Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Multiple Vendors" — 3573 resultados ✕ Limpiar búsqueda
22,340
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1210
Esta semana
RSS
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-90037] In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-…
In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during close_lru reaping An nfs4_openowner left on nn->close_lru after its final CLOSE keeps its last closed stateid in oo_last_closed_stid, holding only a raw pointer to its nfs4_client. The laundromat reaps timed-out entries, drops nn->client_lock, and calls nfs4_put_stid(), which dereferenc…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-90011] In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Reserve a …
In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Reserve a terminator byte for the login payload iscsi_target_check_login_request() rejects a login PDU whose DataSegmentLength exceeds MAX_KEY_VALUE_PAIRS, but the test is '>' and login->req_buf is allocated with exactly MAX_KEY_VALUE_PAIRS bytes. Since iscsit_get_login_rx() receives payload_length + padding…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-90012] In the Linux kernel, the following vulnerability has been resolved: spi: Fix DMA mapping ownership …
In the Linux kernel, the following vulnerability has been resolved: spi: Fix DMA mapping ownership on partial map failure If RX mapping fails after TX mapping succeeds, __spi_map_msg() unmaps TX but leaves tx_sg_mapped set. If TX mapping fails on a later transfer, mappings created for earlier transfers remain active. In both cases, cur_{tx,rx}_dma_dev have not yet been updated because they are …
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-89990] In the Linux kernel, the following vulnerability has been resolved: ceph: lock mutex in ceph_mds_ch…
In the Linux kernel, the following vulnerability has been resolved: ceph: lock mutex in ceph_mds_check_access() MDS session OPEN handling replaces mdsc->s_cap_auths under mdsc->mutex, freeing the previous array and its strings. ceph_mds_check_access() traverses this array without holding the mutex. A concurrent session reopen can therefore free the array while it is being inspected, resulting …
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-89969] In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix out-of-bounds wr…
In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix out-of-bounds write when receiving an over-long PDU nvmet_tcp_try_recv_pdu() reads a PDU header into the fixed 128-byte queue->pdu union, then computes the remaining payload length as queue->left = hdr->hlen - queue->offset + hdgst; and reads that many more bytes into &queue->pdu + queue->offset, without ever b…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-89970] In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: Synchronize timeout…
In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: Synchronize timeout work during SQ teardown nvmet_auth_sq_free() cancels auth_expired_work with cancel_delayed_work(). If the work has already started, cancellation does not wait for the callback. Transport teardown can consequently free or reuse the queue containing struct nvmet_sq while nvmet_auth_expired_work() st…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-89972] In the Linux kernel, the following vulnerability has been resolved: nvme: add missing SRCU grace pe…
In the Linux kernel, the following vulnerability has been resolved: nvme: add missing SRCU grace period in error path nvme_alloc_ns() error path at out_unlink_ns removes ns from the namespace head siblings list with list_del_rcu(&ns->siblings) but does not wait for SRCU readers before freeing the namespace struct. Multipath code iterates the head->list under srcu_read_lock() in nvme_find_path() …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-89930] In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Service local TLB fl…
In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Service local TLB flushes on failed nested VM-Enter KVM services local TLB flushes on "full" nested VM-Exits (through __nested_vmx_vmexit()), but not if a nested VM-Enter fails (e.g. due to failed VMCS checks in nested_vmx_enter_non_root_mode()). However, it is possible that KVM had queued TLB flushes that need to be…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-89914] In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Sign-extend VA for …
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Sign-extend VA for range-based TLBI invalidation When the decode_range_tlbi() helper was moved to be used for S1 TLBIs, the required sign extension was omitted. Add it. As a result, special care must be taken to not overflow PA bits when this is used for S2 invalidation.
