Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 36 min
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
08/09/2026
[CVE-2026-68775] Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a networ…
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-67631] Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a networ…
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-67388] Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a networ…
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-67380] Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a networ…
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-67381] Heap-based buffer overflow in SQL Server allows an authorized attacker to elevate privileges over a …
Heap-based buffer overflow in SQL Server allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-67384] Integer overflow or wraparound in SQL Server allows an authorized attacker to execute code over a ne…
Integer overflow or wraparound in SQL Server allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-67373] Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a networ…
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
08/09/2026
[CVE-2026-62810] Heap-based buffer overflow in Active Directory Certificate Services (AD CS) allows an authorized att…
Heap-based buffer overflow in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-62744] Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to …
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-58599] Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to ex…
Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-58600] Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to el…
Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-79377] A heap overflow in the a2dp_decoder_sbc.cpp component of Bestechnic Co., Ltd BES2300 Bluetooth Audio…
A heap overflow in the a2dp_decoder_sbc.cpp component of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows attackers to cause a Denial of Service (DoS) via sending a crafted L2CAP packet.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-20501] In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to l…
In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9197.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-20502] In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to l…
In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9196.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-81665] A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembl…
A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly. When processing fragmented multicast messages, the buffer used to reassemble fragments lacks a runtime bounds check in release builds. A network-adjacent attacker able to send crafted multicast protocol messages to the cluster could cause a heap buffer overflow with attacker-controlled data. This…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
03/09/2026
[CVE-2026-83959] Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in…
Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-78689] Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list p…
Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can trigger it when an affected NGINX configuration passes an externally controlled XML namespace prefix list to that method. Both the njs and the QuickJS (qjs) engines are affected. A crafted prefix list cau…
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84268] A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious …
A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the allocated buffer size, causing the operation to write past the intended boundaries. This issue allows a malicious server to corrup…
M Alto vulnerabilidad
28/08/2026
[CVE-2026-38821] A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenti…
A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker on the captive portal network to crash the openNDS daemon (denial of service) and potentially achieve remote code execution. This is in http_microhttpd.c.
M Alto vulnerabilidad
27/08/2026
[CVE-2026-34674] Substance3D - Sampler versions 5.1.3 and earlier are affected by a Heap-based Buffer Overflow vulner…
Substance3D - Sampler versions 5.1.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.