Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,340
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1210
Esta semana
RSS
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-91939] Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes r…
Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can exploit PHP object injection through crafted serialized payloads to trigger gadget chains and achieve database manipulation or code execution.
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-91728] Integer overflow in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute …
Integer overflow in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-66890] The affected products use hard-coded credentials, which could allow remote access to files with root…
The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable.
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-61559] `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and …
`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior to version 2.1.27, when the environment variable `ENABLE_DYNAMIC_API_URL=true` is set, the server reads the `X-GitLab-API-URL` HTTP request header and uses it as the base URL for all outbound GitLab API calls made within that request. The server validates that the value is a well-formed URL (`…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-61568] `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to 2.1.30 expos…
`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to 2.1.30 expose the Streamable HTTP MCP endpoint without an effective Host or Origin allowlist. A malicious web page can use DNS rebinding to route browser requests to a victim's local MCP listener while preserving an attacker-controlled `Host` and `Origin`. The server accepts those headers and reaches the MCP in…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-66887] The affected products are missing authorization on state-changing CGIs and session checks are not pe…
The affected products are missing authorization on state-changing CGIs and session checks are not performed.
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-54337] Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.14, an argument Injec…
Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.14, an argument Injection in the video upload function allows unauthenticated attacker to write/overwrite system files. Version 1.6.14 fixes the issue.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-89040] Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a cr…
Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device. An attacker who uploads a webshell can execute arbitrary code as root.
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-87230] Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Sec…
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may signif…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-87223] Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Sec…
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletio…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-87214] Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Sec…
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may signif…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-87217] Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Sec…
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletio…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-87184] Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Sec…
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via SQL to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Fina…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-87186] Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Sec…
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financi…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-87188] Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Sec…
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Fin…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-87189] Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Sec…
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may …
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-87173] Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Sec…
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-87175] Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Sec…
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-87176] Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Sec…
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-87170] Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Sec…
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletio…