Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1012
Esta semana
RSS
M Alto vulnerabilidad
04/09/2026
Vulnerabilidad alta de consumo de recursos en SiYuan anterior a v3.8.2
SiYuan versiones anteriores a v3.8.2 contiene una vulnerabilidad que permite a atacantes no autenticados consumir memoria ilimitada del servidor mediante solicitudes con rutas únicas, degradando la disponibilidad del servicio. Esta falla afecta principalmente a organizaciones en LATAM que utilizan SiYuan para gestión de notas y documentos internos. La vulnerabilidad puede ser explotada sin credenciales, permitiendo ataques de negación de servicio (DoS) contra instancias accesibles en red.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85443] MOOS core-moos through 10.4.0 contains a denial of service vulnerability in MOOSCommServer::ListenLo…
MOOS core-moos through 10.4.0 contains a denial of service vulnerability in MOOSCommServer::ListenLoop() where the accept thread performs a blocking receive without timeout during the wire-protocol handshake. An attacker can open a TCP connection to the MOOSDB port and send no data, causing the accept thread to block indefinitely while holding the socket-list lock, preventing all subsequent client…
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84375] js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2 and 4.3.2, maxTotalMergeKeys…
js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2 and 4.3.2, maxTotalMergeKeys in lib/js-yaml/loader.js and lib/loader.js does not count empty mapping sources while processing the merge key
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82397] Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parse…
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parses application/x-www-form-urlencoded request bodies with urllib.parse.parse_qs in tornado/escape.py without passing max_num_fields. RequestHandler._execute in tornado/web.py parses the body before handler dispatch through HTTPServerRequest._parse_body and parse_body_arguments in tornado/httputil.py, …
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad DoS en multer permite bloqueo de event loop en Node.js
multer, middleware popular para procesar multipart/form-data en Node.js, es vulnerable a ataques de denegación de servicio (DoS). Un atacante puede enviar solicitudes HTTP especialmente diseñadas con nombres de campo malformados que fuerzan al parser a iterar arreglos sparse de tamaño máximo, bloqueando el event loop e impidiendo que la aplicación procese otras peticiones. Afecta aplicaciones web en producción que usen multer para carga de archivos, especialmente relevante en empresas LATAM con infraestructura Node.js alta.
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad en multer 2.2.0: descriptor de archivo no cerrado en cargas abortadas
multer, middleware de Node.js para procesar multipart/form-data, presenta una vulnerabilidad en la versión 2.2.0 donde las cargas abortadas o truncadas no cierran correctamente los descriptores de archivo, dejándolos abiertos en el sistema. Esto permite a atacantes remotos consumir recursos del servidor y potencialmente acceder a información sensible. El riesgo es alta en aplicaciones web que manejan uploads de usuarios sin autenticación robusta.
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-55248] plone.app.portlets provides portlets and a Plone-specific user interface for plone.portlets. Prior t…
plone.app.portlets provides portlets and a Plone-specific user interface for plone.portlets. Prior to 5.0.8, 6.0.4, and 7.0.2, a member who can add an RSS portlet can set its feed URL to a very large response, causing src/plone/app/portlets/portlets/rss.py to download and retain excessive data in memory and deny service. The same RSS URL handling accepts internal hosts, IP addresses, single-word d…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-55247] plone.app.event provides the event content type for Plone. Prior to versions 5.2.4 and 6.0.1, the iC…
plone.app.event provides the event content type for Plone. Prior to versions 5.2.4 and 6.0.1, the iCalendar import in src/plone/app/event/ical/importer.py accepts insufficiently restricted calendar and event URLs, does not adequately bound downloaded bytes or imported events, and commits work per event. A logged-in editor can make the server request internal network resources or local calendar fil…
M Alto vulnerabilidad
28/08/2026
[CVE-2026-55108] KubeVela is an open source application delivery platform. Prior to 1.9.14, from 1.10.0-alpha.1 until…
KubeVela is an open source application delivery platform. Prior to 1.9.14, from 1.10.0-alpha.1 until 1.10.9, and from 1.11.0-alpha.1 until 1.11.0-alpha.4, the Terraform remote configuration loader in pkg/controller/utils/capability.go, GetTerraformConfigurationFromRemote, clones a repository supplied through a core.oam.dev/v1beta1 ComponentDefinition and follows repository-controlled variables.tf …
M Alto vulnerabilidad
28/08/2026
[CVE-2026-38638] An issue in the with_argv function (/unistd/mod.rs) of relibc commit 61f42d allows attackers to caus…
An issue in the with_argv function (/unistd/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-37237] vLLM up to and including 0.17.0 allows remote attackers to cause a Denial of Service via memory exha…
vLLM up to and including 0.17.0 allows remote attackers to cause a Denial of Service via memory exhaustion. The AsyncMediaIO.fetch_audio and AsyncMediaIO.fetch_image functions in multimodal/inputs.py fetch user-supplied media URLs using aiohttp and call r.read() without enforcing a maximum response size, allowing an attacker to exhaust server memory by providing a URL to an arbitrarily large file.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-38636] An issue in the seekdir() function (/dirent/mod.rs) of relibc commit 61f42d allows attackers to caus…
An issue in the seekdir() function (/dirent/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input.
