Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1054
Esta semana
RSS
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105797] SimpleChat is a secure AI conversation application with personal and group workspaces for document-g…
SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. In versions 0.261.003 and 0.261.027, an authorization ordering flaw in POST /api/user/plugins allows an authenticated low-privileged user to omit the top-level MCP type so that _reject_non_admin_mcp_stdio skips inspection before the type is restored from metadata. The stored pe…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105798] SimpleChat is a secure AI conversation application with personal and group workspaces for document-g…
SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.261.029, POST /api/group_documents/upload stores an attacker-controlled group document filename that group_workspaces.html later interpolates into inline Share event handlers. The escapeGroupHtml function leaves apostrophes unchanged, while escapeHtml produces an HTM…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105791] Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. P…
Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the run_shell tool in the CommandLineExecutor component of ufo/client/mcp/local_servers/cli_mcp_server.py validates only the first token of the bash_command parameter and permits explorer.exe. On Windows, explorer.exe delegates its following path argument to ShellExecute, so an attack…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-104069] HortusFox before 6.2 contains a remote code execution vulnerability in ThemeModule::startImport() wh…
HortusFox before 6.2 contains a remote code execution vulnerability in ThemeModule::startImport() where an uploaded ZIP archive is extracted directly into the public web root before any validation of file names, extensions, or content is performed. An authenticated administrator can upload a crafted theme archive containing a PHP file and an .htaccess file to re-enable execution, then request it u…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-85523] Improper neutralization of special elements used in an OS command ('OS command injection') vulnerabi…
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Felisify Information Technologies Industry and Trade Inc. SambaBox allows OS Command Injection. This issue affects SambaBox: before 5.4.1.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-106040] Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allow…
Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to erase any object's disk replica via EvictDiskReplica and BatchEvictDiskReplica. Attackers reaching the coro_rpc master port can evict DISK replicas across all tenants, deleting objects whose only remaining replica is on disk.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-106038] Mooncake Store master through 0.3.13.post1 contains a missing authentication vulnerability that allo…
Mooncake Store master through 0.3.13.post1 contains a missing authentication vulnerability that allows unauthenticated attackers to force-delete any object via Remove, RemoveByRegex, RemoveAll and BatchRemove on the coro_rpc port. Attackers can send forged requests with the force flag set to bypass lease checks, wipe keys matching any regex, or clear the entire store, causing cache loss and reques…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105839] libmikmod before 3.3.14 contains an integer overflow in the Oktalyzer loader OKT_doPBOD() that allow…
libmikmod before 3.3.14 contains an integer overflow in the Oktalyzer loader OKT_doPBOD() that allows attackers to cause heap buffer overflow via crafted track counts. Attackers can supply an OKT module whose SLEN chunk wraps the 16-bit numtrk value, causing PBOD writes past allocated track pointers for crashes or code execution.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105840] lrzsz before 0.13.0 contains a path traversal vulnerability in the lrz receive utility's restricted …
lrzsz before 0.13.0 contains a path traversal vulnerability in the lrz receive utility's restricted mode that allows malicious ZMODEM senders to write files outside the current directory using absolute pathnames. Because checkpath() in src/lrz.c only rejects '../' sequences unless built with --enable-pubdir, attackers can send files named with absolute paths to overwrite any file writable by the r…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105841] lrzsz before 0.13.0 contains an OS command injection vulnerability in the lrz receive utility's pipe…
lrzsz before 0.13.0 contains an OS command injection vulnerability in the lrz receive utility's pipe mode that allows remote senders to execute commands by supplying crafted filenames. When lrz runs under a suffixed name such as lrztar, procheader() in src/lrz.c passes the unescaped ZMODEM/YMODEM filename to popen(), so shell metacharacters execute as the receiving user.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105920] A vulnerability was determined in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e96643…
