Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1014
Esta semana
RSS
M Alto vulnerabilidad
18/09/2026
[CVE-2026-61714] FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6…
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6, configuring synth.midi-channels above 16 allows the MIDI player to index _fluid_player_t::channel_isplaying outside its fixed-size heap allocation while tracking active channels. The resulting out-of-bounds reads and writes invoke undefined behavior and may compromise confidentiality, integrity, o…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-61721] FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6…
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS loader assigns file-controlled wsmp.loop_start and wsmp.loop_length values to samples without calling fluid_sample_validate() or fluid_sample_sanitize_loop(). A crafted DLS file can place sample loop points beyond the sample buffer, causing out-of-bounds reads during audio rendering…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-11726] IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to obtain sensit…
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to improper validation of message header offset values.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93331] A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_par…
A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file src/ietf/rtp_depacketizer.c of the component RTP Depacketizer. Such manipulation of the argument size leads to out-of-bounds read. It is possible to launch the attack remotely. Upgrading to version abi-16.26 is able to resolve this issue. The name of the patch is 6bb0f64b4d1039c0…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-92925] A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, P…
A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packets, fails to properly validate string-carrying extensions for null-termination. This oversight allows a remote attacker to craft a malicious packet, leading to an out-of-bounds read when the packet's payload is processed. Successful exploitation of this vulnerability could result …
M Alto vulnerabilidad
17/09/2026
[CVE-2026-25282] Transient DOS when processing unverified data from a neighboring system causes out of bound memory a…
Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-76870] Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in the mtd_write pre…
Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in the mtd_write pre-flash validation routine triggered by short firmware uploads. Attackers can upload a truncated firmware image via put_file_cgi.c to trigger out-of-bounds reads across main.c, check_image_uuid.c, and oemMD5Update.c.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92176] pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulne…
pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of App obj…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-85234] A flaw was found in tftp-hpa. When the `in.tftpd` remap engine processes an inverse remap rule that …
A flaw was found in tftp-hpa. When the `in.tftpd` remap engine processes an inverse remap rule that also aborts with a non-empty custom error message, it can pass invalid match offsets to the `genmatchstring()` function. This leads to out-of-bounds read/write operations. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted request, causing the daemon to …
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-55211] Surfio is a library for reading and writing surface files. Prior to 0.0.19, surfio does not correctl…
Surfio is a library for reading and writing surface files. Prior to 0.0.19, surfio does not correctly validate size fields in IRAP files, leading to a buffer overflow when untrusted files are parsed. The severity assumes surfio is used to parse untrusted files in a networking context such as a web service. This issue is fixed in version 0.0.19.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-65364] An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Gold…
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A remote attacker may be able to cause unexpected system termination.
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-55209] resdata is software for reading and writing result files from the Eclipse reservoir simulator. Prior…
resdata is software for reading and writing result files from the Eclipse reservoir simulator. Prior to 6.2.9, resdata insufficiently validates numeric fields, grid dimensions, keyword sizes, and array indexes while parsing untrusted GRDECL files in lib/resdata/rd_kw_grdecl.cpp and lib/resdata/rd_grid.cpp. Malformed COORD, ZCORN, CORSNUM, ACTNUM, or MAPAXES data can reach rd_grid_alloc_GRDECL_kw__…
M Alto vulnerabilidad
12/09/2026
[CVE-2026-90560] zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDict…
zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can supply arbitrary offset or length values to read memory past the end of the supplied array, potentially causing JVM termination.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-89046] zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an out-of-bounds read vulnerability in Zstd.getFr…
zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an out-of-bounds read vulnerability in Zstd.getFrameContentSize that fails to validate negative srcPosition arguments. Attackers can supply negative offset values that bypass bounds checks and reach the native frame-header parser, causing out-of-bounds memory reads that lead to information disclosure or JVM crashes.
M Alto vulnerabilidad
10/09/2026
Vulnerabilidad alta en ESP32-audioI2S 3.4.4-4.0.0: lectura fuera de límites en procesamiento ID3
ESP32-audioI2S versiones 3.4.4 a 4.0.0 contienen una vulnerabilidad de lectura fuera de límites en la función read_ID3_Header durante procesamiento de etiquetas ID3 sincronizadas. Atacantes pueden crear archivos MP3 maliciosos o flujos de audio HTTP con declaraciones de tamaño de fotograma exageradas, causando caídas del dispositivo o exposición de memoria adyacente. Afecta principalmente a sistemas IoT, dispositivos embebidos y aplicaciones de streaming de audio en infraestructuras empresariales LATAM.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
09/09/2026
[CVE-2026-22590] eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG…
eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Versions prior to 2.6.12, 2.14.6, 3.2.4, 3.3.1, and 3.4.2 have a remotely triggerable Out-of-Bounds Read while processing RTPS `DATA_FRAG` submessages. An attacker can craft a `DATA_FRAG` with a large `sampleSize` but a small actual payload, and set `fragmentsInSubmessage…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87824] zstd-jni before 1.5.7-14 fails to validate the samples buffer capacity in Zstd.trainFromBufferDirect…
zstd-jni before 1.5.7-14 fails to validate the samples buffer capacity in Zstd.trainFromBufferDirect, allowing attackers to read past buffer boundaries by supplying oversized per-sample lengths. Attackers can trigger out-of-bounds memory access by providing crafted sample length arrays that cause the native implementation to walk past the buffer allocation, resulting in JVM termination.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87795] zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompr…
zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap memory into the compression dictionary, typically causing JVM crashes.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-49314] OOB write vulnerability in the rendering and composition module. Impact: Successful exploitation of …
OOB write vulnerability in the rendering and composition module. Impact: Successful exploitation of this vulnerability may affect availability.
G Crítico vulnerabilidad
09/09/2026
[CVE-2026-87650] Out of bounds read in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to pot…
Out of bounds read in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)