Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "X" — 2315 resultados ✕ Limpiar búsqueda
13,538
Total alertas
3074
Críticas
10192
Altas
8
Ransomware
1802
Esta semana
RSS
M Crítico vulnerabilidad
Hace 5 días
Vulnerabilidad crítica de desbordamiento de búfer en UTT HiPER 1200GW hasta versión 2.5.3-170306
Se ha identificado una debilidad en los equipos UTT HiPER 1200GW (versiones hasta 2.5.3-170306) que permite un desbordamiento de búfer basado en pila mediante manipulación remota del parámetro 'timestart' en la función strcpy del archivo /goform/formGroupConfig. Con puntuación CVSS 9.9, este dispositivo ampliamente utilizado en redes corporativas de LATAM como gateway de seguridad es vulnerable a ejecución remota de código. El exploit está disponible públicamente, elevando significativamente el riesgo de compromiso.
M Crítico vulnerabilidad
Hace 5 días
Vulnerabilidad crítica en UTT HiPER 1250GW permite ejecución remota de código (CVE-2026-76004)
Se ha identificado una vulnerabilidad de desbordamiento de búfer en la pila (stack-based buffer overflow) en UTT HiPER 1250GW versiones hasta 3.2.7-210907-180535. El fallo existe en el manejador HTTP del formulario /goform/aspApBasicConfigUrcp y puede ser explotado remotialmente sin autenticación manipulando el parámetro pvid. El exploit está públicamente disponible, poniendo en riesgo crítico los equipos desplegados en infraestructuras de ISPs, centros de datos y operadores de telecomunicaciones en América Latina.
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-75976] A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. Impacted is the function strcpy of …
A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. Impacted is the function strcpy of the file /cgi-bin/wan.cgi of the component NVRAM. This manipulation of the argument wan_l2tp_password causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-73930] Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).…
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of…
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-73921] Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).…
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.20. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity a…
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-73922] Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).…
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data o…
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-73924] Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).…
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data o…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-73912] Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).…
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity an…
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-73916] Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).…
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data o…
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-73917] Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).…
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or…
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-73920] Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).…
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or…
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-73905] Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).…
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity an…
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-71167] Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).…
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or…
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-73865] Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).…
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data o…
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-73866] Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).…
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-71164] Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).…
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity a…
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-71166] Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).…
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data o…
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-71152] Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).…
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity an…
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-71102] Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions t…
Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Portable Clusterware. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification …
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-71074] Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).…
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity a…