Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1012
Esta semana
RSS
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-14888] IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10,…
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to execute arbitrary code due to a heap-based buffer overflow.
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-14269] IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10,…
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. An unauthenticated remote attacker could overflow the buffer and execute arbitrary code on the system.
M Alto vulnerabilidad
Hace 1 día
Desbordamiento de búfer en rutina Blowfish de hMailServer 6.0.0-6.3.3 (CVE-2026-103010)
Vulnerabilidad alta en Progressive Robot hMailServer permite a usuarios locales sin credenciales ejecutar desbordamiento de búfer en memoria heap mediante la rutina DecryptFromString, afectando servidores de correo en Windows. El proceso del servicio ejecuta con privilegios LocalSystem, permitiendo escritura de bytes arbitrarios con potencial acceso a datos sensibles y ejecución de código. Impacta infraestructuras de correo empresarial en México y LATAM que mantienen versiones 6.0.0 a 6.3.3.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107161] A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DI…
A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes the size of the buffer needed for a challenge/response field before DIGEST-MD5 quoting is applied, but does not recompute that size when quoting (escaping special characters) makes the value longer. The under-sized buffer is then passed to strcat(), causing a heap-based out-…
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-76471] A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote…
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device.  The vulnerability is due to insufficient input validation of data that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP r…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-46570] In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_index_walk_down() in libntfs-3g/in…
In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_index_walk_down() in libntfs-3g/index.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by reading the special crafted file metadata.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-46572] In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ib_cut_tail() in libntfs-3g/index.…
In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ib_cut_tail() in libntfs-3g/index.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by creating a file in a specially crafted directory.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-42618] In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_decompress() in compress.c that al…
In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_decompress() in compress.c that allows an attacker to corrupt one byte of heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by reading the special crafted file.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-42617] In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ir_to_ib() in index.c that allows …
In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ir_to_ib() in index.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by extending a directory, e.g., by creating a file.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-106292] Buffer overflow in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had c…
Buffer overflow in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-106247] Buffer overflow in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had c…
Buffer overflow in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-58835] In cfg2prop of btif_storage.cc, there is a possible out-of-bounds write due to a heap buffer overflo…
In cfg2prop of btif_storage.cc, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-14316] The revoked-key error path builds a human-readable failure reason using sprintf() into a heap buffer…
The revoked-key error path builds a human-readable failure reason using sprintf() into a heap buffer. The allocated buffer is too small for the final formatted message. When sprintf() writes the full message, it can write past the end of the heap allocation.
M Alto vulnerabilidad
30/09/2026
Vulnerabilidad alta en RPM: desbordamiento de búfer por paquete RPM malformado
Se detectó un desbordamiento de búfer en la pila de RPM que permite a atacantes ejecutar código arbitrario mediante paquetes RPM sin firmar con etiqueta RPMTAG_FILESIGNATURES malformada. La vulnerabilidad es accesible a través de herramientas comunes como rpm2cpio, rpm2archive y rpm -qlvp, afectando sistemas Linux en infraestructuras altas de LATAM (servidores, contenedores, pipelines CI/CD). Con CVSS 7.1, representa riesgo alto para empresas que gestionan repositorios RPM o usan distribuciones basadas en Red Hat/CentOS.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-102331] Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote atta…
Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-95350] Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote atta…
Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-95349] Buffer overflow in WebGL in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote atta…
Buffer overflow in WebGL in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-95318] Buffer overflow in Video in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potent…
Buffer overflow in Video in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-95281] Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote atta…
Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-95283] Buffer overflow in Tint in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attac…
Buffer overflow in Tint in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)