Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,394
Total alertas
3047
Críticas
10075
Altas
8
Ransomware
1741
Esta semana
RSS
M Crítico vulnerabilidad Nuevo
Hace 2 horas
[CVE-2026-78169] A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the functio…
A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file /goform/aspRemoteApConfTempSend of the component HTTP Request Handler. Performing a manipulation of the argument Profile results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.
M Alto vulnerabilidad Nuevo
Hace 2 horas
[CVE-2026-78170] A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the…
A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formConfigFastDirectionW. Executing a manipulation of the argument ssid can lead to buffer overflow. The attack may be performed from remote. The exploit has been published and may be used.
M Alto vulnerabilidad Nuevo
Hace 3 horas
[CVE-2026-78161] A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function report_raw_cbor o…
A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function report_raw_cbor of the file lib/misc/lecp.c of the component LECP CBOR Recording. The manipulation results in out-of-bounds write. The attack can be launched remotely. The exploit has been made public and could be used. The patch is identified as 1d44554a1bb262db63ff4e240152a9deecd99054. It is best practice to apply…
M Alto vulnerabilidad Nuevo
Hace 3 horas
[CVE-2026-78157] A vulnerability was detected in Open5GS 2.8.0. This affects the function pcrf_rx_aar_cb of the file …
A vulnerability was detected in Open5GS 2.8.0. This affects the function pcrf_rx_aar_cb of the file src/pcrf/pcrf-rx-path.c of the component Rx AA-Request Handler. Performing a manipulation results in out-of-bounds read. It is possible to initiate the attack remotely. The patch is named c18dc6938bf63cc7374315d3dca303d92066e746. To fix this issue, it is recommended to deploy a patch.
M Alto vulnerabilidad Nuevo
Hace 4 horas
[CVE-2026-78156] A security vulnerability has been detected in Open5GS 2.8.0. Affected by this issue is the function …
A security vulnerability has been detected in Open5GS 2.8.0. Affected by this issue is the function hss_ogs_diam_s6a_air_cb of the file src/hss/hss-s6a-path.c of the component S6a Authentication-Information-Request Handler. Such manipulation of the argument Visited-PLMN-Id leads to heap-based buffer overflow. The attack may be performed from remote. The name of the patch is a9c82ee0b590d76a581b058…
M Crítico vulnerabilidad
Hace 1 día
Desbordamiento de búfer en Comfast CF-N1-S 2.6.0 permite ejecución remota de código
Se identificó una vulnerabilidad crítica (CVSS 9.9) en enrutadores Comfast CF-N1-S versión 2.6.0.1 en el componente de administración web. Un atacante remoto puede explotar un desbordamiento de búfer en la pila mediante manipulación de los parámetros timestr/ntp_client_enabled en la función /cgi-bin/mbox-config para ejecutar código arbitrario. El exploit es público y activamente utilizado en ataques.
M Crítico vulnerabilidad
Hace 1 día
Vulnerabilidad crítica de desbordamiento de búfer en TRENDnet TEW-821DAP 2.2.01b05
Se identificó una vulnerabilidad de severidad crítica (CVSS 10.0) en el manejador de configuración NTP del dispositivo TRENDnet TEW-821DAP versión 2.2.01b05. Un atacante puede manipular parámetros de zona horaria y servidores NTP a través del archivo /cgi-bin/apply_time.cgi para provocar un desbordamiento de búfer en la pila de memoria. Esta vulnerabilidad afecta principalmente a pequeñas y medianas empresas en LATAM que utilizan estos enrutadores/puntos de acceso en infraestructuras de red crítica sin internet directo.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-77148] A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the fi…
A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-config?method=SET&section=ptest_channel of the component Web Management. The manipulation results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-77022] A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the functi…
A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component SSID Configuration. The manipulation of the argument ssid results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-18294] OriginLab Origin Viewer OGW File Parsing Memory Corruption Remote Code Execution Vulnerability. This…
OriginLab Origin Viewer OGW File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of O…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-18291] OriginLab OriginPro OGW File Parsing Memory Corruption Remote Code Execution Vulnerability. This vul…
OriginLab OriginPro OGW File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of OGW files…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-18292] OriginLab OriginPro OGG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vul…
OriginLab OriginPro OGG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro . User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of OGG file…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-76987] A security flaw has been discovered in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. …
A security flaw has been discovered in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. The impacted element is the function CipAttribute::GetAttrData/CipAttribute::SetAttrData of the file ciptypes.h of the component Generic Attribute Logic. Performing a manipulation results in memory corruption. It is possible to initiate the attack remotely. The exploit has been released to the publi…
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-76589] A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the function FUN_401000 …
A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the function FUN_401000 of the file /sbin/mycli. The manipulation of the argument ssid results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used.
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-76590] A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some …
A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some unknown functionality of the file /cgi-bin/wan.cgi of the component ssi. Such manipulation of the argument cameo.wan.wan_pppoe_password_00 leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-76584] A security flaw has been discovered in TRENDnet TV-IP751WIC 11.03.03. Affected by this issue is some…
A security flaw has been discovered in TRENDnet TV-IP751WIC 11.03.03. Affected by this issue is some unknown functionality of the file /cgi-bin/admin/set_time.cgi of the component alphapd. The manipulation of the argument Currenttime results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-20319] As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Wo…
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20319 are related to buffer management issues that are groupe…
M Crítico vulnerabilidad
Hace 5 días
Vulnerabilidad crítica en Comfast CF-N1-S 2.6.0.1 permite desbordamiento de búfer remoto
Se ha identificado una falla de seguridad crítica (CVSS 10.0) en el dispositivo Comfast CF-N1-S versión 2.6.0.1 que afecta el procesamiento de parámetros URI en /cgi-bin/mbox-config. Un atacante remoto puede explotar un desbordamiento de búfer en la pila mediante manipulación de los parámetros width/height, comprometiendo completamente la integridad del dispositivo. Empresas en LATAM que utilicen estos puntos de acceso inalámbricos en infraestructura de oficinas o datos están en riesgo inmediato de intrusión no autorizada.
M Crítico vulnerabilidad
Hace 5 días
Vulnerabilidad crítica de desbordamiento de búfer en UTT HiPER 1200GW hasta versión 2.5.3-170306
Se ha identificado una debilidad en los equipos UTT HiPER 1200GW (versiones hasta 2.5.3-170306) que permite un desbordamiento de búfer basado en pila mediante manipulación remota del parámetro 'timestart' en la función strcpy del archivo /goform/formGroupConfig. Con puntuación CVSS 9.9, este dispositivo ampliamente utilizado en redes corporativas de LATAM como gateway de seguridad es vulnerable a ejecución remota de código. El exploit está disponible públicamente, elevando significativamente el riesgo de compromiso.
M Crítico vulnerabilidad
Hace 5 días
Vulnerabilidad crítica en UTT HiPER 1250GW permite ejecución remota de código (CVE-2026-76004)
Se ha identificado una vulnerabilidad de desbordamiento de búfer en la pila (stack-based buffer overflow) en UTT HiPER 1250GW versiones hasta 3.2.7-210907-180535. El fallo existe en el manejador HTTP del formulario /goform/aspApBasicConfigUrcp y puede ser explotado remotialmente sin autenticación manipulando el parámetro pvid. El exploit está públicamente disponible, poniendo en riesgo crítico los equipos desplegados en infraestructuras de ISPs, centros de datos y operadores de telecomunicaciones en América Latina.