Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,394
Total alertas
3047
Críticas
10075
Altas
8
Ransomware
1739
Esta semana
RSS
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19813] A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts th…
A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Such manipulation of the argument Comment leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19811] A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element i…
A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the argument Comment results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19792] A security flaw has been discovered in Tenda G0 up to 20260625. Impacted is the function setPortMapp…
A security flaw has been discovered in Tenda G0 up to 20260625. Impacted is the function setPortMapping of the file /goform/module of the component httpd web management interface. Performing a manipulation of the argument portMappingServer/porMappingtInternal/portMappingExternal results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been released to the publ…
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19791] A weakness has been identified in Tenda G0 up to 20260625. The affected element is the function addS…
A weakness has been identified in Tenda G0 up to 20260625. The affected element is the function addStaticRoute of the file /goform/module of the component httpd web management interface. Executing a manipulation of the argument staticRouteNet can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be used for att…
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19789] A vulnerability was determined in Tenda AC1206 15.03.06.23_multi_TD01. This vulnerability affects th…
A vulnerability was determined in Tenda AC1206 15.03.06.23_multi_TD01. This vulnerability affects the function set_wl_guest_iplist of the file /goform/WifiGuestSet of the component httpd web management interface. This manipulation of the argument shareSpeed causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized…
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19790] A vulnerability was identified in Tenda G0 up to 20260625. This issue affects the function formSetPo…
A vulnerability was identified in Tenda G0 up to 20260625. This issue affects the function formSetPortMirror of the file /goform/module of the component httpd Web Management Interface. Such manipulation of the argument portMirrorMirroredPorts leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19788] A vulnerability was found in Tenda AC1206 15.03.06.23_multi_TD01. This affects the function set_devi…
A vulnerability was found in Tenda AC1206 15.03.06.23_multi_TD01. This affects the function set_device_name of the file /goform/SetOnlineDevName of the component httpd web management interface. The manipulation of the argument devName results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
09/08/2026
Vulnerabilidad alta en UTT HiPER 1200GW permite desbordamiento de búfer remoto
Se ha identificado un desbordamiento de búfer basado en stack en los modelos UTT HiPER 1200GW versiones hasta 2.5.3-170306, mediante manipulación del parámetro EncryptionMode en la función strcpy del archivo /goform/pptpSrvGlobalConfig. La vulnerabilidad permite ejecución remota de código sin autenticación previa, con CVSS 8.8. El exploit ha sido divulgado públicamente, aumentando el riesgo inmediato para equipos de red altas en LATAM que utilizan este modelo de puerta de enlace.
M Alto vulnerabilidad
05/08/2026
[CVE-2026-20268] As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE So…
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20268 are related to issues with improper restriction of operati…
M Alto vulnerabilidad
05/08/2026
[CVE-2026-18898] A security flaw has been discovered in UTT HiPER 1200GW up to v2.5.3-170306. This affects the functi…
A security flaw has been discovered in UTT HiPER 1200GW up to v2.5.3-170306. This affects the function strcpy of the file /goform/ConfigAdvideo. The manipulation of the argument timestart results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did n…
M Alto vulnerabilidad
05/08/2026
[CVE-2026-18895] A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function st…
A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /goform/APSecurity_5g. Performing a manipulation of the argument cipher results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respon…
M Alto vulnerabilidad
05/08/2026
[CVE-2026-18897] A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element …
A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strcpy of the file /goform/getOneApConfTempEntry. The manipulation of the argument tempName leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did no…
M Alto vulnerabilidad
03/08/2026
[CVE-2026-18607] A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN5…
A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN535, etc. WN529, WN530, WN531, WN535, WN536, WN551, WN557 and NU516 up to 20260609. Affected by this issue is the function strcpy of the file upload.cgi of the component lighttpd. The manipulation of the argument HTTP_COOKIE leads to stack-based buffer overflow. It is possible to initiate the attack …
M Crítico vulnerabilidad
03/08/2026
Vulnerabilidad crítica de desbordamiento de búfer en Wavlink WL-NU516U1 (CVE-2026-18588)
Se ha identificado una vulnerabilidad de desbordamiento de búfer en la pila (stack-based buffer overflow) en el enrutador Wavlink WL-NU516U1 versión 708c073-mt7628, específicamente en la función fgets del archivo nas.cgi. Un atacante remoto puede explotar la manipulación del parámetro CONTENT_LENGTH para ejecutar código arbitrario sin autenticación. Esta vulnerabilidad afecta principalmente a infraestructuras de PyMEs y centros de datos en LATAM que utilizan estos dispositivos como puntos de acceso o enrutadores en redes corporativas.
M Crítico vulnerabilidad
03/08/2026
Vulnerabilidad crítica de desbordamiento de búfer en Wavlink WL-NU516U1 (CVE-2026-18589)
Se identificó una vulnerabilidad de desbordamiento de búfer basado en pila en el router Wavlink WL-NU516U1 (versión 708c073-mt7628) que afecta la función de cambio de contraseña en nas.cgi. Un atacante remoto puede explotar esta falla manipulando el parámetro User1Passwd para ejecutar código arbitrario sin autenticación previa. El exploit es público y existe riesgo inmediato en infraestructuras de LATAM que utilizan este dispositivo.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
A Crítico vulnerabilidad
27/07/2026
[CVE-2026-64771] A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and i…
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption.
A Alto vulnerabilidad
27/07/2026
[CVE-2026-64757] A memory corruption issue was addressed with improved state management. This issue is fixed in Safar…
A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
A Alto vulnerabilidad
27/07/2026
[CVE-2026-64758] The issue was addressed with improved bounds checks. This issue is fixed in iOS 26.6 and iPadOS 26.6…
The issue was addressed with improved bounds checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected app termination.
A Alto vulnerabilidad
27/07/2026
[CVE-2026-64749] The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26…
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, visionOS 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory.
A Crítico vulnerabilidad
27/07/2026
[CVE-2026-64726] The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26…
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An attacker in physical proximity may be able to corrupt process memory.