Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,539
Total alertas
3075
Críticas
10192
Altas
8
Ransomware
1803
Esta semana
RSS
X Alto vulnerabilidad
05/06/2026
[CVE-2026-50258] A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has mu…
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes() does not verify or clamp non-canonical key types to XkbMaxShiftLevel. A client can change key types to excessive shift levels and trigger stack overflows. This is caused by an incomplete fix of CVE-2025-26597. This may…
X Alto vulnerabilidad
05/06/2026
[CVE-2026-50259] A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() …
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer mapWidths[256] indexed by key type index. The helper function CheckKeyTypes() writes to this buffer at a client-controlled offset, allowing a stack buffer overflow. This may be used to crash the server, or for privilege escalation if the X server runs as root.
X Alto vulnerabilidad
05/06/2026
[CVE-2026-50260] A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that s…
A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-after-free when destroying those counters via a second client connection. This may be used to crash the server, or for privilege escalation if the X server runs as root.
X Alto vulnerabilidad
05/06/2026
[CVE-2026-50261] A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client …
A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via a second client connection while changing those counters. This may be used to crash the server, or for privilege escalation if the X server runs as root.
X Alto vulnerabilidad
05/06/2026
[CVE-2026-50256] A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between …
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum font name length can cause a stack buffer overflow during font alias resolution. The server allocates a 256 byte stack buffer but libXfont2's alias target name length is 1024 bytes. A font alias name between 257 and 1023 bytes causes the X server to c…
X Alto vulnerabilidad
05/06/2026
[CVE-2026-50257] A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client…
A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a use-after-free function pointer call. An attacker would connect to the X server to set up a fence and await that fence, then a second X connection destroys the fence, causing the use-after-free. This may be used to crash the server, or for privileg…
S Alto vulnerabilidad
05/06/2026
[CVE-2026-21035] Improper input validation in Samsung Plus TV prior to version 1.0.28.6 allows remote attackers to ac…
Improper input validation in Samsung Plus TV prior to version 1.0.28.6 allows remote attackers to access sensitive information.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
S Alto vulnerabilidad
05/06/2026
[CVE-2026-21037] Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to acc…
Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to access arbitrary URL and launch arbitrary activity with Samsung Members privilege.
S Alto vulnerabilidad
05/06/2026
[CVE-2026-21030] Improper access control in MediaTek Audio HAL prior to SMR Jun-2026 Release 1 allows local attackers…
Improper access control in MediaTek Audio HAL prior to SMR Jun-2026 Release 1 allows local attackers to trigger privileged functions.
S Alto vulnerabilidad
05/06/2026
[CVE-2026-21031] Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch a…
Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activity. User interaction is required for triggering this vulnerability.
S Alto vulnerabilidad
05/06/2026
[CVE-2026-21032] Improper export of android application components in SmartHomeWidgetReceiver of Samsung Assistant pr…
Improper export of android application components in SmartHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script.
S Alto vulnerabilidad
05/06/2026
[CVE-2026-21033] Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant …
Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script.
M Alto vulnerabilidad
05/06/2026
[CVE-2026-11332] A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency speci…
A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galax…
M Crítico vulnerabilidad
05/06/2026
[CVE-2026-49777] Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider…
Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce allows Malicious Software Implanted. This issue affects Product Slider Pro for WooCommerce: from n/a before 3.5.4.
M Crítico vulnerabilidad
05/06/2026
[CVE-2026-6274] Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerabi…
Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electronics Industry and Trade Ltd. Co. Redline WR3200 allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Redline WR3200: from 7.1.3 before 7.1.8.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
H Alto vulnerabilidad
05/06/2026
[CVE-2026-21837] HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Man…
HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API.  An attacker may execute arbitrary operating system commands, typically inheriting the privileges of the vulnerable application, which could possibly lead to a complete system takeover and data compromise.
M Alto vulnerabilidad
05/06/2026
[CVE-2026-50593] Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actio…
Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset is within the allowed slot-map range.
M Crítico vulnerabilidad
05/06/2026
[CVE-2026-7762] A heap-based buffer overflow vulnerability in the dot11ah.ko HaLow Wi-Fi kernel driver in Morse Micr…
A heap-based buffer overflow vulnerability in the dot11ah.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attacker within radio range to cause a Denial of Service (kernel panic) or potentially achieve Remote Code Execution via a crafted 802.11ah beacon or probe response frame containing a malformed S1G Capabilities Information El…
M Crítico vulnerabilidad
05/06/2026
[CVE-2026-7763] A heap-based buffer overflow vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro …
A heap-based buffer overflow vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attacker within radio range to cause a Denial of Service (kernel panic) or potentially achieve Remote Code Execution via a crafted 802.11ah beacon frame containing a malformed Traffic Indication Map (TIM) Information Element. T…
M Alto vulnerabilidad
05/06/2026
[CVE-2026-41567] Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to…
Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries (such as `xz` or `unpigz`) from the container's filesystem rather than the host's due to incorrect ordering of operation…