Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1003
Esta semana
RSS
M Alto vulnerabilidad
24/09/2026
[CVE-2026-88372] libsndfile 1.2.2 contains an integer overflow vulnerability in mat4_read_header() when parsing craft…
libsndfile 1.2.2 contains an integer overflow vulnerability in mat4_read_header() when parsing crafted MAT4 (MATLAB v4) files.
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-93577] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 …
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to an integer overflow issue when compiling a specially crafted regular expression in a CI/CD configuration.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-6668] Integer overflow in the packet buffer growth logic in PgBouncer through 1.25.2 allows an unauthentic…
Integer overflow in the packet buffer growth logic in PgBouncer through 1.25.2 allows an unauthenticated remote attacker to cause a denial of service. Sufficiently large input makes the buffer size computation overflow, leaving the growth loop unable to terminate. Because PgBouncer serves all clients from a single process, this saturates a CPU core and stalls every pooled connection until the proc…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-95619] A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the ali…
A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-11725] IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arb…
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in MQINQ request processing.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-46655] virtio-win provides Windows paravirtualized drivers for QEMU and KVM. From mm210 until mm320, the Vi…
virtio-win provides Windows paravirtualized drivers for QEMU and KVM. From mm210 until mm320, the Viosock driver permits a low-privilege local process to submit an IOCTL_SELECT request with attacker-controlled VIRTIO_VSOCK_SELECT.Fdss[*].fd_count values that overflow the 32-bit sum used by VIOSockSelect for bounds checking. The wrapped sum can pass the FD_SETSIZE check even though an individual de…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-11378] IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arb…
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in distribution list processing.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93652] Integer overflow in µD3TN v0.15.0 TCPCLv3 handshake causes heap overflow, allowing remote attackers …
Integer overflow in µD3TN v0.15.0 TCPCLv3 handshake causes heap overflow, allowing remote attackers to reliably cause DoS
M Alto vulnerabilidad
17/09/2026
[CVE-2026-25290] Memory Corruption when validating large data buffers from external sources using addition to check b…
Memory Corruption when validating large data buffers from external sources using addition to check buffer length.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-63126] Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.5 and 7.0…
Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.5 and 7.0.0-alpha04, Wire protobuf readers do not consistently validate attacker-controlled lengths against the current logical message boundary before advancing cursors, pointers, limits, slices, or allocations. In Kotlin, ProtoAdapter.decode(ByteArray) and ProtoAdapter.decode(ByteString) use ByteArrayProto…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92248] A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially…
A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG header. This leads to an undersized heap allocation, resulting in a heap-based buffer overflow when the image data is decoded. This buffer overflow corrupts adjacent hea…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-91728] Integer overflow in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute …
Integer overflow in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
15/09/2026
[CVE-2026-55351] In VPU, there is a possible out-of-bounds write due to an integer overflow. This could lead to local…
In VPU, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-90715] A security vulnerability has been detected in marcobambini Gravity up to 0.9.7. This affects an unkn…
A security vulnerability has been detected in marcobambini Gravity up to 0.9.7. This affects an unknown function of the file src/utils/gravity_json.c of the component udp json-parser. Such manipulation leads to integer overflow. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. Upgrading to version 0.9.8 mitigates this issue. The name of the patch is…
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90593] A vulnerability was determined in embedded-graphics up to 0.8.2. This affects the function ImageRaw:…
A vulnerability was determined in embedded-graphics up to 0.8.2. This affects the function ImageRaw::draw_sub_image of the file src/image/image_raw.rs. Executing a manipulation of the argument width can lead to integer overflow. The attack may be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad alta en libde265 permite desbordamiento de enteros en procesamiento de video HEVC
libde265 versiones anteriores a 1.1.1 contienen un fallo de desbordamiento de enteros en cálculo de desplazamientos de píxeles que permite a archivos HEVC malformados con dimensiones grandes provocar lecturas/escrituras fuera de límites en memoria heap. El impacto incluye exposición de datos sensibles, corrupción de memoria o crasheo del decodificador afectando plataformas de procesamiento de video, streaming y análisis multimedia en operaciones en LATAM.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad alta en libde265: desbordamiento de enteros en códecs H.265
libde265, biblioteca de código abierto para decodificación de vídeo H.265 (HEVC), contiene un desbordamiento de enteros en versiones anteriores a 1.1.1 que permite a atacantes mediante flujos HEVC manipulados provocar lectura fuera de límites en memoria heap, exponiendo datos sensibles o causando caída del servicio. Afecta servidores multimedia, plataformas de streaming y sistemas de videoconferencia en empresas LATAM que procesan vídeo con esta biblioteca.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-87020] An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds w…
An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc DICOM Server decodes an attacker-supplied PNG.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad alta en libp2p-rendezvous permite desbordamiento de temporizador en clientes
libp2p-rendezvous versión 0.17.1 y anteriores no valida correctamente los valores TTL en respuestas de descubrimiento, permitiendo que servidores rendezvous maliciosos causen pánico en procesos cliente mediante aritmética de temporizador no limitada. Afecta infraestructuras de red descentralizada, nodos blockchain y aplicaciones P2P en México y LATAM.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-85228] An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from…
An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain information from adjacent process memory or cause a denial of service via a crafted tensor payload. To remediate this issue, users should upgrade to version 0.37.0 or above.