Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1023
Esta semana
RSS
M Crítico vulnerabilidad Nuevo
Hace 3 horas
[CVE-2026-15340] lwIP SMTP client does not check the size of inputs, potentially allowing a buffer overflow.
lwIP SMTP client does not check the size of inputs, potentially allowing a buffer overflow.
M Crítico vulnerabilidad
23/09/2026
[CVE-2026-6730] IBM Concert 1.0.0 through 3.0.0 is vulnerable to a buffer overflow, caused by improper bounds checki…
IBM Concert 1.0.0 through 3.0.0 is vulnerable to a buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.
M Crítico vulnerabilidad
21/09/2026
Vulnerabilidad crítica de desbordamiento de búfer en Netcore NBR200V2 1.3.241127.071246
Se ha identificado una vulnerabilidad crítica (CVSS 9.9) en el enrutador Netcore NBR200V2 versión 1.3.241127.071246. La falla existe en la función vlan_load_form_uci del archivo /usr/bin/routerd, permitiendo un desbordamiento de búfer mediante manipulación del parámetro wan_num. El ataque es remoto, el exploit está públicamente disponible y el fabricante fue notificado previamente. Esta vulnerabilidad afecta directamente a infraestructuras de conectividad en empresas mexicanas y latinoamericanas que utilizan este dispositivo como gateway de red.
M Crítico vulnerabilidad
21/09/2026
Vulnerabilidad crítica de desbordamiento de búfer en Netcore NBR200V2 (CVE-2026-94100)
Se identificó una debilidad crítica (CVSS 9.9) en el enrutador Netcore NBR200V2 versión 1.3.241127.071246 que afecta la función wan_config_set_vlan del componente de reconfiguración VLAN WAN. Un atacante remoto puede manipular el parámetro vlan_wanX.ports para provocar un desbordamiento de búfer y potencialmente ejecutar código arbitrario. El exploit está disponible públicamente, aumentando significativamente el riesgo para dispositivos expuestos en redes corporativas e ISPs de la región.
M Crítico vulnerabilidad
19/09/2026
Vulnerabilidad crítica de desbordamiento de búfer en router Totolink A3002MU
Se ha descubierto una falla de seguridad crítica (CVSS 10.0) en el router Totolik A3002MU versión Hh-B20211125.1046 que permite desbordamiento de búfer remoto a través del parámetro submit-url en la función formWlWds. El exploit está disponible públicamente, aumentando significativamente el riesgo de compromiso en infraestructuras de pequeñas y medianas empresas en Latinoamérica que utilizan este dispositivo como gateway de red.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-93739] A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function form…
A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation of the argument submit-url can lead to buffer overflow. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-93740] A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formW…
A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-93738] A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSched…
A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boafrm/formSchedule. Performing a manipulation of the argument webpage results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-55209] resdata is software for reading and writing result files from the Eclipse reservoir simulator. Prior…
resdata is software for reading and writing result files from the Eclipse reservoir simulator. Prior to 6.2.9, resdata insufficiently validates numeric fields, grid dimensions, keyword sizes, and array indexes while parsing untrusted GRDECL files in lib/resdata/rd_kw_grdecl.cpp and lib/resdata/rd_grid.cpp. Malformed COORD, ZCORN, CORSNUM, ACTNUM, or MAPAXES data can reach rd_grid_alloc_GRDECL_kw__…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-90608] A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function fo…
A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function formPortFw of the file /boafrm/formPortFw of the component boa. This manipulation of the argument service_type causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may be used.
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-90607] A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNew…
A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNewSchedule of the file /boafrm/formNewSchedule of the component boa. The manipulation of the argument submit-url results in buffer overflow. The attack may be performed from remote. The exploit is now public and may be used.
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-90605] A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the…
A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6addr can lead to buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-90606] A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects…
A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the file /boafrm/formIpv6Setup of the component boa. The manipulation of the argument static_ipv6 leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-87931] A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearabl…
A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple Notification Center Service Event Handler. The manipulation leads to buffer overflow. The attack must be carried out from within the local network. The vendor was contacted early about this disclosure but did not respond in any…