Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1777
Esta semana
RSS
M Alto vulnerabilidad
Hace 2 días
Vulnerabilidad de referencia nula en kin-openapi afecta validación de solicitudes
kin-openapi, biblioteca Go para procesar archivos OpenAPI, presenta una vulnerabilidad (CVSS 7.5) en versiones 0.10.0 a 0.141.0 que permite un acceso a memoria nula cuando procesa campos escalares malformados en solicitudes multipart/form-data. Un atacante puede causar bloqueo de servicio contra aplicaciones que usan esta biblioteca para validación de APIs. Empresas en LATAM con servicios REST y microservicios basados en Go están en riesgo si implementan kin-openapi sin parchear.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-17165] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a NULL pointer dereference.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76928] X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-16817] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a NULL pointer dereference.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-65681] Null pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny ser…
Null pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-59132] Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a ne…
Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-48438] CAI Content Credentials is affected by a NULL Pointer Dereference vulnerability that could result in…
CAI Content Credentials is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
10/08/2026
[CVE-2026-11810] The UpdateHub firmware-update agent's probe handler (z_impl_updatehub_probe() in subsys/mgmt/updateh…
The UpdateHub firmware-update agent's probe handler (z_impl_updatehub_probe() in subsys/mgmt/updatehub/updatehub.c) parses the JSON metadata returned by the update server into a fixed two-level nested-array struct. After parsing it validates only the outer array length (objects_len != 2) and then dereferences objects[1].objects[0].objects.sha256sum via strlen() without checking that the inner obje…
M Alto vulnerabilidad
10/08/2026
Vulnerabilidad alta de denegación de servicio en FastSchema v0.15.1 permite caída del servidor
Una vulnerabilidad de desreferencia de puntero NULL en FastSchema hasta la versión 0.15.1 permite que atacantes no autenticados derriben el servidor con una única solicitud HTTP. El defecto se encuentra en la función sendOTPEmail (pkg/auth/local.go) que procesa solicitudes de recuperación de contraseña sin validar correctamente el manejo de errores, causando un pánico fatal que interrumpe toda la aplicación. Afecta particularmente a empresas en LATAM que usan FastSchema en entornos de producción para autenticación de usuarios.
M Alto vulnerabilidad
07/08/2026
Vulnerabilidad alta en Klever-Go causa denegación de servicio en nodos blockchain
Klever-Go versiones 1.7.14 a 1.7.17 son vulnerables a un pánico por null-pointer desencadenado cuando una transacción protobuf omite el sub-mensaje RawData incrustado. Un atacante puede enviar transacciones malformadas a través de la red P2P de Klever-Go para causar caída inmediata de nodos validadores. Esto afecta principalmente a operadores de nodos blockchain, exchanges cripto y plataformas DeFi en México y LATAM que ejecuten estas versiones.
M Alto vulnerabilidad
07/08/2026
[CVE-2026-48097] NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a use…
NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 have a command execution vulnerability due to unsafe use of `shell=True` with commands that rely on executable resolution through the `PATH` environment variable. An attacker controlling the execution environment can place malicious executables such as sudo ea…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-70640] llama.cpp builds b1886 through b7445 contain a race condition use-after-free vulnerability in the LL…
llama.cpp builds b1886 through b7445 contain a race condition use-after-free vulnerability in the LLaMA-Android JNI wrapper where bench_1model() and free_1context() lack synchronization, allowing Thread A to operate on freed memory while Thread B concurrently frees the llama_context. Attackers can exploit this by performing heap spray with attacker-controlled data containing a fake vtable to hijac…
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-67870] In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation …
In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with an empty targetServerUri and a non-zero targetNodeId.serverIndex, causing the target node pointer to remain NULL while execution continues.
M Alto vulnerabilidad
01/08/2026
Vulnerabilidad alta de desreferencia nula en FreeRDP 3.28.x y anteriores
FreeRDP versiones anteriores a 3.29.0 contiene una vulnerabilidad de desreferencia de puntero nulo en el manejo de solicitudes de control de dispositivos smartcard. Un atacante puede enviar peticiones IRP malformadas con datos de estado de lector truncados para causar el bloqueo del proceso. Esta vulnerabilidad afecta servidores de acceso remoto y clientes RDP en infraestructuras de LATAM que dependen de autenticación por tarjeta inteligente.
M Alto vulnerabilidad
01/08/2026
[CVE-2026-67288] FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request d…
FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. When smartcard emulation is enabled, attackers can send crafted smartcard cache requests with NULL lookup-name pointers to trigger strlen() on a null pointer, causing client process…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
30/07/2026
[CVE-2026-18064] An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) ap…
An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a separate NULL pointer dereference reachable in versions through 7.0.1. An attacker who can trigger the affected command under specific conditions could cause the HS application to crash, resulting in a denial-of-service condition and processor reset.
M Alto vulnerabilidad
29/07/2026
[CVE-2026-58161] Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handli…
Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
M Alto vulnerabilidad
28/07/2026
[CVE-2026-67184] TinyWeb through 0.0.8 contains a null pointer dereference vulnerability that allows unauthenticated …
TinyWeb through 0.0.8 contains a null pointer dereference vulnerability that allows unauthenticated remote attackers to crash worker processes by sending a malformed HTTP request line with an invalid version string. The HttpParser::execute() function fails to allocate the Url object when version parsing fails, leaving the url pointer NULL, and buildResponse() subsequently dereferences this NULL po…
M Alto vulnerabilidad
28/07/2026
[CVE-2026-47427] GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the CompletionsHandler function i…
GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the CompletionsHandler function in pkg/github/server.go accesses params.Ref without first checking whether it is nil, so a completion/complete request with a missing or empty ref field triggers a nil pointer dereference and a Go runtime panic; because the crash occurs before any authentication or token validation, any unauthenticat…
A Alto vulnerabilidad
24/07/2026
[CVE-2026-45816] NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event. This req…
NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event. This requires disabled asserts (otherwise assert would trigger before NULL dereference) and bogus (or misbehaving) controller, thus severity is low. This issue affects Apache NimBLE: through 1.9.0. Users are recommended to upgrade to version 1.10.0, which fixes the issue.