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-89915] In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Remove VM-wide VNCR…
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Remove VM-wide VNCR mapping counter The global VNCR mapping counter is used to decide whether an L1 provided VNCR page is mapped in L0 on any CPU at the point of dealing with a TLB invalidation. It is incremented when a mapping is made in the fixmap, and decremented when unmapped. As it turns out, this tracking has …
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-89916] In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Make VNCR invalidat…
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Make VNCR invalidation participate in MMU invalidation retry A VNCR TLB invalidation can occur on one vcpu while another vcpu is faulting in this same page. Without correctly handling this, we can end up with the following scenario: - vcpu A walks the PTs to translate VNCR - before vcpu A is able to grab the MMU loc…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-89918] In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Correctly handle en…
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Correctly handle end of VA space TLBI invalidation Our TLB invalidation by VA code is based on comparing two ranges, one defined by the TLB, and one defined by the TLBI instruction. Each range is defined by a start and a size. However, the way the comparison is done doesn't account for address rollover, as it compar…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-89857] In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Hold qpair lock …
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject qla_nvme_ls_reject_iocb() allocates from and advances the request ring through __qla2x00_alloc_iocbs() (which assumes the hardware_lock is held) and qla2x00_start_iocbs() (which advances the ring and rings the request-in doorbell), but takes no lock itself. Two of its ca…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-89846] In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Bound rsp_info_l…
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read In qla2x00_status_entry(), the FWI2 status path advances sense_data and shrinks par_sense_len by rsp_info_len: if (IS_FWI2_CAPABLE(ha)) { sense_data += rsp_info_len; par_sense_len -= rsp_info_len; } rsp_info_len is a 32-bit value taken directly from the targe…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-89847] In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Avoid double com…
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Avoid double completion in async IOCB timeout qla2x00_async_iocb_timeout() tries to abort a timed-out async IOCB. When qla24xx_async_abort_cmd() fails, both the SRB_LOGIN_CMD path and the SRB_CTRL_VP/default path scan outstanding_cmds[] for the SRB and then call sp->done(sp, QLA_FUNCTION_TIMEOUT) unconditionally, …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
16/09/2026
CVE-2026-86106: Ejecución remota no autenticada en unidades Edge con Alta Disponibilidad
Una vulnerabilidad crítica (CVSS 9.6) permite a actores no autenticados con acceso a la interconexión privada de HA activar funciones sensibles sin verificación, resultando en ejecución de comandos elevados en unidades Edge donde HA está habilitada. Afecta principalmente a infraestructuras de borde en centros de datos y cloud híbrido en LATAM.
M Crítico vulnerabilidad
16/09/2026
Vulnerabilidad crítica en Arista EOS con P4Runtime permite ejecución remota de código
Una vulnerabilidad de puntuación CVSS 10 en Arista EOS permite que clientes no autenticados ejecuten código arbitrario con privilegios administrativos en switches configurados con P4Runtime. Aunque P4Runtime está deshabilitado por defecto, equipos que lo han activado para programabilidad de red enfrentan riesgo crítico. Esta falla afecta especialmente a proveedores de servicios y operadores de centros de datos en Latinoamérica que utilizan infraestructura Arista.
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-89786] In the Linux kernel, the following vulnerability has been resolved: ext4: fix out-of-bounds read in…
In the Linux kernel, the following vulnerability has been resolved: ext4: fix out-of-bounds read in ext4_read_inline_dir() ext4_read_inline_dir() can read a dirent header past the end of its inline buffer, triggering a slab-out-of-bounds read during getdents64(): BUG: KASAN: slab-out-of-bounds in __ext4_check_dir_entry Read of size 2 at addr ffff88800f3dd23c by task exploit/148 ... __…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-89788] In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix tree connection use-…
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix tree connection use-after-free in smb2_tree_connect() ksmbd_tree_conn_connect() publishes a new tree connection in sess->tree_conns with a single reference and returns its pointer to smb2_tree_connect(). The handler continues to initialize the object and build the response after publication. A concurrent session logof…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-89778] In the Linux kernel, the following vulnerability has been resolved: isofs: fix out-of-bounds page a…
In the Linux kernel, the following vulnerability has been resolved: isofs: fix out-of-bounds page array access on empty zisofs block zisofs_uncompress_block()'s empty-block fast path returns pcount