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad de agotamiento de memoria en SvelteKit 2.49.0-2.52.1 con funciones remotas
SvelteKit (@sveltejs/kit) versiones 2.49.0 a 2.52.1 con funciones remotas experimentales (experimental.remoteFunctions) contienen una vulnerabilidad de agotamiento de memoria que permite a atacantes causar negación de servicio mediante datos de formulario malformados. La asignación excesiva de memoria resultante provoca caída del proceso del servidor, afectando aplicaciones web en producción. Empresas en LATAM que usan estas versiones con esta característica experimental habilitada están en riesgo alta.
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad de agotamiento de CPU en SvelteKit 2.49.0-2.52.1 permite denegación de servicio
SvelteKit versiones 2.49.0 a 2.52.1 con funciones remotas experimentales habilitadas contienen una vulnerabilidad que permite a atacantes enviar datos de formulario malformados para agotar recursos de CPU del servidor, causando indisponibilidad del servicio. Afecta aplicaciones web en producción en LATAM que usan estas versiones. La vulnerabilidad fue corregida en versión 2.52.2.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-42391] An unauthenticated attacker can send an IMAP ID command with a very large number of parameters befor…
An unauthenticated attacker can send an IMAP ID command with a very large number of parameters before logging in, which causes memory and CPU usage to grow disproportionately. The login process can be terminated by the out-of-memory handling, which also terminates all other connections handled by the same process. This can cause degradation or denial of service for IMAP logins. Limit the number of…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
28/08/2026
[CVE-2026-27852] An attacker that can send mail to a user can craft a message whose headers contain a very large numb…
An attacker that can send mail to a user can craft a message whose headers contain a very large number of email addresses or MIME parameters, which causes excessive memory usage when the message is later parsed. The message is still delivered, but reading it over IMAP can exhaust the memory limit of the process and terminate it, causing denial of service for the affected user. Update to non-vulner…
M Alto vulnerabilidad
28/08/2026
[CVE-2026-33605] An unauthenticated attacker can crash the ManageSieve login process by sending a small malformed com…
An unauthenticated attacker can crash the ManageSieve login process by sending a small malformed command before authenticating. If running in high-security mode (default for community releases), only the attacker's own connection is terminated. If running in high-performance mode (default for Pro releases), all connections handled by the same managesieve-login process are terminated. Repeating the…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-53580] Trilium is an open-source hierarchical note-taking application. In versions prior to 0.104.0, the au…
Trilium is an open-source hierarchical note-taking application. In versions prior to 0.104.0, the automatic image-download feature accepts file:// URLs in a note's img tags and reads the referenced local file with no path validation, allowing any authenticated user to disclose arbitrary files readable by the Trilium process. When a text note is saved, Trilium scans its HTML for image sources and d…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-81721] openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and ke…
openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and keystore headers, allowing attackers to trigger unbounded memory allocation. Attackers can craft malicious encrypted files declaring arbitrarily large Argon2, scrypt, or balloon KDF parameters to exhaust system memory and crash the process without authentication.
M Alto vulnerabilidad
27/08/2026
[CVE-2026-47886] Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulner…
Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand and a large exponent value. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3…