Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1002
Esta semana
RSS
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-97673] IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitra…
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper input validation.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-97678] IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitra…
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper input validation.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-92121] In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves…
In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves an internal "inside signed content" flag permanently set. The WS-SecurityPolicy enforcer uses that flag to decide whether an element needs checking, so it stops evaluating SignedParts and SignedElements for the rest of the message. A policy requiring the SOAP Body to be signed is then satisfied eve…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102673] Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and C…
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.4, 42.5.2, and 43.0.0, popups opened from a sandboxed iframe through Electron's OpenURLFromTab navigation path, including links using target="_blank" or a middle-click, did not receive the inherited HTML sandbox restrictions. An untrusted iframe using the allow-scripts allow-popup…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102674] Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and C…
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, windows opened from a sandboxed top-level document did not inherit that document's active HTML sandbox restrictions. Untrusted content in a sandboxed top-level document that was permitted to open popups could therefore create a window with the…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100676] January, the media proxy/embed service of stoatchat (stoatchat/stoatchat), before version 0.15.5 imp…
January, the media proxy/embed service of stoatchat (stoatchat/stoatchat), before version 0.15.5 improperly resolves SVG values as local filesystem paths when a fetched resource is served as image/svg+xml. An unauthenticated remote attacker who causes the service to proxy an attacker-hosted SVG (e.g. via the /proxy endpoint) can determine whether local files exist through observable r…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-92959] vm2 before 3.11.8 does not fully enforce the allowAsync: false option in VM and NodeVM. While localP…
vm2 before 3.11.8 does not fully enforce the allowAsync: false option in VM and NodeVM. While localPromise.prototype.then is replaced with a handler that throws 'Async not available', the sandbox's Promise static methods (Promise.resolve, Promise.all, Promise.race, Promise.any, and Promise.allSettled) still assimilate attacker-supplied thenables: native promise resolution performs PromiseResolveTh…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
16/09/2026
[CVE-2026-76825] RestrictedPython is a tool that helps define a subset of the Python language for accepting program i…
RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment. Prior to 8.4, RestrictedPython could allow a sandbox escape when a custom import policy or globals exposed the standard library string module, the string.Formatter class, a Formatter instance, or a Formatter subclass to restricted code. The string.Formatter methods for…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92122] Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check the method called th…
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check the method called through the proxy created when a sandboxed script coerces a value to an interface, if the value inherits a method of the same name as an interface method, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92123] Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not intercept operations perfo…
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not intercept operations performed on a null receiver (method calls, property and attribute accesses, and array accesses), allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92124] Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier checks the operations Groovy will p…
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier checks the operations Groovy will perform with the elements it reads from a collection that a sandboxed script casts to another type but performs the cast on the collection itself, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code i…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92129] Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check calls from sandboxed…
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check calls from sandboxed scripts to methods added dynamically to a class at runtime, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute code outside the sandbox.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-58766] In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic e…
In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-58704] In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This coul…
In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
M Alto vulnerabilidad
15/09/2026
Vulnerabilidad alta en PraisonAI permite ejecución no autorizada de herramientas (CVE-2026-57137)
PraisonAI versiones 1.4.0 a 1.7.2 contienen una falla de control de acceso en createAgentLoop() que ejecuta herramientas antes de validar permisos. Un atacante puede forzar la ejecución de funciones no autorizadas que generen efectos secundarios irreversibles, comprometiendo sistemas de IA generativa en empresas mexicanas y latinoamericanas. El CVSS 8.8 refleja impacto alto en confidencialidad e integridad de datos.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
15/09/2026
Vulnerabilidad alta de inyección de comandos en PraisonAI (CVE-2026-57133)
PraisonAI versiones 1.5.1 a 1.7.2 contienen una vulnerabilidad de inyección de comandos en la función shell() que permite eludir validaciones de lista blanca. Un atacante puede ejecutar comandos arbitrarios prefijando su payload con un comando permitido. Afecta especialmente a equipos que utilizan PraisonAI en pipelines de automatización altas en empresas de tecnología, fintech y servicios en LATAM.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-57135] PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, SandboxExecutor network-isolated mo…
PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, SandboxExecutor network-isolated mode in src/praisonai-ts/src/cli/features/sandbox-executor.ts uses buildEnv() only to inject invalid http_proxy and https_proxy environment variables and does not establish an operating-system network boundary. Programs that ignore those proxy variables can open sockets directly, allowing supposedly i…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-57136] PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, CommandValidator in src/praisonai-t…
PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, CommandValidator in src/praisonai-ts/src/cli/features/sandbox-executor.ts validates only the first whitespace-delimited executable against allowedCommands, then SandboxExecutor passes the complete command string to sh -c. A command beginning with an allowed executable can append a non-allowlisted command through shell metacharacters,…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-76059] IBM Langflow OSS 1.0.0 through 1.11.5 An attacker who could submit custom component source code coul…
IBM Langflow OSS 1.0.0 through 1.11.5 An attacker who could submit custom component source code could bypass the static security scanner by crafting an annotated class-body assignment that resolved to a dangerous callable through alias tracking; the resolved value was never checked against the dangerous callable blocklist due to the logic error. If the crafted component reached the runtime executi…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-45770] Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M…
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, a Lua rule that registers too many flow variables can corrupt Lua detection state and may bypass Suricata's restricted Lua sandbox. This requires an affected Lua script/rule to be loaded. Excessive flow variables being registere…