Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1014
Esta semana
RSS
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-44756] A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Und…
A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availabil…
M Crítico vulnerabilidad
06/09/2026
CVE-2026-86165: Vulnerabilidad crítica de desbordamiento de búfer en Tenda HG10 300001138
Se identificó una vulnerabilidad de desbordamiento de búfer (buffer overflow) en el router Tenda HG10 modelo 300001138, específicamente en la función formURL del archivo /boaform/admin/formURL. Un atacante remoto puede manipular los parámetros Keywd/urlFQDN para ejecutar código arbitrario sin autenticación previa. El exploit es público y activamente explotado en la región LATAM, afectando principalmente a PyMEs con infraestructura de redes domésticas y pequeñas oficinas.
M Alto vulnerabilidad
06/09/2026
Vulnerabilidad alta de desbordamiento de buffer en Tenda HG10 300001138
Se identificó una vulnerabilidad en el componente Boa Web Server del router Tenda HG10 (modelo 300001138) que permite desbordamiento de buffer mediante manipulación del parámetro 'if' en la función formWanRedirect. El exploit ha sido divulgado públicamente y puede ser explotado de forma remota. Esta vulnerabilidad afecta principalmente a pequeñas y medianas empresas en México y Latinoamérica que utilizan este dispositivo como router de acceso a Internet o en infraestructuras de red.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85110] A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formWlanSetup of th…
A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formWlanSetup of the file /boaform/formWlanSetup of the component Boa Web Server. The manipulation of the argument ssid leads to buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85109] A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of…
A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of the file /boaform/formLogin of the component Boa Web Server. Executing a manipulation of the argument Username can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85031] A vulnerability was found in TOTOLINK CP450 4.1.0. The impacted element is an unknown function of th…
A vulnerability was found in TOTOLINK CP450 4.1.0. The impacted element is an unknown function of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument topicurl results in buffer overflow. Remote exploitation of the attack is possible.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-83596] A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to i…
A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
30/08/2026
[CVE-2026-82542] A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formI…
A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-75124] PLANET GS-4210-16P2S firmware before 3.441b260626 contains a pre-authentication memory corruption vu…
PLANET GS-4210-16P2S firmware before 3.441b260626 contains a pre-authentication memory corruption vulnerability in the web management interface where the _readHttpParam function copies an oversized HTTP query string without guaranteeing NUL termination, allowing parse_query_string to process attacker-controlled data into a fixed-size stack buffer. An unauthenticated remote attacker can send an ove…
M Alto vulnerabilidad
25/08/2026
Vulnerabilidad alta de buffer overflow en BlueZ afecta stack Bluetooth de Linux
Una vulnerabilidad de desbordamiento de búfer en la pila Bluetooth de Linux (BlueZ) permite a atacantes remotos dentro del rango de radio enviar paquetes Extended Inquiry Response (EIR) malformados que causan bloqueos del servicio bluetoothd. Afecta servidores Linux, dispositivos IoT y sistemas embebidos comunes en infraestructura LATAM, con potencial de denegación de servicio y ejecución de código remoto.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-71399] Adobe XD is affected by a Buffer Overflow vulnerability that could result in arbitrary code executio…
Adobe XD is affected by a Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
M Alto vulnerabilidad
24/08/2026
[CVE-2026-19568] A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption …
A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
M Alto vulnerabilidad
24/08/2026
[CVE-2026-71938] Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the switch_lan_gvrp f…
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the switch_lan_gvrp function. The vulnerability is caused by unsafe copying of the portList field into an undersized buffer. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires valid administrative credentials …
M Alto vulnerabilidad
24/08/2026
[CVE-2026-71939] Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup…
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Add ACE function. The vulnerability is caused by copying the name field into a fixed-size buffer without length validation. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires valid admini…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-71940] Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup…
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Edit ACE function. The vulnerability is caused by copying the name field into a fixed-size buffer without length validation. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires valid admin…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
24/08/2026
[CVE-2026-71941] Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the diag_logmail func…
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the diag_logmail function. The vulnerability is caused by concatenating multiple smtpReceiver email addresses into a fixed-size buffer without checking the remaining buffer size. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. E…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-71942] Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the mail_mailalert fu…
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the mail_mailalert function. The vulnerability is caused by concatenating multiple smtpReceiver email addresses into a fixed-size buffer without checking the remaining buffer size. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands.…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-71934] Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the pingtrace functio…
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the pingtrace function. The vulnerability is caused by missing length checks when the host, count, and interval fields are concatenated into a fixed-size buffer. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requi…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-71935] Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the webBackupAction f…
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the webBackupAction function. The vulnerability is caused by repeated string concatenation of the pathN, valueN, key, and option fields into fixed-size stack buffers without total length checks. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbit…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-71936] Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the sysreboot functio…
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the sysreboot function. The vulnerability is caused by unsafe concatenation of split valueN data into a fixed-size buffer. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires valid administrative credentials fo…