Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-79811] A SQL injection vulnerability in the API of ClearPass Policy Manager could allow a remote authentica…
A SQL injection vulnerability in the API of ClearPass Policy Manager could allow a remote authenticated attacker with administrative privileges to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful exploitation could allow an attacker to execute arbitrary database commands.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-79797] An improper access control vulnerability exists in the Android client application for HPE Networking…
An improper access control vulnerability exists in the Android client application for HPE Networking ClearPass Policy Manager, where application functionality may be invoked by untrusted sources. Successful exploitation could allow an unauthenticated remote attacker, with user interaction, to obtain sensitive information from the affected user.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-79799] A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an una…
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-79800] An authenticated path traversal vulnerability exists in the command line interface of ClearPass Poli…
An authenticated path traversal vulnerability exists in the command line interface of ClearPass Policy Manager. Successful exploitation could allow a low-privileged authenticated remote attacker to execute arbitrary code with elevated privileges on the underlying operating system.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-79802] A command injection vulnerability exists in the client software of ClearPass Policy Manager. Success…
A command injection vulnerability exists in the client software of ClearPass Policy Manager. Successful exploitation could allow an attacker who is able to supply crafted input to the affected software to execute arbitrary commands with elevated privileges on the affected host.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-79803] A command injection vulnerability exists in the API of ClearPass Policy Manager. Successful exploita…
A command injection vulnerability exists in the API of ClearPass Policy Manager. Successful exploitation could allow an authenticated remote attacker to escalate privileges and gain administrative control of the affected system.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-76748] A privilege escalation vulnerability exists in the API of AOS-S. Successful exploitation could allow…
A privilege escalation vulnerability exists in the API of AOS-S. Successful exploitation could allow an authenticated read-only user to escalate their privileges and gain administrative access to the affected system.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-103009] Authorization Bypass Through User-Controlled Key (CWE-639) in Elasticsearch can lead to Information …
Authorization Bypass Through User-Controlled Key (CWE-639) in Elasticsearch can lead to Information Disclosure via a specially crafted cross-cluster search request that references an unauthorized shard identifier. Elasticsearch contains an authorization bypass weakness in its handling of cross-cluster search requests made through the Remote Cluster Security (RCS) 2.0 model. An authorization check …
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-103007] Incorrect Authorization (CWE-863) in Elasticsearch can lead to Privilege Escalation via a delegated …
Incorrect Authorization (CWE-863) in Elasticsearch can lead to Privilege Escalation via a delegated administrative privilege whose scope is not fully enforced during authorization checks. Elasticsearch contains an incorrect authorization weakness in a configurable, non-default privilege that lets an administrator delegate limited role-management capability to another user, scoped to specific indic…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-102406] Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana could lead to cross-tenant data…
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana could lead to cross-tenant data interception. In this context, "tenant" refers to a user or team sharing the same Kibana deployment, not a separate Elastic Cloud organization or customer. Kibana's Fleet package installation process allowed a user holding delegated Fleet package-management privileges, without direct Elasticsearch …
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-102160] An operating system (OS) command injection vulnerability in CloudVision CUE backup management may al…
An operating system (OS) command injection vulnerability in CloudVision CUE backup management may allow an authenticated Super User to submit a crafted backup request and execute arbitrary commands with the privileges of the affected service.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-102161] An unauthenticated attacker located on an adjacent private network (or any attacker routed through a…
An unauthenticated attacker located on an adjacent private network (or any attacker routed through a reverse proxy/load balancer that forwards client headers) can forge their source IP address and gain administrative session privileges on the CV-CUE backend.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-102162] On affected Arista Wi-Fi access points with captive portal, or application firewall enabled on at le…
On affected Arista Wi-Fi access points with captive portal, or application firewall enabled on at least one SSID, a vulnerability in the wireless gateway service could allow an unauthenticated network-adjacent attacker to send a crafted packet that triggers a stack overflow, resulting in a denial-of-service condition or potentially execute arbitrary code on the device. The wireless gateway service…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-102163] On affected Arista access points with Wireless Intrusion Prevention System (WIPS) active, an unauthe…
On affected Arista access points with Wireless Intrusion Prevention System (WIPS) active, an unauthenticated attacker within radio frequency (RF) proximity can send a crafted frame to crash the sensor service, disabling WIPS monitoring on the access point, or potentially achieve remote code execution. No wireless association or authentication is required.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-102165] On affected Arista Wi-Fi access points, an unauthenticated attacker with network access to the captu…
On affected Arista Wi-Fi access points, an unauthenticated attacker with network access to the capture service can send a crafted packet to cause the service to crash or potentially achieve remote code execution. This exploit requires an uncommonly used non-default streaming mode.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-102167] On affected Arista Wi-Fi access points, a memory corruption vulnerability exists in access point's w…
On affected Arista Wi-Fi access points, a memory corruption vulnerability exists in access point's wired uplink network endpoints. An unauthenticated attacker can crash the sensor service or potentially achieve remote code execution. Exploitation requires the attacker to be on the same network segment as the access point's wired uplink.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-101158] A missing input validation vulnerability in the Fileserver upload API allows an authenticated attack…
A missing input validation vulnerability in the Fileserver upload API allows an authenticated attacker with file upload privileges to execute stored cross-site scripting (XSS). Successful exploitation could enable the attacker to hijack another CloudVision user's web session, potentially granting full access to their account and administrative permissions.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-102155] An XML External Entity (XXE) injection vulnerability in the WiFi-server Spectralight application all…
An XML External Entity (XXE) injection vulnerability in the WiFi-server Spectralight application allows any authenticated user to send malicious requests, leading to arbitrary local file disclosure and partial denial of service.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-101152] Insufficient validation in the Single Sign-On (SSO) login flow could allow a remote, unauthenticated…
Insufficient validation in the Single Sign-On (SSO) login flow could allow a remote, unauthenticated attacker to craft a URL that, when clicked by a user, causes the identity provider (IdP) to deliver authentication material to an attacker-controlled URL instead of to CloudVision.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-101153] On affected versions of CloudVision Portal (on-premises) or CloudVision Sensor, a path traversal vul…
On affected versions of CloudVision Portal (on-premises) or CloudVision Sensor, a path traversal vulnerability exists. An authenticated user with sufficient high privileges could exploit this to extract unintended data from the Sensor.