Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Canonical" — 33 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
Hace 1 día
Vulnerabilidad alta en Progressive Robot hMailServer permite denegación de servicio remota
Una complejidad algorítmica ineficiente en la verificación de firmas DKIM y ARC en Progressive Robot hMailServer 6.0.0 a 6.3.5 permite a atacantes remotos no autenticados saturar servidores de correo mediante mensajes especialmente crafted. El procesamiento de encabezados crece exponencialmente, causando consumo excesivo de recursos y caída del servicio de correo, impactando directamente la comunicación empresarial en organizaciones que dependen de este servidor.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-89322] Vault and Vault Enterprise did not consistently evaluate ACL policies against the canonical form of …
Vault and Vault Enterprise did not consistently evaluate ACL policies against the canonical form of resource and policy names. This may allow an authenticated user with delegated permissions to bypass an explicit deny restriction and access a protected resource or assign a denied policy, potentially leading to privilege escalation. This vulnerability (CVE-2026-89322) is fixed in Vault Community Ed…
M Alto vulnerabilidad
02/10/2026
[CVE-2026-104422] The block sync download path in Zebra (zebrad) before 6.3.0 reads a block's height from its unvalida…
The block sync download path in Zebra (zebrad) before 6.3.0 reads a block's height from its unvalidated coinbase scriptSig and drops blocks that appear too far behind the tip before consensus validation, without penalizing the supplying peer. Because V5 transaction IDs exclude the scriptSig, a malicious peer can repeatedly serve a canonical block whose coinbase claims height 1 while keeping the re…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-97335] Incorrect authorization in the custom storage volume creation endpoint in Canonical LXD versions 5.0…
Incorrect authorization in the custom storage volume creation endpoint in Canonical LXD versions 5.0.0 and later (fixed in 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create custom volumes in a project to copy, and so read, any custom storage volume from any other project on the server, including its snapshots and configuration. The client does this with a c…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-97731] MinIO through 7aac2a2 does not verify that every x-amz-* header present on a request also appears in…
MinIO through 7aac2a2 does not verify that every x-amz-* header present on a request also appears in the client-supplied X-Amz-SignedHeaders list. extractSignedHeaders() in cmd/signature-v4-utils.go iterates only the claimed list and never enumerates the headers that actually arrived, and thus a header that arrives unsigned is neither hashed into the canonical request nor rejected. Because cmd/api…
M Alto vulnerabilidad
16/09/2026
Vulnerabilidad alta en NLnet Labs Unbound: desbordamiento de búfer por consultas DNS malformadas
NLnet Labs Unbound versiones hasta 1.26.0 es vulnerable a desbordamiento de búfer en memoria durante el procesamiento de respuestas TCP con nombres de consulta de 255 caracteres. Un atacante controlando un servidor DNS malicioso puede explotar esta falla para ejecutar código arbitrario o causar negación de servicio en recursores DNS de empresas. El impacto es alta en infraestructuras de LATAM que dependen de Unbound para resolución DNS.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad de traversal de directorios en libks anteriores a v2.0.11
libks, biblioteca fundamental para productos SignalWire C, contiene un defecto en la función `clean_uri()` del analizador HTTP que permite eludir la validación de rutas. Versiones anteriores a 2.0.11 no rechazarán URIs con segmentos de ruta excesivos, dejando secuencias ".." intactas y facilitando ataques de traversal de directorios. Esto afecta a cualquier aplicación que integre libks y procese solicitudes HTTP, comprometiendo el acceso a archivos sensibles en servidores de telecomunicaciones y plataformas de comunicaciones unificadas.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
10/09/2026
[CVE-2026-75584] ION-DTN before 4.2.1-a.1 contains a denial of service vulnerability that allows unauthenticated remo…
ION-DTN before 4.2.1-a.1 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash the ION process by sending a BPv7 bundle with a zero-length payload. The canonicalizePayloadBlock() function in bpsec_util.c passes bundle->payload.length to zco_clone() without validating it against zero, causing a failed CHKZERO assertion that triggers sm_Abort() and terminat…
M Alto vulnerabilidad
03/09/2026
Vulnerabilidad en fast-uri permite validación incorrecta de autoridades en URL
fast-uri acepta hosts con corchetes de autoridad desbalanceados o mal posicionados sin generar error, lo que permite que URLs malformadas se procesen incorrectamente. Esto afecta aplicaciones Node.js que utilizan esta librería para parsear URLs, potencialmente permitiendo evasión de validaciones de seguridad en servidores web, proxies y clientes HTTP. El riesgo es alta en empresas LATAM que procesan URLs no confiables sin validación adicional.
