Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1014
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-107838] RIOT is an open-source microcontroller operating system designed for Internet of Things devices and …
RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. From version 2023.07 through version 2026.07, nanocoap_fileserver callers in sys/net/application_layer/nanocoap/fileserver.c ignore a failure returned by _resp_init() when coap_build_reply() cannot fit a response header into the response buffer. A remote client can send a CoA…
M Alto vulnerabilidad Nuevo
Hace 2 horas
[CVE-2026-39453] Navigating to a certain URL on the switch’s web server causes the switch to reboot. This can be auto…
Navigating to a certain URL on the switch’s web server causes the switch to reboot. This can be automated using a tool like curl to create DoS conditions where the switch constantly reboots.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-103104] Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in th…
Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation which allows a remote attacker to trigger a software abort resulting in a denial of service.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-103108] Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation in t…
Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting in a denial of service
M Alto vulnerabilidad
30/09/2026
[CVE-2026-103099] Pexip Infinity before 41.1 is affected by improper input validation in the media implementation that…
Pexip Infinity before 41.1 is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting in a denial of service.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-103100] Pexip Infinity before 40.1 is affected by improper input validation in the signaling implementation …
Pexip Infinity before 40.1 is affected by improper input validation in the signaling implementation that allows a malicious attacker to trigger a software abort resulting in a denial of service.
M Alto vulnerabilidad
21/09/2026
[CVE-2026-94623] vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix cachin…
vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fails to properly validate block counts across multi-prompt completion requests in prefill/decode disaggregated deployments. Attackers can trigger an assertion failure in NixlBaseConnectorWorker._apply_prefix_caching by submitting completion requests with multiple prompts of va…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
17/09/2026
[CVE-2026-92971] InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistServe decod…
InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistServe decode migration loop that allows unauthenticated attackers to terminate the inference engine. Attackers can submit a migration_request with an empty remote_block_ids list to trigger an AssertionError that crashes the engine loop and causes subsequent inference requests to fail.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-80274] If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative serve…
If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC at the same owner name, it will trigger an unexpected program exit. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-76163] If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker …
If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of QTYPE TKEY which may cause an assertion failure and subsequent unexpected program exit. This issue affects BIND 9 versions 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, and 9.20.9-S1 through 9.20.27-S1.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad alta en libp2p-rendezvous permite desbordamiento de temporizador en clientes
libp2p-rendezvous versión 0.17.1 y anteriores no valida correctamente los valores TTL en respuestas de descubrimiento, permitiendo que servidores rendezvous maliciosos causen pánico en procesos cliente mediante aritmética de temporizador no limitada. Afecta infraestructuras de red descentralizada, nodos blockchain y aplicaciones P2P en México y LATAM.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-75584] ION-DTN before 4.2.1-a.1 contains a denial of service vulnerability that allows unauthenticated remo…
ION-DTN before 4.2.1-a.1 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash the ION process by sending a BPv7 bundle with a zero-length payload. The canonicalizePayloadBlock() function in bpsec_util.c passes bundle->payload.length to zco_clone() without validating it against zero, causing a failed CHKZERO assertion that triggers sm_Abort() and terminat…