Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 42 min
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1009
Esta semana
RSS
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-104077] Obsidian Desktop before 1.14.0 contains a remote code execution vulnerability that allows attackers …
Obsidian Desktop before 1.14.0 contains a remote code execution vulnerability that allows attackers to craft malicious Markdown notes exploiting insufficient sanitization of the data-background-iframe attribute, which bypasses DOMPurify and is processed by the bundled Reveal.js 4.3.1 within the Slides core plugin, allowing a javascript: URL to execute in the resulting background iframe. Because No…
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-104078] Obsidian Desktop before 1.14.0 contains a filter bypass vulnerability in the bundled MathJax 3.2.2 S…
Obsidian Desktop before 1.14.0 contains a filter bypass vulnerability in the bundled MathJax 3.2.2 Safe component that allows attackers to execute arbitrary code by embedding a crafted \href value with a TAB byte in the URL scheme, causing filterURL to produce an empty protocol that bypasses the configured safeProtocols restrictions. Attackers can craft a note containing a malicious MathJax formul…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105744] Docling simplifies document processing by parsing diverse formats and providing integrations with th…
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.94.0 until 2.132.0, callers that opt into LatexBackendOptions(tikz_engine="tectonic") invoke docling/backend/latex/engines/tectonic.py to compile an untrusted TikZ body and document preamble without restricting TeX file primitives including \openin and \openout. Cra…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102676] Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and C…
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, an Electron guest could enable nodeIntegrationInWorker for its Web Workers even when the unsandboxed embedder had Node.js integration disabled, allowing untrusted guest content to create a Node-enabled worker with more privilege than…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-93354] Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthe…
Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers to register arbitrary OAuth clients and take over user accounts by exploiting the OAuth 2.0 Dynamic Client Registration endpoint, which is enabled by default and requires no authentication. Attackers can send a POST request to the registration endpoint to obtain a client_id and cl…
M Alto vulnerabilidad
24/09/2026
SigNoz v0.8.0 a v0.142.x: Secreto JWT vacío permite falsificación de tokens de sesión
SigNoz anterior a la versión 0.143.0 configura por defecto una clave HMAC vacía para firmar tokens JWT, permitiendo que un atacante forge tokens de sesión sin autenticación válida. Afecta a despliegues que no definen explícitamente SIGNOZ_TOKENIZER_JWT_SECRET o SIGNOZ_JWT_SECRET. La validación de configuración no rechaza valores vacíos, comprometiendo la integridad de sesiones en plataformas de observabilidad y monitoreo.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-77348] Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, the f…
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, the fix for CVE-2026-33407 (GHSA-hhjq-82f8-m6rc, "SSRF via HTTP Proxy Environment Variable") hardened endpoints/logos/search.php by disabling cURL proxying (CURLOPT_PROXY = '' + CURLOPT_NOPROXY = '*'). However, Wallos ships a second, near-identical, unauthenticated logo-image search endpoint — endpoints/…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
25/08/2026
[CVE-2026-55581] mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0…
mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default Docker security.yaml includes /bin/bash in allowed_executables, while security.go validates only the first token and checkBlockedPatternsAndCommands does not reject the shell command-mode flag -c. A caller of the shell_exec MCP tool can provide the command argument `/bin/bash -c
M Alto vulnerabilidad
22/08/2026
[CVE-2026-62388] NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation …
NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle deserialization protections by exploiting the disabled security controls that are only active when manually enabled.
M Alto vulnerabilidad
18/08/2026
[CVE-2026-75926] Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permission model so that code runnin…
Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permission model so that code running through PostCSS, Babel, or TailwindCSS could not reach the file system outside the project directory. Hugo 0.162.0 added tailwindcss to the AllowChildProcess default in config/security/securityConfig.go, which makes nodePermissionArgs in common/hexec/exec.go append --allow-child-process whenever t…
M Alto vulnerabilidad
28/07/2026
[CVE-2026-65881] Joomla Extension - joomdle.com - Insecure default configuration allows read/write user account acces…
Joomla Extension - joomdle.com - Insecure default configuration allows read/write user account access in Joomdle < 3.1.1 - The default configuration of the extension allowed read access and password reset of CMS accounts.
M Alto vulnerabilidad
13/07/2026
[CVE-2026-62185] Argo CD Helm Chart before 10.0.0 fails to install network policies by default, allowing any pod on a…
Argo CD Helm Chart before 10.0.0 fails to install network policies by default, allowing any pod on a cluster to access repo-server and other Argo APIs. Attackers can exploit this unrestricted network access through combined attacks to achieve cluster compromise and remote code execution.
M Alto vulnerabilidad
11/07/2026
[CVE-2026-61439] PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block…
PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults to CRITICAL severity, allowing HIGH-level threats to pass through unblocked. Attackers can submit single-vector prompt injection attacks such as instruction overrides or financial manipulation that trigger HIGH severity detection but are logged without blocking, enabling system p…
M Alto vulnerabilidad
07/07/2026
[CVE-2026-14474] A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicit…
A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.
M Alto vulnerabilidad
29/06/2026
[CVE-2026-56285] Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and use…
Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and uses a hardcoded default HMAC key, allowing unauthenticated attackers to compute valid HMACs for arbitrary URLs. Attackers can retrieve HTTP responses from any host reachable by the server, including cloud metadata services and internal network resources.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
24/06/2026
[CVE-2026-54066] SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the patch for CVE-202…
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the patch for CVE-2026-41894 ("Path Traversal via Double URL Encoding") sanitized the /export/ route but the identical root cause remains in the /assets/*path route. In publish mode (anonymous read-only HTTP endpoint, default port 6808), an unauthenticated remote attacker can read arbitrary files inside WorkspaceDir — i…
M Alto vulnerabilidad
22/06/2026
[CVE-2026-48502] MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader…
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader.ReadDateTime() can allocate stack memory based on an attacker-controlled MessagePack extension length. In the slow path for timestamp extension parsing, the computed tokenSize includes the extension body length from the wire and is used in a stackalloc operation before the extension length is valid…
N Alto vulnerabilidad
12/06/2026
[CVE-2026-44892] Netty is a network application framework for development of protocol servers and clients. Prior to v…
Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final, the default configuration of the `Http3ConnectionHandler` in the Netty HTTP/3 codec lacks an enforced maximum header size limit. When a peer does not explicitly specify `HTTP3_SETTINGS_MAX_FIELD_SECTION_SIZE`, the implementation defaults to an unbounded limit. This insecure defa…
M Alto vulnerabilidad
11/06/2026
[CVE-2026-40994] Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that i…
Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation disabled WSS4J BSP enforcement on RequestData. Services that validate WS-Security on the network could therefore accept messages that violate BSP rules, weakening protocol-level checks. Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through …
M Alto vulnerabilidad
10/06/2026
[CVE-2026-46517] LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.1…
LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, hardcoded "trust_remote_code=True" enables HF supply-chain RCE without user opt-in. At time of publication, there are no publicly available patches.