Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1014
Esta semana
RSS
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-57545] Memory corruption when processing draw objects of incorrect type during graphics command list execut…
Memory corruption when processing draw objects of incorrect type during graphics command list execution.
M Alto vulnerabilidad
Hace 4 días
Vulnerabilidad alta en controlador i3c afecta validación de memoria del sistema
Se ha identificado una vulnerabilidad en el verificador de llamadas al sistema para i3c_do_ccc() en drivers/i3c/i3c_handlers.c que no valida correctamente los búferes de datos por destino en la estructura i3c_ccc_target_payload. Un atacante local podría explotar esta deficiencia para acceder o modificar memoria del kernel, afectando sistemas embebidos e IoT industriales comúnmente desplegados en infraestructura alta de LATAM.
M Crítico vulnerabilidad
02/10/2026
[CVE-2026-103764] Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::r…
Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to read and write arbitrary process memory via the TCP transport data port. Attackers can send a crafted SessionHeader with arbitrary addr and size values using READ or WRITE opcodes to disclose KV cache contents, prompts and secrets or corrupt memory …
M Alto vulnerabilidad
24/09/2026
[CVE-2026-58007] Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of…
Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through socfpga_v2.14.0.
M Alto vulnerabilidad
24/09/2026
[CVE-2026-58006] Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of…
Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through socfpga_v2.14.0.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-91795] Foxit PDF Editor/Reader's FileOpen plugin did not adequately validate certain encryption metadata in…
Foxit PDF Editor/Reader's FileOpen plugin did not adequately validate certain encryption metadata in specially crafted PDF files. This could leave an internal pointer in an invalid state, resulting in chained read and write access violations and potentially enabling arbitrary code execution.
M Alto vulnerabilidad
21/09/2026
[CVE-2026-94403] A weakness has been identified in ColorFul iGameCenter 1.0.3.4. This impacts the function sub_140001…
A weakness has been identified in ColorFul iGameCenter 1.0.3.4. This impacts the function sub_140001AF0 in the library ene.sys of the component IOCTL Handler. This manipulation causes untrusted pointer dereference. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did no…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
17/09/2026
[CVE-2025-59607] Memory Corruption when copying large input data exceeds normal allocation limits.
Memory Corruption when copying large input data exceeds normal allocation limits.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-83498] Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an autho…
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-83939] Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate…
Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-80083] Untrusted pointer dereference in Windows Hyper-V allows an authorized attacker to execute code local…
Untrusted pointer dereference in Windows Hyper-V allows an authorized attacker to execute code locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-78444] Untrusted pointer dereference in Windows Failover Cluster allows an unauthorized attacker to execute…
Untrusted pointer dereference in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69900] Untrusted pointer dereference in Kernel Streaming WOW Thunk Service Driver allows an authorized atta…
Untrusted pointer dereference in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69874] Untrusted pointer dereference in Windows ALPC allows an authorized attacker to elevate privileges lo…
Untrusted pointer dereference in Windows ALPC allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69717] Untrusted pointer dereference in Windows Group Policy allows an authorized attacker to elevate privi…
Untrusted pointer dereference in Windows Group Policy allows an authorized attacker to elevate privileges over a network.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69501] Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate…
Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69475] Untrusted pointer dereference in Windows Remote Desktop Services allows an authorized attacker to el…
Untrusted pointer dereference in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-67378] Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a net…
Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
20/08/2026
[CVE-2026-19442] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtua…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtual SCSI (vSCSI) initiator driver. Successful exploitation may result in denial of service, privilege escalation, or full compromise of the client LPAR kernel.
M Alto vulnerabilidad
20/08/2026
[CVE-2026-18840] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to improper validation of an attacker-controlled pointer.