Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Linux" — 390 resultados ✕ Limpiar búsqueda
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1012
Esta semana
RSS
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-89783] In the Linux kernel, the following vulnerability has been resolved: xfrm6: fix out-of-bounds write …
In the Linux kernel, the following vulnerability has been resolved: xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full The depth check in xfrm6_input_addr() is off by one: if (1 + sp->len == XFRM_MAX_DEPTH) goto drop; ... sp->xvec[sp->len++] = x; xfrm_input() can leave sp->len == XFRM_MAX_DEPTH, and the transport-mode receive path re-enters IPv6 input via…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-89774] In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: hold sk properl…
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: hold sk properly in sco_conn_ready sk deref in sco_conn_ready must be done either under conn->lock, or holding a refcount, to avoid concurrent close. conn->sk and parent sk is currently accessed without either, and without checking parent->sk_state: [Task 1] [Task 2] sco_so…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-89775] In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Handle negative S1 …
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation Computing the effects of a TLB invalidation involves looking at the size of the mapping cached by the TLB. For S1 mappings such as VNCR, this is deducted from the combination of the base granule size and the mapping level. However, this implies that the S1 M…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-61554] emp3r0r is a C2 designed by Linux users for Linux environments. Prior to version 4.2.5, the `http_po…
emp3r0r is a C2 designed by Linux users for Linux environments. Prior to version 4.2.5, the `http_poll` C2 transport accepts attacker-controlled HTTP polling sessions before CBOR `MsgAuth` authentication is completed. A remote unauthenticated attacker can create arbitrary polling sessions and send request bodies that are forwarded into the C2 dispatch path. This can consume server resources and tr…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-53713] Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based…
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, to_absolute_normalized_path in internal/gatewayapi/luavalidator/security.lua does not collapse redundant separators before is_critical_path evaluates Lua submitted through EnvoyExtensionPolicy during default Strict validation. Linux resolves a double-s…
M Alto vulnerabilidad
14/09/2026
[CVE-2023-32803] The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not pr…
The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly remove certain TrustCor root certificates from the root store. NOTE: this issue exists because of an incorrect fix for CVE-2022-23491.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad en Melange y Apko permite instalar paquetes APK maliciosos sin validación
Melange versiones anteriores a 0.50.4 y Apko anteriores a 1.2.9 no verifican la integridad de los archivos de datos en paquetes APK durante la instalación, solo validan metadatos. Un atacante que controle un espejo, envenenene un caché o realice ataques MITM puede distribuir paquetes comprometidos que se instalarán sin detección. Afecta infraestructuras que utilizan estos gestores de compilación en entornos Linux containerizados.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
C Informativo vulnerabilidad
11/09/2026
[CVE-2026-89566] In the Linux kernel, the following vulnerability has been resolved: jbd2: check need_resched() when…
In the Linux kernel, the following vulnerability has been resolved: jbd2: check need_resched() when skipping busy checkpoint buffers journal_shrink_one_cp_list() skips busy checkpoint buffers when called with JBD2_SHRINK_BUSY_SKIP. The continue statement on this path also skips the need_resched() check at the end of the loop body. Consequently, when a checkpoint list contains mostly busy buffe…
C Informativo vulnerabilidad
11/09/2026
[CVE-2026-89567] In the Linux kernel, the following vulnerability has been resolved: jbd2: bound shrinker scans by e…
In the Linux kernel, the following vulnerability has been resolved: jbd2: bound shrinker scans by examined checkpoint buffers The jbd2 shrinker currently accounts only checkpoint buffers that it successfully releases against nr_to_scan. Busy buffers therefore do not consume the scan budget. If a checkpoint transaction contains mostly busy buffers, the shrinker can scan its entire checkpoint li…
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-19583] Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the…
Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. However, no such check was implemented for client monitoring artifacts. Additionally there was no requirement that client monitoring artifacts carry the CLIENT_EVENTS …