Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,417
Total alertas
4761
Críticas
17025
Altas
8
Ransomware
1261
Esta semana
RSS
M Alto vulnerabilidad
28/09/2026
[CVE-2026-55160] Stringer is a self-hosted, anti-social RSS reader. Prior to commit 75cb095, an unrestricted Server-S…
Stringer is a self-hosted, anti-social RSS reader. Prior to commit 75cb095, an unrestricted Server-Side Request Forgery (SSRF) vulnerability allows any authenticated user to force the Stringer server to send arbitrary HTTP/HTTPS requests to internal networks, localhost services, and cloud metadata endpoints (e.g. AWS IMDS 169.254.169.254). When self-service signup is enabled (Setting::UserSignup),…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-87114] A flaw was found in kube-compare. When processing a 'container://' reference path, the tool incorrec…
A flaw was found in kube-compare. When processing a 'container://' reference path, the tool incorrectly executes an untrusted container image's entrypoint instead of merely extracting data from a stopped container. This allows a remote attacker to achieve arbitrary code execution on the operator's workstation. If the Docker daemon requires elevated privileges, the untrusted code may execute with r…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-55096] fast-mcp-telegram is a Telegram MCP Server. Prior to version 30.1, the send_message/send_message_to_…
fast-mcp-telegram is a Telegram MCP Server. Prior to version 30.1, the send_message/send_message_to_phone MCP tools accept files as a list of http(s) URLs, which the server downloads and attaches to the outgoing Telegram message. Downloads are guarded by _validate_url_security, an SSRF denylist that checks the URL's literal hostname string but never resolves DNS. The fetch (httpx.AsyncClient.get) …
M Alto vulnerabilidad
28/09/2026
[CVE-2026-54160] Network UPS Tools is a collection of programs which provide a common interface for monitoring and ad…
Network UPS Tools is a collection of programs which provide a common interface for monitoring and administering UPS, PDU and SCD hardware. Prior to commits 658b24e and 1aa31d1, the GitHub Actions script used to prepare NUT tarballs and update GitHub Checks statuses and PR comments about it was mis-structured in terms of mixing code running with higher privileges (single-use token generated with wr…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-93348] Unsloth Zoo versions 2025.9.9 before 2026.8.14, as implemented in Unsloth 2025.9.9 through 2026.8.19…
Unsloth Zoo versions 2025.9.9 before 2026.8.14, as implemented in Unsloth 2025.9.9 through 2026.8.19, contains a code injection vulnerability in the model-loading compile path where the get_transformers_model_type() function in hf_utils.py collects model_type values from nested model configurations without enforcing a character allowlist, allowing newlines and arbitrary Python source to survive no…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-88805] Incorrect credential cleaning on logout could be used by remote attackers to keep access credentials…
Incorrect credential cleaning on logout could be used by remote attackers to keep access credentials even after the account was logged out. Affected is SUSE Rancher 2.15 before 2.15.2.
M Alto vulnerabilidad
28/09/2026
[CVE-2026-88808] A vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to …
A vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to downstream clusters using its own cluster-admin credentials instead of the ServiceAccount pinned to the deployment. It affects multi-tenancy environments where different tenants share the same downstream clusters, for example different privileged or untrusted teams inside the same organization. This…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
28/09/2026
[CVE-2026-93538] A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated clus…
A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated cluster registration, cluster labels supplied by the registering agent, including labels in the reserved management.cattle.io/ namespace such as the cluster display name label, were applied to the resulting upstream Cluster object. Because Fleet resolves GitRepo and Bundle targets from those cluster lab…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-80357] Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug …
Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS-N1 controllers. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Unauthorized access.
M Alto vulnerabilidad
28/09/2026
[CVE-2026-4556] Exam4 is affected by a local privilege escalation vulnerability in the com.extegrity.LogTool privile…
Exam4 is affected by a local privilege escalation vulnerability in the com.extegrity.LogTool privileged helper, which communicates with the application via XPC. The [ConsoleLogHelper copyConsoleIntoFileFromStartDate:] method executes a syslog command using attacker-controlled parameters without proper sanitization, enabling command injection. Successful exploitation allows a local attacker to exec…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-101073] A security flaw has been discovered in Netcore NR289-GE 1.4.5102. Impacted is an unknown function of…
A security flaw has been discovered in Netcore NR289-GE 1.4.5102. Impacted is an unknown function of the file /bin/boa of the component CGI Dispatcher. Performing a manipulation results in improper authentication. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-97335] Incorrect authorization in the custom storage volume creation endpoint in Canonical LXD versions 5.0…
Incorrect authorization in the custom storage volume creation endpoint in Canonical LXD versions 5.0.0 and later (fixed in 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create custom volumes in a project to copy, and so read, any custom storage volume from any other project on the server, including its snapshots and configuration. The client does this with a c…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-86595] Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i…
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Iron Mountain Archiving Services Inc. EnVision allows SQL Injection. This issue affects enVision: before 260655.
M Alto vulnerabilidad
28/09/2026
[CVE-2026-90925] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Inno…
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Path Traversal. This issue affects Logsign SIEM: from 6.4.101 before 6.4.117.
M Alto vulnerabilidad
28/09/2026
[CVE-2026-90926] Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecom…
Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue affects Logsign SIEM: from 6.4.101 before 6.4.117.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
A Alto vulnerabilidad
28/09/2026
watchOS 27.0.1 (24R365)
Apple lanza actualización de seguridad para watchOS versión 27.0.1. Esta actualización incluye parches de seguridad importantes. Se recomienda actualizar de inmediato en todos los dispositivos Apple.
M Alto vulnerabilidad
28/09/2026
[CVE-2026-86330] An OS command injection flaw was found in the set_hostname_internal function of NooBaa's cluster_int…
An OS command injection flaw was found in the set_hostname_internal function of NooBaa's cluster_internal_api. This component is responsible for managing the Multi-Cloud Object Gateway in OpenShift Data Foundation. The vulnerability occurs because the hostname parameter is passed directly to a shell command without proper sanitization. An authenticated attacker with administrative privileges can p…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-82323] Authorization bypass through User-Controlled key vulnerability in Enocta Educational Technologies In…
Authorization bypass through User-Controlled key vulnerability in Enocta Educational Technologies Inc. Enocta Platform allows Exploitation of Trusted Identifiers. This issue affects Enocta Platform: through 2026-09-28.
M Alto vulnerabilidad
28/09/2026
[CVE-2026-101292] Apache ActiveMQ Artemis before 2.34.0 contains an unsafe reflection vulnerability in FederationStrea…
Apache ActiveMQ Artemis before 2.34.0 contains an unsafe reflection vulnerability in FederationStreamConnectMessage.getFederationPolicy(). The method calls Class.forName(clazz).getConstructor().newInstance() where clazz is read directly from the CORE protocol wire buffer without type validation. An authenticated federation peer can send a FEDERATION_DOWNSTREAM_CONNECT packet with a crafted class n…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-12265] Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Insufficient access control…
Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Insufficient access control in HA failover endpoint leading to destructive PostgreSQL database operations.