Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
Buscando: "Multiple Vendors" — 5284 resultados ✕ Limpiar búsqueda
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1003
Esta semana
RSS
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-88285] Cámara GeoVision GV-LPC2211 V1.13 expone control PTZ sin autenticación
La cámara GeoVision GV-LPC2211 versión 1.13 expone un servicio de control PTZ (Pan-Tilt-Zoom) accesible por red sin requerir autenticación, permitiendo a atacantes remotos recuperar información de posicionamiento e inyectar comandos PTZ o comandos seriales arbitrarios. Esta vulnerabilidad afecta sistemas de vigilancia en infraestructura crítica, oficinas corporativas y centros de datos en México y Latinoamérica. Con CVSS 9.4, representa riesgo crítico de compromiso del perímetro de seguridad física y acceso no autorizado a sistemas de monitoreo.
M Alto vulnerabilidad
10/09/2026
Vulnerabilidad alta en GeoVision GV-LPC2211 V1.13 permite denegación de servicio en conexiones PTZ
GeoVision GV-LPC2211 versión 1.13 presenta una gestión inadecuada del estado de conexión PTZ (Pan-Tilt-Zoom) que permite a un atacante remoto no autenticado bloquear el bucle de aceptación y prevenir nuevas conexiones PTZ. Esta vulnerabilidad afecta sistemas de vigilancia altas en instalaciones de seguridad física en México y Latinoamérica, donde estas cámaras son ampliamente deployadas en bancos, hospitales y centros comerciales.
M Alto vulnerabilidad
10/09/2026
Vulnerabilidad alta en GeoVision GV-LPC2211 V1.13 permite denegación de servicio remota
La cámara IP GeoVision GV-LPC2211 versión 1.13 presenta una falla en la validación de tokens ONVIF WS-Discovery que permite a atacantes remotos sin autenticación corromper el estado de control de pila y crashear el proceso de descubrimiento. Esta vulnerabilidad afecta directamente la disponibilidad de sistemas de videovigilancia altas en infraestructuras de seguridad física de empresas, data centers y operaciones en LATAM.
M Alto vulnerabilidad
10/09/2026
Vulnerabilidad alta en GeoVision GV-LPC2211 V1.13 permite escalada de privilegios
La cámara IP GeoVision GV-LPC2211 versión 1.13 contiene una vulnerabilidad que permite a usuarios invitados sobrescribir la configuración del dispositivo y reemplazar la contraseña del administrador a través del servicio SSVR. Esta falla afecta directamente a sistemas de videovigilancia desplegados en México y Latinoamérica, poniendo en riesgo el acceso no autorizado a infraestructura alta de seguridad física.
M Alto vulnerabilidad
10/09/2026
Vulnerabilidad alta en GeoVision GV-LPC2211 V1.13 permite ejecución de comandos como root
La cámara GeoVision GV-LPC2211 versión 1.13 permite a administradores inyectar metacaracteres de shell en nombres de usuario que se ejecutan con privilegios root al eliminar la cuenta. Esta vulnerabilidad afecta principalmente sistemas de vigilancia en infraestructuras altas, retail y datos centers en LATAM. El impacto es alta: compromiso total del dispositivo y potencial lateral movement en redes corporativas.
M Alto vulnerabilidad
10/09/2026
Vulnerabilidad alta en GeoVision GV-LPC2211 V1.13 permite ejecución de comandos como root
La cámara IP GeoVision GV-LPC2211 versión 1.13 contiene una vulnerabilidad de escape de shell que permite a administradores ejecutar comandos arbitrarios con privilegios root a través del campo de usuario PPPoE. Esta falla afecta principalmente a sistemas de videovigilancia en LATAM, donde estos dispositivos son comúnmente desplegados en infraestructuras altas, puntos de venta y centros de datos.
