Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1003
Esta semana
RSS
M Alto vulnerabilidad
29/09/2026
[CVE-2026-92368] TeamViewer Full Client and Host for Linux and macOS prior version 15.82 contain a heap-based buffer …
TeamViewer Full Client and Host for Linux and macOS prior version 15.82 contain a heap-based buffer overflow vulnerability in the processing of .tvs session recording files. A size mismatch during decompression of recorded session data can result in out-of-bounds heap writes. By convincing a user to open a specially crafted session recording through the "Play or convert recorded session…" feature,…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-95389] Caída del disector SCTP permite denegación de servicio en versiones 4.4.0-4.4.18 y 4.6.0-4.6.8
Una vulnerabilidad en el disector del protocolo SCTP permite que un atacante remoto provoque un bloqueo de servicio mediante paquetes especialmente crafteados. Afecta infraestructuras de telecomunicaciones, proveedores de VoIP y sistemas de comunicaciones altas en LATAM. Con CVSS 8.1, el riesgo es significativo para operadores de red y centros de datos.
M Alto vulnerabilidad
29/09/2026
Falla alta en disector SPDY permite denegación de servicio (CVE-2026-95387)
Una vulnerabilidad en el disector del protocolo SPDY afecta versiones 4.6.0 a 4.6.8 y 4.4.0 a 4.4.18, permitiendo ataques de denegación de servicio (DoS) con puntuación CVSS 8.1. El exploit puede derribar servicios de análisis de tráfico y monitoreo de red altas en infraestructuras empresariales de LATAM que utilicen estas versiones. La explotación remota sin autenticación representa riesgo significativo para disponibilidad operacional.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-75649] Bridge is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code…
Bridge is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-75665] Bridge is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code…
Bridge is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-94127] When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific mal…
When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software version…
M Crítico vulnerabilidad
22/09/2026
[CVE-2016-15059] Net::IDN::Punycode versions before 2.301 for Perl allow a heap buffer overflow via unchecked writes …
Net::IDN::Punycode versions before 2.301 for Perl allow a heap buffer overflow via unchecked writes past the output buffer in encode_punycode. The XS backend builds the encoded label in the string buffer of the scalar it returns, sized from the input length. The loop that emits the digits of each code point checks for room before every write, but the write of the last digit of each round and the …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
21/09/2026
[CVE-2026-94424] A vulnerability has been found in Moore Threads MTT S80 Driver Package up to 340.150. Impacted is th…
A vulnerability has been found in Moore Threads MTT S80 Driver Package up to 340.150. Impacted is the function sub_140001000 in the library mtdispkm64.sys of the component IOCTL Handler. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The vendor was contacted early about this disclosure but did not respond in any way.
M Alto vulnerabilidad
21/09/2026
[CVE-2026-88806] A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbG…
A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map.
M Alto vulnerabilidad
20/09/2026
[CVE-2026-93962] A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element …
A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP Diameter Receiver. Executing a manipulation can lead to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. Up…
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-58264] FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6…
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6, the FluidSynth command handler accepts a pitch_bend_range command whose channel argument is not bounds checked before the supplied value is written through the selected synth channel. An out-of-range channel can therefore cause an out-of-bounds heap write, leading to denial of service or possible …
M Alto vulnerabilidad
18/09/2026
[CVE-2026-61714] FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6…
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6, configuring synth.midi-channels above 16 allows the MIDI player to index _fluid_player_t::channel_isplaying outside its fixed-size heap allocation while tracking active channels. The resulting out-of-bounds reads and writes invoke undefined behavior and may compromise confidentiality, integrity, o…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-61721] FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6…
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS loader assigns file-controlled wsmp.loop_start and wsmp.loop_length values to samples without calling fluid_sample_validate() or fluid_sample_sanitize_loop(). A crafted DLS file can place sample loop points beyond the sample buffer, causing out-of-bounds reads during audio rendering…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-11727] IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remote attacker to cause…
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of queue manager responses when requesting AMS policy data.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-11716] IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denia…
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code during queue manager startup due to improper validation of cluster migration data.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
18/09/2026
[CVE-2026-46655] virtio-win provides Windows paravirtualized drivers for QEMU and KVM. From mm210 until mm320, the Vi…
virtio-win provides Windows paravirtualized drivers for QEMU and KVM. From mm210 until mm320, the Viosock driver permits a low-privilege local process to submit an IOCTL_SELECT request with attacker-controlled VIRTIO_VSOCK_SELECT.Fdss[*].fd_count values that overflow the 32-bit sum used by VIOSockSelect for bounds checking. The wrapped sum can pass the FD_SETSIZE check even though an individual de…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-67549] OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format…
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.1.16.0, A crafted 1-bit contiguous cmyk tiff is exposed through a native uint1 imagespec, so callers allocate a bit-packed buffer. tiffinput::read_native_scanline_locked() nevertheless invokes tiffinput::bit_convert() with 8-bit output and writes one expanded…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-63422] OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format…
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A valid tiled openexr image whose width is not a multiple of its tile width can trigger an overflow when a caller reads a partial edge-tile rectangle. openexrinput::read_native_tiles() copies each row into the caller buffe…
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-10858] IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denia…
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer underflow when processing multi-segment messages.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-11375] IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arb…
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a stack buffer overflow when processing XA transaction identifiers.