Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 42 min
22,345
Total alertas
4745
Críticas
16970
Altas
8
Ransomware
1213
Esta semana
RSS
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102109] A SQL injection vulnerability existed in Kiteworks Secure Data Forms, where a value derived from the…
A SQL injection vulnerability existed in Kiteworks Secure Data Forms, where a value derived from the authenticated user's stored account data was incorporated into a database query without proper sanitization. An authenticated user could potentially influence that value to inject SQL. Exploitation requires an authenticated session and applies only to deployments where a specific optional feature i…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102096] Kiteworks Core before version 9.5.0 is vulnerable to OS Command Injection that allows an authenticat…
Kiteworks Core before version 9.5.0 is vulnerable to OS Command Injection that allows an authenticated administrator to upload a configuration package whose contents were not sufficiently validated before being processed. A crafted package could cause the underlying system to execute arbitrary operating-system commands, potentially with elevated privileges, on the affected appliance.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102097] Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Remote Code Execution. Kite…
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Remote Code Execution. Kiteworks Email Protection Gateway allowed an authenticated administrator to import configuration whose contents were not sufficiently validated before being processed. A crafted submission could potentially allow arbitrary commands to be executed on the affected gateway.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102098] Kiteworks Core before version 9.5.0 is vulnerable to SQL Injection. A stored SQL injection vulnerabi…
Kiteworks Core before version 9.5.0 is vulnerable to SQL Injection. A stored SQL injection vulnerability in a Kiteworks administrative reporting feature could allow an authenticated administrator to read sensitive data from the underlying database and to affect the availability of the service. Exploitation requires an existing, authenticated administrative account with access to the affected repor…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102099] Kiteworks Core before version 9.5.0 is vulnerable to Arbitrary File Write. An improper restriction o…
Kiteworks Core before version 9.5.0 is vulnerable to Arbitrary File Write. An improper restriction of a user-supplied file path in a Kiteworks administrative export feature could allow an authenticated administrator to write a file to an arbitrary location on the underlying host, potentially leading to command execution on the appliance. Exploitation requires an existing, authenticated administrat…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102100] Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-Site Scripting. A stored cross-sit…
Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-Site Scripting. A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an authenticated user to submit content that, when later viewed by another user, executes arbitrary JavaScript in that user's authenticated session. This could be used to perform actions on the victim's behalf and may have permitted account ta…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102101] Kiteworks Core before version 9.5.0 is vulnerable to Deserialization of Untrusted Data. A deserializ…
Kiteworks Core before version 9.5.0 is vulnerable to Deserialization of Untrusted Data. A deserialization weakness in Kiteworks Core could, under certain conditions, allow crafted data to be deserialized unsafely, potentially resulting in remote code execution on the appliance. Exploitation depends on an attacker first being able to influence the affected data, so this issue is not exploitable on …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102089] Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to a path traversal weakness i…
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to a path traversal weakness in an administrative import function allowed an authenticated administrator to write files to arbitrary locations on the server. This could potentially be leveraged to execute arbitrary code on the underlying system.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102091] Kiteworks Secure Data Forms before version 9.5.0 is vulnerable to Server-Side Request Forgery that c…
Kiteworks Secure Data Forms before version 9.5.0 is vulnerable to Server-Side Request Forgery that could allow an unauthenticated, remote attacker to make the server issue arbitrary outbound network requests and read back the responses. This could potentially be used to reach internal-only services or other network-restricted resources.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102092] Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-site Scripting (XSS) that could al…
Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-site Scripting (XSS) that could allow an authenticated user to store crafted content that executes arbitrary JavaScript in another user's authenticated session when they preview shared content. This could potentially lead to session compromise and account takeover.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102093] Kiteworks Core before version 9.5.0 is vulnerable to Improper Privilege Management and does not corr…
Kiteworks Core before version 9.5.0 is vulnerable to Improper Privilege Management and does not correctly enforce restrictions on role assignment, which could allow an authenticated administrative user with limited, non-Sysadmin role-management permissions to elevate another user to full system-administrator privileges beyond those the administrative user was authorized to grant.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102094] Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Unsafe Reflection and does …
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Unsafe Reflection and does not sufficiently restrict the code that the mail-processing pipeline could load from an imported rule configuration. An authenticated administrator with mail-rule configuration privileges could cause the gateway to load and execute code beyond the approved set of mail-processing components, potentia…
M Alto vulnerabilidad
30/09/2026
[CVE-2023-54403] Yonyou U8 CRM before V16.5 and V18 contains an arbitrary file read vulnerability in /ajax/getemailda…
Yonyou U8 CRM before V16.5 and V18 contains an arbitrary file read vulnerability in /ajax/getemaildata.php that allows unauthenticated attackers to bypass authentication using the DontCheckLogin=1 parameter and read arbitrary files via an unvalidated filePath parameter. Attackers can exploit this flaw to read sensitive files outside the web application directory, including configuration files cont…
M Alto vulnerabilidad
30/09/2026
[CVE-2024-58387] Inspur Haiyue HCM Cloud contains an arbitrary file read vulnerability in the /api/model_report/file/…
Inspur Haiyue HCM Cloud contains an arbitrary file read vulnerability in the /api/model_report/file/download endpoint that allows unauthenticated remote attackers to read arbitrary files by supplying unvalidated path parameters index and ext. Attackers can craft requests such as /api/model_report/file/download?index=/&ext= to traverse the filesystem and disclose sensitive files including /et…
M Alto vulnerabilidad
30/09/2026
[CVE-2023-54402] iDocView contains a server-side request forgery vulnerability in its /doc/upload endpoint that allow…
iDocView contains a server-side request forgery vulnerability in its /doc/upload endpoint that allows remote unauthenticated attackers to fetch arbitrary URLs by supplying a hardcoded default token value (testtoken) to bypass authentication. Attackers can exploit the unrestricted URL scheme handling, including file:// URIs, to read arbitrary local files such as operating-system and application con…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
30/09/2026
[CVE-2026-101885] ZeroClaw versions before 0.8.5 built with plugins-wasm feature contain a path traversal vulnerabilit…
ZeroClaw versions before 0.8.5 built with plugins-wasm feature contain a path traversal vulnerability in plugin installation that fails to validate the wasm_path manifest field. Attackers can convince users to install crafted plugins that write arbitrary files to paths outside the plugins directory, such as shell startup files, enabling code execution.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-101884] OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in syste…
OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in system.run that fails to block GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, and JAVA_TOOL_OPTIONS variables. Attackers with gateway or agent access can supply these variables to allowlisted tools like git, dotnet, or java to load attacker-controlled code and achieve arbitrary code execution.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-101882] OpenClaw Windows Node before 2026.7.1 contains an incomplete validation vulnerability in system.exec…
OpenClaw Windows Node before 2026.7.1 contains an incomplete validation vulnerability in system.execApprovals.set that accepts wildcard-executable rules and abusable system binaries like mshta, rundll32, and certutil. Remote callers can add broad allow rules to execute arbitrary commands on the Windows host through system.run without operator checks or user prompts.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-101880] OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the syste…
OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the system.run exec-approval policy where ExecShellWrapperParser fails to split commands on pipe operators or extract command substitutions. Connected gateways or agents can bypass approval rules by placing denied commands behind allowed prefixes using pipe operators or command substitution syntax, achieving…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-97256] Editor PHP Object Injection in Page Builder by SiteOrigin <= 2.36.0 versions.
Editor PHP Object Injection in Page Builder by SiteOrigin