Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1013
Esta semana
RSS
M Alto vulnerabilidad
08/09/2026
[CVE-2026-70573] Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate pri…
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-70581] Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate…
Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-69845] Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code ov…
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69614] Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute co…
Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69352] Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate pri…
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69293] Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate pri…
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69295] Out-of-bounds read in Windows USB Driver allows an authorized attacker to elevate privileges locally…
Out-of-bounds read in Windows USB Driver allows an authorized attacker to elevate privileges locally.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69270] Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized att…
Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-68839] Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker …
Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-79376] An issue in the l2cap_handle_data() function of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firm…
An issue in the l2cap_handle_data() function of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows attackers to cause a Denial of Service (DoS) via sending a crafted L2CAP packet.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-62647] A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A random number generat…
A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A random number generator is used to generate security-relevant values (such as session identifiers used for authentication purposes) that is not initialized with a True Random Number Generator (TRNG), resulting in a predictable sequence of generated values. This could allow an unauthenticated remote attacker to more easi…
M Alto vulnerabilidad
07/09/2026
[CVE-2022-51017] PocketMine-MP versions before 3.26.5 and 4.0.5 fail to validate the length of skin data fields submi…
PocketMine-MP versions before 3.26.5 and 4.0.5 fail to validate the length of skin data fields submitted by players, allowing uncapped values to exceed the 32767 byte TAG_String limit. Attackers can submit oversized skin data fields like skinID or geometryName to trigger exceptions during NBT data serialization, causing server crashes.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-84469] fastify versions before 5.12.2 decide whether to compile a request schema based on JavaScript truthi…
fastify versions before 5.12.2 decide whether to compile a request schema based on JavaScript truthiness, but JSON Schema Draft 7 defines the boolean false as a valid schema that rejects every instance. When an application assigns false to a route's body, querystring, params, or headers schema to deny all input, fastify treats it as a missing schema, compiles no validator, and runs the route handl…
M Alto vulnerabilidad
04/09/2026
[CVE-2026-84504] fastify versions before 5.12.2 treat the object resolved by a successful Ajv async validator as the …
fastify versions before 5.12.2 treat the object resolved by a successful Ajv async validator as the value result protocol used by custom validator compilers. If a request that passes its route schema contains a property named value at the root, fastify replaces the entire request body with that property's value before the handler runs, so the handler receives a different object than the one that s…
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85047] Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82…
Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-84325] Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote a…
Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app. (Chromium security severity: High)
M Alto vulnerabilidad
30/08/2026
[CVE-2026-82648] WWBN AVideo contains a server-side request forgery filter bypass vulnerability in the isSSRFSafeURL …
WWBN AVideo contains a server-side request forgery filter bypass vulnerability in the isSSRFSafeURL function that fails to normalize NAT64 addresses written in hexadecimal form. Attackers can bypass SSRF protections by supplying hex-encoded NAT64 addresses like 64:ff9b::a9fe:a9fe to reach cloud metadata services and loopback interfaces.
M Alto vulnerabilidad
30/08/2026
[CVE-2026-82639] NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the…
NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that allows attackers to obtain the server's OpenAI API key. The x-base-url header is validated using substring matching instead of hostname parsing, allowing any URL containing 'api.openai.com' to pass validation and receive the server's credentials in the Authorization header.
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-81707] openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allow…
openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inject ANSI escape sequences that forge the fingerprint verification line displayed to users. Attackers can deliver a crafted identity bundle through normal contact-exchange flows or keyserver responses to manipulate terminal output and display a fraudulent fingerprint, bypassing th…
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-57499] Liman is open source server management software. Prior to 2.2.2 - 1103, an OS command injection vuln…
Liman is open source server management software. Prior to 2.2.2 - 1103, an OS command injection vulnerability in the log rotation configuration endpoint allows an authenticated administrator to execute arbitrary operating system commands on the Liman server. The `ip_address` parameter is embedded directly into a shell command without sanitization, enabling shell escape via single-quote injection. …