Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,417
Total alertas
4761
Críticas
17025
Altas
8
Ransomware
1263
Esta semana
RSS
M Alto vulnerabilidad
29/09/2026
Vulnerabilidad alta en HPE OneView permite secuestro remoto de sesiones
HPE OneView contiene una vulnerabilidad de severidad alta (CVSS 8.2) que permite a atacantes remotos secuestrar sesiones activas y ejecutar acciones no autorizadas en infraestructuras de centros de datos. Esta exposición afecta directamente a empresas en México y LATAM que utilizan HPE OneView para gestión de servidores físicos en entornos altas, representando riesgo de acceso administrativo no autorizado a recursos de TI sensibles.
M Alto vulnerabilidad
29/09/2026
Vulnerabilidad alta en HPE OneView permite secuestro de sesiones y robo de datos (CVE-2026-76719)
HPE OneView presenta una vulnerabilidad remota (CVSS 8.2) que permite a atacantes secuestrar sesiones, acceder a datos sensibles y ejecutar acciones no autorizadas en infraestructuras de centros de datos. En LATAM, esto afecta principalmente a empresas medianas y grandes con plataformas de gestión hiperconvergente. El riesgo es alta para operaciones de TI que dependen de HPE OneView para administrar servidores, almacenamiento y virtualización.
M Alto vulnerabilidad
29/09/2026
CVE-2026-57095 Win32k Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-57095 Win32k Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).
M Alto vulnerabilidad
29/09/2026
Falta de autenticación en Progress Fiddler Everywhere 8.0.2 permite acceso no autorizado a tokens OAuth
Progress Software Fiddler Everywhere 8.0.2 presenta una vulnerabilidad alta (CVSS 7.7) que permite a un atacante local sin credenciales acceder al backend .NET (Fiddler.WebUi) a través de canales HTTP y SignalR no autenticados. Esto posibilita la generación de tokens OAuth fraudulentos y la lectura del certificado raíz man-in-the-middle. Afecta principalmente a desarrolladores y equipos de testing que utilizan esta herramienta en México y Latinoamérica para análisis de tráfico HTTPS.
M Alto vulnerabilidad
29/09/2026
Vulnerabilidad de autorización impropia en tacomall 1.0.0 (CVE-2026-102293)
Se identificó una vulnerabilidad de autorización impropia en tacomall versión 1.0.0 que afecta el componente api-admin Backend. Un atacante remoto puede manipular los parámetros isAdmin y jobId en la función OrgStaffServiceImpl.add para eludir controles de acceso y escalar privilegios. El exploit está disponible públicamente, aumentando el riesgo de explotación inmediata en entornos de producción.
M Alto vulnerabilidad
29/09/2026
Vulnerabilidad de traversal de ruta en Flatpak permite acceso a archivos altas del sistema
Una vulnerabilidad de traversal de ruta en Flatpak (CVSS 7.1) permite que aplicaciones maliciosas vacíen o reemplacen con enlaces simbólicos archivos del sistema host como passwd, group, machine-id y resolv.conf durante la instalación o actualización. En instalaciones a nivel de sistema, la escritura se ejecuta como root, comprometiendo la integridad de servidores en entornos empresariales y de infraestructura alta en LATAM.
