Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1012
Esta semana
RSS
M Alto vulnerabilidad
11/08/2026
[CVE-2026-63526] Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code loca…
Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-63527] Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code…
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-62877] Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges lo…
Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-62878] Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a ne…
Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-62824] Stack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code…
Stack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-62792] Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a…
Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-62768] Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges…
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
11/08/2026
[CVE-2026-62755] Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileg…
Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-59086] A vulnerability has been identified in Simcenter Nastran (All versions < V2606). The affected applic…
A vulnerability has been identified in Simcenter Nastran (All versions < V2606). The affected applications contain a stack overflow vulnerability while parsing specially strings as argument for one of the application binaries. This could allow an attacker to execute code in the context of the current process.
M Alto vulnerabilidad
09/08/2026
Vulnerabilidad alta en UTT HiPER 1200GW permite desbordamiento de búfer remoto
Se ha identificado un desbordamiento de búfer basado en stack en los modelos UTT HiPER 1200GW versiones hasta 2.5.3-170306, mediante manipulación del parámetro EncryptionMode en la función strcpy del archivo /goform/pptpSrvGlobalConfig. La vulnerabilidad permite ejecución remota de código sin autenticación previa, con CVSS 8.8. El exploit ha sido divulgado públicamente, aumentando el riesgo inmediato para equipos de red altas en LATAM que utilizan este modelo de puerta de enlace.
M Alto vulnerabilidad
07/08/2026
[CVE-2026-20345] A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attac…
A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&nbsp;memory corruption on an affected device. This vulnerability is due to improper handling of an endian conversion operation, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerab…
M Alto vulnerabilidad
05/08/2026
[CVE-2026-71265] Domoticz's MochadTCP::MatchLine() handler for MOCHAD_RFSEC messages (hardware/MochadTCP.cpp) copies …
Domoticz's MochadTCP::MatchLine() handler for MOCHAD_RFSEC messages (hardware/MochadTCP.cpp) copies network-received data from the up-to-1028-byte m_mochadbuffer into a fixed 50-byte stack buffer tempRFSECbuf using strcpy() with no length check, across three separate code branches (DS10A/KR10A/MS10A device types). An attacker on the local network segment able to reach the Mochad TCP bridge (defaul…
M Alto vulnerabilidad
05/08/2026
[CVE-2026-71266] tinyobjloader-c's tinyobj_parse_and_index_mtl_file() (tinyobj_loader_c.h) reads each line of a .mtl …
tinyobjloader-c's tinyobj_parse_and_index_mtl_file() (tinyobj_loader_c.h) reads each line of a .mtl material file into a fixed 4096-byte stack buffer `linebuf` via memcpy(linebuf, p, p_len), guarded only by `assert(p_len < 4095)`. Because assert() compiles to a no-op under -DNDEBUG (standard for release builds), a crafted .mtl file containing a line (e.g. a "newmtl" material name) longer than 4096…
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-71267] microtar's mtar_write_file_header() and mtar_write_dir_header() functions (src/microtar.c) copy a ca…
microtar's mtar_write_file_header() and mtar_write_dir_header() functions (src/microtar.c) copy a caller-supplied entry name into the 100-byte `name` field of a stack-allocated mtar_header_t via strcpy(h.name, name), with no check that strlen(name) is less than 100 before the copy. Any application that calls these functions with an externally-influenced filename longer than 99 characters (e.g. whe…
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-61486] ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issu…
** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
05/08/2026
[CVE-2026-18898] A security flaw has been discovered in UTT HiPER 1200GW up to v2.5.3-170306. This affects the functi…
A security flaw has been discovered in UTT HiPER 1200GW up to v2.5.3-170306. This affects the function strcpy of the file /goform/ConfigAdvideo. The manipulation of the argument timestart results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did n…
M Alto vulnerabilidad
05/08/2026
[CVE-2026-18895] A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function st…
A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /goform/APSecurity_5g. Performing a manipulation of the argument cipher results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respon…
M Alto vulnerabilidad
05/08/2026
[CVE-2026-18897] A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element …
A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strcpy of the file /goform/getOneApConfTempEntry. The manipulation of the argument tempName leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did no…
M Crítico vulnerabilidad
04/08/2026
[CVE-2026-45538] OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions 4.0.0 and prior, …
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions 4.0.0 and prior, processing a SIP message with a header name longer than 255 bytes causes a stack buffer overflow when sip_to_json() is called in the routing script. Function sip_to_json() (modules/sipmsgops/sipmsgops.c) copies SIP header names into a fixed 255-byte stack buffer without bounds checking, performing a…
M Crítico vulnerabilidad
04/08/2026
[CVE-2026-49435] Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauth…
Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet and execute arbitrary code with administrative privileges.