Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1815
Esta semana
RSS
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-71263] The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool() (demo/LINUXT…
The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool() (demo/LINUXTCP/port/porttcp.c). The check `if (usTCPFrameBytesLeft > MB_TCP_BUF_SIZE)` uses a strict greater-than comparison instead of greater-than-or-equal against the 263-byte MB_TCP_BUF_SIZE limit. An MBAP frame with a Length field of 264 makes usTCPFrameBytesLeft equal to 263, which passes the flawed check…
M Crítico vulnerabilidad
05/08/2026
Vulnerabilidad crítica en nanoMODBUS v1.23.0: desbordamiento de búfer en servidor
nanoMODBUS hasta la versión 1.23.0 contiene un desbordamiento de búfer (out-of-bounds write) en la función handle_read_file_record() del servidor Modbus (FC 0x14). La validación de tamaño de solicitud es insuficiente, permitiendo que atacantes remotos causen escritura de memoria fuera de límites a través de múltiples sub-solicitudes acumulativas. Afecta infraestructuras SCADA, sistemas embebidos y dispositivos IoT industriales comunes en manufactura y utilidades de LATAM.
M Alto vulnerabilidad
05/08/2026
Vulnerabilidad alta en nanoMODBUS v1.23.0: desbordamiento de búfer en lectura de identificación
nanoMODBUS versiones anteriores a v1.24.0 contiene una escritura fuera de límites en la función recv_read_device_identification_res() (FC 0x2B/MEI 0x0E) que permite a servidores Modbus remotos sobrescribir memoria del cliente. Esta vulnerabilidad afecta sistemas de automatización industrial, SCADA y dispositivos IoT en plantas manufactureras, utilities y infraestructura alta en LATAM. Un atacante en la red puede ejecutar código arbitrario o causar denial of service explotando validaciones insuficientes del campo object_length.
M Alto vulnerabilidad
04/08/2026
[CVE-2026-24253] NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds writ…
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service and data tampering.
M Alto vulnerabilidad
03/08/2026
[CVE-2026-10849] The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response…
The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update server into a heap buffer in response_json_cb() (subsys/mgmt/hawkbit/hawkbit.c). The buffer is sized to hold the received body bytes but reserves no space for a terminating NUL. When the full response has arrived, the code writes response_data[downloaded_size] = '\0' — and whenever …
M Alto vulnerabilidad
02/08/2026
Vulnerabilidad alta en cliente OCPP 1.6: desbordamiento de buffer en parse_rpc_msg()
Se detectó una falla de seguridad en el procesamiento de marcos WAMP RPC dentro del cliente OCPP 1.6 (subsys/net/lib/ocpp). La función extract_string_field() utiliza strncpy() sin garantizar NUL-terminación, permitiendo lectura de memoria adyacente mediante campos uid y action malformados. Esto afecta sistemas de carga de vehículos eléctricos y controladores IoT en infraestructura de movilidad en Latinoamérica.
M Crítico vulnerabilidad
02/08/2026
[CVE-2026-68579] FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard cli…
FreeRDP before 3.30.0 (

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
31/07/2026
[CVE-2026-34641] Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code…
Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-47876] VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A m…
VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17727] Out of bounds write in WebGL in Google Chrome on Android prior to 151.0.7922.72 allowed a remote att…
Out of bounds write in WebGL in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17721] Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to po…
Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17691] Out of bounds write in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote att…
Out of bounds write in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17675] Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who h…
Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
29/07/2026
[CVE-2026-18022] Integer wraparound in IVFFlat index build in pgvector before 0.8.6 allows a database user to write d…
Integer wraparound in IVFFlat index build in pgvector before 0.8.6 allows a database user to write data out-of-bounds, which could lead to arbitrary code execution. Only 32-bit systems are affected.
M Alto vulnerabilidad
29/07/2026
[CVE-2026-18220] An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c…
An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform adequate bounds checking on attacker-controlled relocation type values (via ELF32_R_TYPE(r_info)) before indexing into the dlx_elf_howto_table[] array. The DLX relocation …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
29/07/2026
[CVE-2026-58188] Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. This…
Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
A Alto vulnerabilidad
29/07/2026
[CVE-2026-58184] The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations…
The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
A Alto vulnerabilidad
29/07/2026
[CVE-2026-58177] The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-f…
The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 10.1.4, which fix the issue.
M Alto vulnerabilidad
29/07/2026
[CVE-2026-58154] Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP heade…
Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
M Alto vulnerabilidad
28/07/2026
[CVE-2026-15057] IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of se…
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrolled heap allocation.