Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1014
Esta semana
RSS
M Alto vulnerabilidad
14/09/2026
[CVE-2026-90689] A security flaw has been discovered in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. Impacted is the fun…
A security flaw has been discovered in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. Impacted is the function formDelWebAuthWhiteUser. Performing a manipulation of the argument webAuthWhiteUserIndex results in stack-based buffer overflow. The attack can be initiated remotely.
M Alto vulnerabilidad
14/09/2026
[CVE-2023-46273] Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has …
Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has an ah_bgd buffer overflow via ah_event_send.
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-90680] A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is th…
A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of the file /HNAP1/SetStaticRouteSettings of the component HNAP1. The manipulation of the argument PAddress/SubnetMask/Gateway results in stack-based buffer overflow. The attack can be launched remotely.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-33963] An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2…
An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. A stack-based buffer overflow occurs when a malformed message is sent to the camera driver, causing a denial of service.
M Alto vulnerabilidad
13/09/2026
Vulnerabilidad alta de desbordamiento de buffer en SIPp 3.7.7 permite crash remoto
SIPp versiones hasta 3.7.7 contiene un desbordamiento de buffer en la función createAuthHeader() al procesar desafíos de autenticación SIP con parámetros de algoritmo manipulados. Un servidor SIP malicioso puede enviar una respuesta 401 o 407 fraudulenta para corromper la memoria del proceso cliente y causar su caída, afectando sistemas de telefonía empresarial y centros de contacto en la región.
M Crítico vulnerabilidad
12/09/2026
[CVE-2026-90558] sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting rout…
sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized Call-ID, X-Call-ID, or other header fields to overflow stack buffers and cause crashes or execute arbitrary code during packet parsing and rendering.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-86093] IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to…
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that improperly copies user-controlled data into a fixed-size stack buffer without bounds checking.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
10/09/2026
Vulnerabilidad alta en GeoVision GV-LPC2211 V1.14 permite denial of service remoto
GeoVision GV-LPC2211 versión 1.14 (260903) contiene un fallo de validación en campos de longitud variable en múltiples manejadores de solicitudes VLSVR, permitiendo que atacantes no autenticados causen el colapso del servicio. Esta vulnerabilidad afecta principalmente a sistemas de vigilancia y control de acceso implementados en infraestructuras altas de México y Latinoamérica, generando riesgo de indisponibilidad operativa.
M Alto vulnerabilidad
10/09/2026
Vulnerabilidad alta en GeoVision GV-LPC2211 V1.13 permite denegación de servicio remota
La cámara IP GeoVision GV-LPC2211 versión 1.13 presenta una falla en la validación de tokens ONVIF WS-Discovery que permite a atacantes remotos sin autenticación corromper el estado de control de pila y crashear el proceso de descubrimiento. Esta vulnerabilidad afecta directamente la disponibilidad de sistemas de videovigilancia altas en infraestructuras de seguridad física de empresas, data centers y operaciones en LATAM.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-42805] A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI385 SensorAPI (C librar…
A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI385 SensorAPI (C library) within the debug message parser function bhi385_parse_debug_message (located in bhi385_parse.c). The function parses FIFO events and extracts an 8-bit message length directly from the attacker-controlled event payload (callback_info->data_ptr[0]) without enforcing bounds checks or clamping th…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-42804] A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI360 SensorAPI(C-Library…
A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI360 SensorAPI(C-Library) in versions up to and including commit d6b200416a. The vulnerability is located within the FIFO parsing and debug logging subsystem inside the function bhi360_parse_debug_message() in bhi360_parse.c (lines 1852-1875). The parser trusts the first payload byte of a debug frame as the message …
M Alto vulnerabilidad
10/09/2026
[CVE-2026-82079] A stack-based buffer overflow vulnerability in the Nintendo Switch local wireless networking functio…
A stack-based buffer overflow vulnerability in the Nintendo Switch local wireless networking functionality may allow an attacker within wireless range to execute arbitrary code using return-oriented programming (ROP) through crafted network traffic. This issue affects Nintendo Switch: before 23.0.0.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-83990] Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate…
Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-81953] Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute cod…
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-81396] Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute cod…
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
08/09/2026
[CVE-2026-81388] Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute cod…
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-78504] Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code…
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-78439] Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execu…
Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-73006] Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execu…
Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-72982] Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over…
Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.