M Alto vulnerabilidad
02/09/2026
Vulnerabilidad de autorización en Craft CMS 5.0.0-RC1 a 5.10.10 permite eliminación no autorizada
Craft CMS versiones desde 5.0.0-RC1 hasta 5.10.10 presentan un fallo en la validación de autorización independiente en ElementsController::actionDeleteForSite(). El método verifica permisos únicamente contra el borrador provisional del usuario, permitiendo que la eliminación se propague al elemento canónico sin re-validación. Esto expone plataformas de contenido en LATAM a eliminación no autorizada de datos altas con CVSS 7.1.
M Alto vulnerabilidad
24/08/2026
[CVE-2026-10582] Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRem…
Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRemote, and it inspects the URL text alone. CheckAllowedHTTPURL in config/security/securityConfig.go applies the configured pattern list and then re-checks a canonicalised form of an integer, hex or octal IPv4 host, but it never resolves the hostname and never inspects the address the HTTP client actua…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-75931] fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input …
fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input carries an explicit scheme, so a scheme-relative reference such as a host preceded by two slashes is returned with its host verbatim and no error set. As a result fast-uri's own entry points disagree with each other: parse, resolve, normalize, and equal can yield different hosts for the same input d…
M Alto vulnerabilidad
18/08/2026
[CVE-2026-52829] ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated IPv4 peer can det…
ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated IPv4 peer can deterministically terminate a synced Zebra node using the default Linux dual-stack listener configuration. The handshake path canonicalized an IPv4-mapped IPv6 PeerSocketAddr such as ::ffff:127.0.0.1 to plain IPv4 before storing it through MetaAddr::new_connected, but the mempool misbehavior path forwa…
M Alto vulnerabilidad
18/08/2026
[CVE-2026-75914] CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool th…
CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool that fails to canonicalize symlinks before reading files. Attackers can create workspace symlinks pointing to external files with image extensions to leak file bytes to the vision endpoint without user approval.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-57233] Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the WinGup decompress functi…
Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the WinGup decompress function joins untrusted ZIP entry names to unzipDestTo without canonical containment validation, allowing an entry such as ../mimeTools/mimeTools.dll to overwrite a DLL in a sibling plugin directory and execute attacker-controlled code when Notepad++ next loads that plugin. This issue is fixed in version…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72533] An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privi…
An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypass Docker proxy authorization checks via non-canonical URL normalization, defeating all authorization middleware. The proxy endpoint fails to normalize request paths before applying access controls, allowing crafted requests to be interpreted differently by the proxy and the autho…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-18427] @fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. …
@fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file handler rejected only parent directory segments, but it did not canonicalize dot segments, duplicate slashes, encoded dots, or backslashes before route matching and before delegating to the send layer. As a result, an unauthenticated attacker could request a file protected by a route…
M Alto vulnerabilidad
30/07/2026
[CVE-2026-62663] Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4,…
Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4, all four media filters (image, audio, video, document) in banks accept untrusted user input as file paths via Path(value) and pass them directly to open(file_path, "rb") without any path sanitization, canonicalization, or directory restriction. An attacker who controls template variables passed to …
M Alto vulnerabilidad
24/07/2026
[CVE-2026-66040] FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in …
FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output…
M Alto vulnerabilidad
21/07/2026
[CVE-2026-8933] A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component…
A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap applications. This vulnerability uniquely affects versions of snap-confine configured with set-capabilities (rather than standard set-uid-root installations). Due to a flaw in how privilege boundaries or secur…