M Alto vulnerabilidad
10/09/2026
CVE-2026-88274: Ejecución remota de comandos en cámaras GeoVision GV-LPC2211 V1.13
La cámara GeoVision GV-LPC2211 versión 1.13 contiene una vulnerabilidad que permite a administradores ejecutar comandos arbitrarios con privilegios de root mediante configuración maliciosa del SSID inalámbrico. Esta falla afecta sistemas de videovigilancia en infraestructuras altas, hospitales y centros financieros en LATAM. Un atacante con acceso administrativo puede comprometer completamente el dispositivo y la red corporativa.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88275] GeoVision GV-LPC2211 V1.13 allows an administrator-controlled WPA-PSK containing shell syntax to exe…
GeoVision GV-LPC2211 V1.13 allows an administrator-controlled WPA-PSK containing shell syntax to execute arbitrary commands as root when wireless configuration is applied.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88276] GeoVision GV-LPC2211 V1.13 allows administrator-controlled WEP key values containing shell syntax to…
GeoVision GV-LPC2211 V1.13 allows administrator-controlled WEP key values containing shell syntax to execute arbitrary commands as root.
M Alto vulnerabilidad
10/09/2026
Vulnerabilidad alta en cámaras GeoVision GV-LPC2211: inyección de comandos shell
GeoVision GV-LPC2211 versión 1.13 contiene una vulnerabilidad que permite a usuarios ONVIF autenticados inyectar comandos shell a través del parámetro ConsumerReference.Address, resultando en ejecución de código arbitrario con permisos root. Afecta sistemas de vigilancia en infraestructuras altas, acceso remoto corporativo y centros de datos en LATAM.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-88278] GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse prote…
GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse protection, allowing a captured PasswordDigest token to be replayed for subsequent ONVIF operations.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-84042] A flaw was found in crun. When crun is built with libkrun and a container is started rootful with pa…
A flaw was found in crun. When crun is built with libkrun and a container is started rootful with passt networking (krun.use_passt), crun can execute attacker-controlled payload from the container image with host root privileges. The issue is a regression in crun 1.29. It affects crun >= 1.29
M Alto vulnerabilidad
10/09/2026
[CVE-2026-42805] A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI385 SensorAPI (C librar…
A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI385 SensorAPI (C library) within the debug message parser function bhi385_parse_debug_message (located in bhi385_parse.c). The function parses FIFO events and extracts an 8-bit message length directly from the attacker-controlled event payload (callback_info->data_ptr[0]) without enforcing bounds checks or clamping th…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-42807] A heap-based buffer overflow vulnerability in the PC bridge protocol decoder of BoschSensortec COINE…
A heap-based buffer overflow vulnerability in the PC bridge protocol decoder of BoschSensortec COINES_SDK (versions 2.10 through 2.12.2) allows attackers to cause a denial of service (process crash) or potentially execute arbitrary code. The bridge decoder ({{bridge_decoder.c}}) trusts the packet length field provided by the external device and forwards it to the host response queue ({{mqueue_…
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-44950] fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph's bitmap in…
fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph's bitmap into a single buffer. Existing checks validates only that the source slice (position, length) lies within the source bitmap buffer. It does not check whether the running destination cursor has exceeded the allocation. A malicious font server can send overlapping source offsets -- for example 1000 gly…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-59679] fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character enc…
fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents in the separate FS_QueryXExtents16 reply. The two CARD32 fields are never cross-checked. A malicious or compromised font server can send a small num_extents (e.g. 1) in …
M Alto vulnerabilidad
10/09/2026
[CVE-2026-42804] A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI360 SensorAPI(C-Library…
A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI360 SensorAPI(C-Library) in versions up to and including commit d6b200416a. The vulnerability is located within the FIFO parsing and debug logging subsystem inside the function bhi360_parse_debug_message() in bhi360_parse.c (lines 1852-1875). The parser trusts the first payload byte of a debug frame as the message …
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-80352] Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K. A YAML…
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K. A YAML injection vulnerability in custom resource configuration allows an authorized CR author to inject arbitrary Kubernetes objects, potentially enabling unauthorized resource creation with the privileges of the operator. This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 2.10.1 before …
M Alto vulnerabilidad
10/09/2026
[CVE-2026-80354] Authorization bypass through User-Controlled key vulnerability in Apache Camel K. An authorizatio…
Authorization bypass through User-Controlled key vulnerability in Apache Camel K. An authorization vulnerability in custom resource resolution allows a tenant to reference secrets by name in the operator namespace, potentially exposing secrets belonging to other tenants or operator components. This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 2.10.1 before 2.10.2. Users are…
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-80351] Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability…
Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability in Apache Camel K. An improper neutralization of directives in dynamically evaluated Maven configuration allows tenant-controlled repository content to influence code execution within the operator pod, potentially enabling tenants to execute arbitrary code with the privileges of the operator. …