A vulnerability was determined in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e9664384ff75000c7da45466d2. The impacted element is an unknown function of the file student_signup.php of the component Student Registration Endpoint. This manipulation causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. This product use…
G Alto vulnerabilidad
Hace 4 días
[CVE-2026-105788] Vulnerabilidad Android en Android Framework - CVSS 8.8
Vulnerabilidad de seguridad en Android (Android Framework): Vulnerabilidad de seguridad en Android. CVSS: 8.8. Afecta dispositivos Android, 80%+ del mercado movil en Mexico y LATAM. Actualiza tu dispositivo en Ajustes - Actualizacion del sistema.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105837] libmikmod before 3.3.14 contains an integer overflow vulnerability in DSM_Load() in load_dsm.c that …
libmikmod before 3.3.14 contains an integer overflow vulnerability in DSM_Load() in load_dsm.c that allows attackers to trigger heap buffer overflow via crafted track counts. Attackers can supply a DSM module whose numchn and numpat product wraps a 16-bit value, overwriting heap memory to cause crashes or potential code execution.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-82531] Smarty before 4.5.8 and 5.x before 5.8.5 contains a code injection vulnerability where the top-level…
Smarty before 4.5.8 and 5.x before 5.8.5 contains a code injection vulnerability where the top-level nocache_hash is never restored during extends:/multi-component template inheritance, leaving it null. Attackers can supply assigned data containing a forged SmartyNocache marker that is copied verbatim into the regenerated PHP cache file, executing arbitrary PHP on include for remote code execution…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105919] A vulnerability was found in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e9664384ff7…
A vulnerability was found in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e9664384ff75000c7da45466d2. The affected element is the function mysql_query of the file admin/login.php of the component Administrator Login Endpoint. The manipulation of the argument username/password results in sql injection. The attack can be launched remotely. The exploit has been made public and could be…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105835] PLANKA 2.2.0 through 2.2.1 fails to limit incorrect TOTP codes submitted to POST /api/access-tokens/…
PLANKA 2.2.0 through 2.2.1 fails to limit incorrect TOTP codes submitted to POST /api/access-tokens/verify-totp, allowing attackers to brute force two-factor authentication codes. Attackers who know a user's password can reuse the ten-minute pending token to guess six-digit codes until one succeeds, obtaining a full access token.
M Alto vulnerabilidad
Hace 4 días
Inyección SQL alta en Kusalkasilva Learning-Management-System compromete credenciales
Se ha identificado una vulnerabilidad de inyección SQL (CVSS 7.3) en el endpoint de login de Kusalkasilva Learning-Management-System que permite manipular los parámetros de usuario y contraseña para acceder no autorizado a bases de datos. La falla reside en la función mysql_error del archivo login.php y puede ser explotada remotamente sin autenticación previa. Este riesgo es alta para instituciones educativas y corporativas en LATAM que usen este LMS, exponiendo registros académicos, datos personales y credenciales de usuarios.
M Alto vulnerabilidad
Hace 4 días
Ejecución remota de código autenticada en Craft CMS 5.10.13.2
Craft CMS 5.10.13.2 contiene una vulnerabilidad de ejecución remota de código (RCE) en el panel de control que afecta a usuarios autenticados. Un atacante con acceso básico al panel puede manipular propiedades de componentes y tipos de entrada para ejecutar código arbitrario. Esta vulnerabilidad impacta principalmente a agencias web, desarrolladores y empresas en LATAM que utilizan Craft CMS como gestor de contenidos.
M Alto vulnerabilidad
Hace 4 días
Vulnerabilidad alta en controlador WibuKey para Windows permite modificación de memoria del kernel
El controlador WibuKey para Windows en versiones anteriores a 6.72 contiene validación insuficiente de entrada de usuario al calcular el tamaño de búfer del kernel, permitiendo escritura de datos fuera de los límites asignados. Esto puede causar caída del sistema y, en circunstancias desfavorables, modificación no autorizada de memoria adyacente del kernel. Afecta a empresas en LATAM que utilizan soluciones de licenciamiento basadas en WibuKey.
M Alto vulnerabilidad
Hace 4 días
XSS sin autenticación en Fluent Forms Pro Add On Pack <= 6.2.13
Vulnerabilidad de Cross Site Scripting (XSS) sin autenticación afecta Fluent Forms Pro Add On Pack en versiones 6.2.13 y anteriores. Atacantes pueden inyectar código malicioso en formularios web sin credenciales, comprometiendo datos de usuarios y sesiones. Esta vulnerabilidad impacta principalmente a empresas en LATAM que usan este plugin en WordPress para gestión de formularios y contacto.