M Alto vulnerabilidad
29/09/2026
Vulnerabilidad alta en shell-quote permite inyección de comandos via función quote()
La función quote() de la librería shell-quote procesa incorrectamente tokens de comentario, permitiendo que un atacante inyecte comandos shell arbitrarios mediante saltos de línea en cadenas de texto. Esta vulnerabilidad afecta aplicaciones Node.js en servidores de LATAM que utilizan shell-quote para sanitización de argumentos, pudiendo comprometer sistemas de CI/CD, contenedores Docker y plataformas de automatización.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102248] A vulnerability was identified in Rebuild up to 4.4.7/4.5.0-beta5. This affects an unknown part of t…
A vulnerability was identified in Rebuild up to 4.4.7/4.5.0-beta5. This affects an unknown part of the file /user/login of the component Login Endpoint. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Alto vulnerabilidad
29/09/2026
Vulnerabilidad de autorización en REBUILD hasta v4.4.11 permite acceso no autorizado remoto
Se ha identificado una falla de seguridad en REBUILD versiones hasta 4.4.11 que afecta el módulo /commons/file-editor-save, permitiendo omitir controles de autorización mediante manipulación de parámetros (url/fileKey). Esta vulnerabilidad de severidad alta (CVSS 7.3) puede ser explotada remotamente y su código de ataque ya es público. Empresas en LATAM que usan REBUILD para gestión de contenidos están expuestas a acceso no autorizado a archivos sensibles.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102245] A weakness has been identified in MODSetter SurfSense up to 2.0.3. The affected element is an unknow…
A weakness has been identified in MODSetter SurfSense up to 2.0.3. The affected element is an unknown function of the file surfsense_backend/app/routes/circleback_webhook_route.py of the component circleback Endpoint. Executing a manipulation can lead to missing authentication. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. The…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102243] A vulnerability was identified in MODSetter SurfSense up to 2.0.3. This issue affects some unknown p…
A vulnerability was identified in MODSetter SurfSense up to 2.0.3. This issue affects some unknown processing of the file /api/search-source/connectors/mcp/test of the component MCP Connector Integration. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosu…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-96326] The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to S…
The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Rich Text Editor Field in all versions up to, and including, 2.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses …
M Alto vulnerabilidad
29/09/2026
[CVE-2026-101860] A vulnerability was found in RaspAP raspap-webgui up to 3.5.5. Affected by this issue is the functio…
A vulnerability was found in RaspAP raspap-webgui up to 3.5.5. Affected by this issue is the function PluginInstaller::addSudoers of the file src/RaspAP/Plugins/PluginInstaller.php of the component sudo Configuration. Performing a manipulation results in improper privilege management. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-101878] Bitwarden Server 2025.6.0 before 2026.5.0 declares the @ExternalId parameter of the User_ReadBySsoUs…
Bitwarden Server 2025.6.0 before 2026.5.0 declares the @ExternalId parameter of the User_ReadBySsoUserOrganizationIdExternalId stored procedure as NVARCHAR(50) while the column it queries stores NVARCHAR(300), silently truncating the SSO login identifier on SQL Server deployments and allowing a user whose identity-provider identifier begins with another organization member's full 50-character iden…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-101280] A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected is the functi…
A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected is the function opendmarc_policy_query_dmarc of the component Multi-Record Set Handler. The manipulation results in authentication bypass by spoofing. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any wa…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
29/09/2026
[CVE-2026-101281] A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerabilit…
A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_sp2_find_mailfrom_domain of the file libopendmarc/opendmarc_spf.c of the component SPF Macro Handler. This manipulation causes improper authentication. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch name: c48a74c75…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-102335] Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, al…
Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin users with manage permissions to inject arbitrary nginx directives. Attackers can inject malicious nginx configuration such as alias directives to serve arbitrary files or control routing for their assigned hosts.
M Alto vulnerabilidad
28/09/2026
[CVE-2026-102334] Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthe…
Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-force login credentials via POST /api/tokens and subsequently guess TOTP codes via POST /api/tokens/2fa to gain full session access and administrative control.
M Alto vulnerabilidad
28/09/2026
[CVE-2026-102281] Nest is a framework for building scalable Node.js server-side applications. Prior to 11.2.4 and 12.0…
Nest is a framework for building scalable Node.js server-side applications. Prior to 11.2.4 and 12.0.2, a single message with a deeply nested object in its pattern can terminate a NestJS microservice using the TCP or RabbitMQ transport. ServerTCP#handleMessage and ServerRMQ#handleMessage pass a client-controlled non-string pattern to JSON.stringify to derive the handler lookup key; sufficiently de…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-101188] A security vulnerability has been detected in Netcore POWER13 2.0.240730.162638. This issue affects …
A security vulnerability has been detected in Netcore POWER13 2.0.240730.162638. This issue affects the function routerd.passwd_set of the file /ubus. Such manipulation leads to weak password recovery. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.