Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1012
Esta semana
RSS
M Alto vulnerabilidad
29/09/2026
[CVE-2026-100761] Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was…
Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-100762] Sandbox escape due to use-after-free in the DOM: Content Processes component. This vulnerability was…
Sandbox escape due to use-after-free in the DOM: Content Processes component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-100765] Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR…
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-100767] Use-after-free in the Networking: Cache component. This vulnerability was fixed in Firefox ESR 153.4…
Use-after-free in the Networking: Cache component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
M Alto vulnerabilidad
25/09/2026
[CVE-2026-93834] A use-after-free vulnerability was found in QEMU's 9pfs subsystem. A race condition between the main…
A use-after-free vulnerability was found in QEMU's 9pfs subsystem. A race condition between the main thread and a worker thread when processing concurrent Tlcreate and Twalk requests allows a malicious guest user to craft a fid path containing stale heap data, bypassing directory traversal restrictions and escaping the shared directory boundary. This can lead to arbitrary host file read/write and …
M Crítico vulnerabilidad
23/09/2026
[CVE-2026-6928] IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed. This allows a…
IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed. This allows an attacker who can influence program execution or input may exploit this condition to corrupt memory, cause application crashes, or execute arbitrary code.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-96889] A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincl…
A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate entity declarations, a use-after-free error can occur. This vulnerability arises because the library incorrectly frees an XML entity that is still in use by the parser. An attacker could potentially exploit this to cause a denial of service or execute arbitrary code.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
23/09/2026
[CVE-2026-91818] A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s JavaScript handling of PDF annota…
A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s JavaScript handling of PDF annotations. Reentrant page-event processing during annotation enumeration may release the associated page object, which is subsequently accessed, resulting in an application crash.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-91809] A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed PDF form fi…
A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed PDF form fields. Improper validation during field-name traversal may cause the application to access a released object, resulting in an application crash.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-91816] A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of PDF annotations. Reen…
A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of PDF annotations. Reentrant annotation deletion triggered by embedded JavaScript can cause the application to access an annotation object after it has been released, resulting in a use-after-free condition and application crash.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-91805] A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s PDF page-tree handling. A special…
A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s PDF page-tree handling. A specially crafted PDF can trigger page-structure changes during rendering, causing the application to access released page objects and resulting in memory corruption and an application crash.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-91806] A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of PDF form fields. Embe…
A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of PDF form fields. Embedded JavaScript may access form-field references after the corresponding fields have been released, resulting in an application crash.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-91792] When processing a specially crafted PDF, Foxit PDF Editor/Reader may perform reentrant zoom and layo…
When processing a specially crafted PDF, Foxit PDF Editor/Reader may perform reentrant zoom and layout operations through page- and annotation-related JavaScript actions. This can cause the application to access page objects after they have been released, resulting in a use-after-free condition and an application crash.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-91793] When opening a specially crafted PDF, Foxit PDF Editor/Reader executes scripts that modify annotatio…
When opening a specially crafted PDF, Foxit PDF Editor/Reader executes scripts that modify annotation rich-text attributes containing malformed font data. During subsequent annotation appearance reconstruction, it accesses an object after it has been released, resulting in a use-after-free condition and an application crash.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-91799] A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of JavaScript array obje…
A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of JavaScript array objects. A specially crafted PDF may cause the application to access a released object during array processing, potentially resulting in application crashes or arbitrary code execution.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
23/09/2026
[CVE-2026-91790] When rendering the page image, Foxit PDF Editor/Reader fails to perform validation on image objects …
When rendering the page image, Foxit PDF Editor/Reader fails to perform validation on image objects whose optional content attributes are malformed. As a result, the program may access an already-freed internal data structure, triggering a crash due to UAF.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-91791] When processing a specially crafted PDF file, Foxit PDF Editor/Reader may encounter a reentrant exec…
When processing a specially crafted PDF file, Foxit PDF Editor/Reader may encounter a reentrant execution condition involving JavaScript triggered by page-visibility events. This can cause the application to access a released page-view object while calculating annotation boundaries, resulting in an invalid memory read and application crash.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-74766] Net::IDN::Punycode versions from 2.301 before 2.590 for Perl allow a heap use-after-free via a decod…
Net::IDN::Punycode versions from 2.301 before 2.590 for Perl allow a heap use-after-free via a decoded code point that reallocates the output buffer in decode_punycode. The XS backend inserts each decoded code point into the string buffer of the scalar it returns. decode_punycode computes the insertion pointer first and only then grows the buffer when the code point does not fit. The growth reall…
M Alto vulnerabilidad
21/09/2026
[CVE-2026-73512] Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36…
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's HttpDatagramHandler caches the current RequestDecoder when Capsule Protocol is enabled. Stream recreation, including an internal redirect, replaces the ActiveStream and updates EnvoyQuicServerStream but does not update the handler's cached pointer. A subseque…
M Alto vulnerabilidad
21/09/2026
[CVE-2026-73513] Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36…
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's optional oghttp2 upstream HTTP/2 codec accepts a response trailer HEADERS frame without END_STREAM. Envoy completes and deferred-deletes the ActiveRequest while oghttp2 keeps the stream open, leaving ClientStreamImpl with a dangling response_decoder_ referenc…