Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1778
Esta semana
RSS
M Alto vulnerabilidad
Hace 1 día
Vulnerabilidad alta en strongSwan anterior a 6.0.7: doble liberación de memoria en análisis de identidades EAP
strongSwan antes de la versión 6.0.7 presenta un defecto en el manejo de análisis y clonación de identidades EAP que genera una condición de doble liberación de memoria (double-free). Esto afecta principalmente a servidores VPN y de autenticación en infraestructuras corporativas de LATAM que utilizan este software de código abierto para IPsec. Un atacante remoto autenticado podría explotar esta vulnerabilidad para causar denegación de servicio o potencialmente ejecutar código arbitrario.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-65780] Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-62889] Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to ex…
Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-62766] Double free in Windows Kerberos allows an authorized attacker to elevate privileges locally.
Double free in Windows Kerberos allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-61366] Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges…
Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
07/08/2026
[CVE-2026-20338] A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker …
A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in zip files during scanning. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to …
M Alto vulnerabilidad
06/08/2026
[CVE-2026-43622] llama.cpp builds b1886 through b7445 contain a double free vulnerability in the LLaMA-Android JNI wr…
llama.cpp builds b1886 through b7445 contain a double free vulnerability in the LLaMA-Android JNI wrapper where new_1batch() allocates memory using malloc() while free_1batch() deallocates it using the C++ delete operator, causing heap metadata corruption. Attackers can trigger this memory management mismatch to cause denial of service through process crashes or potentially achieve arbitrary code …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
25/07/2026
[CVE-2026-66373] Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows …
Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.
M Alto vulnerabilidad
24/07/2026
[CVE-2026-66032] libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_op…
libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call retur…
M Alto vulnerabilidad
23/07/2026
[CVE-2026-43823] When initializing an RSA public key from DER or PEM bytes throws an error, the EVP_PKEY* is double-f…
When initializing an RSA public key from DER or PEM bytes throws an error, the EVP_PKEY* is double-freed: first in the catch block, then in the deinit. This can lead to a crash on future memory allocations. This double-free manifests when BoringSSL cannot decode the public key from the bytes provided. This vulnerability is addressed in swift-crypto version 4.5.1.
F Alto vulnerabilidad
22/07/2026
[CVE-2026-64832] FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware d…
FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path frees memory via nvdec_fdd_priv_free while the calling layer subsequently frees the same frame descripti…
F Alto vulnerabilidad
20/07/2026
[CVE-2026-64621] FreeRDP before 3.28.0 (affected 3.x through 3.27.1) contains a double-free vulnerability in freerdp_…
FreeRDP before 3.28.0 (affected 3.x through 3.27.1) contains a double-free vulnerability in freerdp_client_rdp_file_apply_to_settings() (client/common/file.c) when parsing the selectedmonitors field of a .rdp connection file. The MonitorIds array is allocated through the settings object, and a raw non-owning pointer to it is freed on the strtoul error path without clearing settings->MonitorIds, le…
M Alto vulnerabilidad
14/07/2026
[CVE-2026-55132] Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-50685] Double free in Windows DHCP Server allows an authorized attacker to execute code over a network.
Double free in Windows DHCP Server allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-50361] Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges l…
Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
14/07/2026
[CVE-2026-55004] Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally…
Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.
H Crítico vulnerabilidad
03/07/2026
[CVE-2026-8925] The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice…
The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer twice.
M Alto vulnerabilidad
30/06/2026
[CVE-2026-14164] A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially c…
A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent processing of another archive entry can trigger a second free of the same memory region, resulting in a double-free condition. Successful exploitation may cause applic…
L Alto vulnerabilidad
26/06/2026
[CVE-2026-53322] In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Clean up DMABUFs befo…
In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Clean up DMABUFs before disabling function On device shutdown, make vfio_pci_core_close_device() call vfio_pci_dma_buf_cleanup() before the function is disabled via vfio_pci_core_disable(). This ensures that all access via DMABUFs is revoked before the function's BARs become inaccessible. This fixes an issue where, i…
L Alto vulnerabilidad
26/06/2026
[CVE-2026-53294] In the Linux kernel, the following vulnerability has been resolved: mailbox: mailbox-test: don't fr…
In the Linux kernel, the following vulnerability has been resolved: mailbox: mailbox-test: don't free the reused channel The RX channel can be aliased to the TX channel if it has a different MMIO. This special case needs to be handled when freeing the channels otherwise a double-free occurs.