024-51314] The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_424CE0 function of…
The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_424CE0 function of the file /goform/setMacFilterCfg.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
20/07/2026
[CVE-2024-51315] The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_425964 function of…
The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_425964 function of the file /goform/SetOnlineDevName
M Crítico vulnerabilidad
20/07/2026
[CVE-2024-51312] The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EEE0 function of…
The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EEE0 function of the file /goform/SetStaticRouteCfg.
M Crítico vulnerabilidad
20/07/2026
[CVE-2024-51311] The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the sub_4418CC function of…
The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the sub_4418CC function of the file /goform/SetNetControlList.
M Crítico vulnerabilidad
20/07/2026
[CVE-2024-51313] The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EA38 function of…
The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EA38 function of the file /goform/SetVirtualServerCfg.
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-51807] Heap-based out-of-bounds write in j2k_precinct_subband::parse_packet_header() in OpenHTJ2K versions …
Heap-based out-of-bounds write in j2k_precinct_subband::parse_packet_header() in OpenHTJ2K versions 0.18.3 and earlier (fixed in v0.18.4) caused by missing bounds validation before coding-pass lengths are written to j2k_codeblock::pass_length[128]. A crafted JPEG 2000 codestream containing malformed PPM packet headers can trigger a heap-based out-of-bounds write in j2k_precinct_subband::parse_pack…