Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Socket" — 272 resultados ✕ Limpiar búsqueda
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1020
Esta semana
RSS
M Alto vulnerabilidad
08/09/2026
[CVE-2026-71332] Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to e…
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-70565] Use after free in Windows AF_UNIX Socket Provider allows an authorized attacker to elevate privilege…
Use after free in Windows AF_UNIX Socket Provider allows an authorized attacker to elevate privileges locally.
F Alto vulnerabilidad
08/09/2026
Broken Access control on Websocket streams
Fortinet PSIRT publica advisory de seguridad: Broken Access control on Websocket streams. Tipo: Control de Acceso Inadecuado. Producto afectado: Fortisoar.
M Alto vulnerabilidad
05/09/2026
[CVE-2026-86188] AVideo with YPTSocket plugin enabled contains a cross-site scripting vulnerability allowing unauthen…
AVideo with YPTSocket plugin enabled contains a cross-site scripting vulnerability allowing unauthenticated attackers to execute arbitrary JavaScript in other users' browsers via the websocket callback mechanism. Attackers can send crafted socket messages with callback names resolving to global functions like avideoConfirmHTML that accept untrusted data and assign it to innerHTML, achieving script…
M Alto vulnerabilidad
04/09/2026
[CVE-2026-19534] undici's WebSocket client crashes the whole Node.js process during the opening handshake when a serv…
undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A default WebSocket connection sends no subprotocol, but if the server's 101 response includes a Sec-WebSocket-Protocol header, undici dereferences a null value while checking it against the requested list and throws an uncaught TypeErr…
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85443] MOOS core-moos through 10.4.0 contains a denial of service vulnerability in MOOSCommServer::ListenLo…
MOOS core-moos through 10.4.0 contains a denial of service vulnerability in MOOSCommServer::ListenLoop() where the accept thread performs a blocking receive without timeout during the wire-protocol handshake. An attacker can open a TCP connection to the MOOSDB port and send no data, causing the accept thread to block indefinitely while holding the socket-list lock, preventing all subsequent client…
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85183] Taipy configures its socket.io server with wildcard CORS origin and credential flag enabled, allowin…
Taipy configures its socket.io server with wildcard CORS origin and credential flag enabled, allowing any web page to establish credentialed WebSocket connections to victim applications. Attackers can open socket.io sessions from arbitrary domains and invoke state variable modifications and action callbacks without CSRF protection.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85124] @fastify/http-proxy versions before 11.6.2 do not validate proxied HTTP request paths for backslash …
@fastify/http-proxy versions before 11.6.2 do not validate proxied HTTP request paths for backslash based dot-segments before forwarding them to the configured upstream. The plain HTTP request handler skips the destination validation that the WebSocket path performs, and the underlying reply-from library only rejects forward-slash traversal, so a request containing backslash dot-segments can escap…
M Alto vulnerabilidad
03/09/2026
[CVE-2026-80735] In the Linux kernel, the following vulnerability has been resolved: ovpn: ensure socket is owned by…
In the Linux kernel, the following vulnerability has been resolved: ovpn: ensure socket is owned by ovpn before deref sk_user_data Some subsystems, like BPF SOCKMAP, set sk_user_data without actually setting the encap_type. For this reason, we must make sure that the type is the one ovpn expects before dereferencing sk_user_data. Failing to do so may lead to out-of-bounds reads.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-80738] In the Linux kernel, the following vulnerability has been resolved: bpf: Check sk_state before sk_p…
In the Linux kernel, the following vulnerability has been resolved: bpf: Check sk_state before sk_protocol in bpf_tcp_*_syncookie bpf_tcp_gen_syncookie and bpf_tcp_check_syncookie accept a socket pointer 'sk' with argument type ARG_PTR_TO_BTF_ID_SOCK_COMMON. However, they access sk->sk_protocol without validating whether 'sk' represents a full socket. Fix this issue by checking sk->sk_state != …
M Alto vulnerabilidad
02/09/2026
Vulnerabilidad alta en HTTPX2: falla de inicio de TLS en conexiones WebSocket seguras por proxy SOCKS5
HTTPX2 (cliente HTTP de próxima generación para Python) versiones anteriores a 2.10.0 no inicia correctamente TLS al conectar a servidores WebSocket seguro (wss://) a través de proxy SOCKS5, debido a que el validador de protocolo solo reconoce https. La falla afecta aplicaciones que usan Client.websocket() y AsyncClient.websocket() desde v2.6.0, exponiendo comunicaciones que deberían estar cifradas en entornos corporativos y financieros de LATAM.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-81624] Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how …
Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow handles WebSocket connections. Specifically, certain configuration limits like message buffer sizes and session timeouts cannot be adjusted and default to being unlimited. This allows a remote attacker to send large amounts of data or maintain connections indefinitely, potentially crashing …
M Alto vulnerabilidad
30/08/2026
Vulnerabilidad alta de desbordamiento de búfer en NASA Trick 19.6.0 (CVE-2026-82478)
Se identificó una vulnerabilidad de desbordamiento de búfer en pila en NASA Trick 19.6.0, específicamente en la función JSONVariableServerThread::parse_request del manejador de sockets TCP. Esta falla permite ejecución remota de código sin autenticación previa. Afecta principalmente a instituciones de investigación, universidades y centros aeroespaciales en Latinoamérica que utilizan esta herramienta de simulación científica.
M Crítico vulnerabilidad
29/08/2026
[CVE-2026-82448] Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that al…
Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries. Attackers reaching the child node port can present the hardcoded key during WebSocket handshake, then dispatch SQL queries through the onWebSocketDataFromChildNode handler to read and modify user records and camera configuration.
M Alto vulnerabilidad
27/08/2026
[CVE-2026-5680] A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending speciall…
A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDeflateFunction.largerBuffer() method using exponential doubling, resulting in a Denial of Service (DoS) for the affected application.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
27/08/2026
[CVE-2026-47888] A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framewo…
A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.0.RELEASE - 5.2.25.RELEASE
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-80585] In the Linux kernel, the following vulnerability has been resolved: mptcp: fastopen: only mark MPTF…
In the Linux kernel, the following vulnerability has been resolved: mptcp: fastopen: only mark MPTFO subflows with SYN data Passive TCP Fast Open accepts a valid-cookie SYN even when it carries no data. In that case the child socket's receive queue is intentionally left empty. mptcp_fastopen_subflow_synack_set_params() set is_mptfo before checking for queued SYN data. That made data-less TFO SY…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-58090] The SOCK_STREAM receive path in the unix socket implementation failed to fully detach control messag…
The SOCK_STREAM receive path in the unix socket implementation failed to fully detach control messages from the socket buffer before processing them. Some error paths would free those messages, leaving freed data mbufs in the receive socket buffer. An unprivileged local user can exploit this use-after-free to escalate privileges.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-65183] Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix …
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allows an unauthorised local user to access the unix domain socket. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.42 through 9.0.120. Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes t…
M Alto vulnerabilidad
25/08/2026
[CVE-2026-55571] djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered pe…
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to 1.0.4, LiveViewConsumer.handle_mount sends a `{"type":"navigate","to":...}` frame when login_required, permission_required, or a redirecting on_mount hook denies a LiveView mount, but returns without closing the WebSocket or clearing self.view_instance. A browser follows the redi…