Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 41 min
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1009
Esta semana
RSS
M Crítico vulnerabilidad Nuevo
Hace 41 min
[CVE-2026-108261] Tina is a headless content management system. Prior to tinacms 3.14.0 and @tinacms/app 2.5.14, the /…
Tina is a headless content management system. Prior to tinacms 3.14.0 and @tinacms/app 2.5.14, the /~/* admin preview route in packages/tinacms/src/admin/index.tsx can turn an attacker-controlled hash-router splat into an off-origin iframe URL through packages/@tinacms/app/src/preview.tsx, while packages/@tinacms/app/src/lib/preview-origin.ts derives expectedOrigin from that same URL for the Graph…
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-103922] Capacitor is a cross-platform native runtime for web applications. From 6.0.0 until 6.2.2, 7.6.9, 8.…
Capacitor is a cross-platform native runtime for web applications. From 6.0.0 until 6.2.2, 7.6.9, 8.3.5, 8.4.3, and 8.5.1, the Android and iOS WebView navigation guard validates a target URL's host and scheme but not its path, allowing a victim who activates an untrusted link to navigate a frame to /_capacitor_http_interceptor_. The native proxy can fetch an attacker-selected URL and return the re…
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-92701] trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested …
trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) Intel TDX verification path does not copy the expected current-session freshness value into the TDX quote-body policy before quote validation, so structurally valid TDX QuoteV4 Evidence is accepted without checking that its REPORT_DATA field matches the reportData expected for the current…
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-92702] Cocos AI is a confidential computing system for running AI workloads inside trusted execution enviro…
Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) AMD SEV-SNP verification path does not enforce attestation freshness when the expected reportData value is nil, empty, or omitted, leaving the SEV-SNP policy ReportData unset so the verifier accepts unrelated or s…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-59971] MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL datab…
MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to 0.4.2, setting MCP_TRANSPORT=sse causes src/mysql_mcp_server/server.py to construct SseServerTransport without security_settings or enable_dns_rebinding_protection, while the Starlette routes /, /sse, and /messages/ have no authentication and the service binds to 0.0.0.0 by default. A…
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-75156] Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of A…
Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login. Deployments are affected only when the FAB auth manager is configured with Azure AD as an OAuth provider. Because the signing keys are fetched from Microsoft's **multi-tenant** JWKS endpoint, an `id_token` minted in *any* Azure tenant — including one the attac…
M Crítico vulnerabilidad
07/08/2026
Vulnerabilidad crítica en OpenYak permite ejecución de código remoto desde navegadores web
OpenYak, un runtime local para modelos de IA con herramientas integradas, presenta una vulnerabilidad crítica (CVSS 9.6) en versiones anteriores a 1.1.3. El backend del escritorio expone una API HTTP sin validación de origen, autenticación de loopback ni enforcement de Content-Type, con política CORS abierta. Cualquier página web visitada mientras OpenYak se ejecuta puede ejecutar comandos arbitrarios en el sistema local, comprometiendo completamente la máquina del usuario.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-16381] Same-origin policy bypass in the Networking: DNS component. This vulnerability was fixed in Firefox …
Same-origin policy bypass in the Networking: DNS component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-16387] Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153, Firef…
Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-16375] Site isolation issue in the Networking: HTTP component. This vulnerability was fixed in Firefox 153,…
Site isolation issue in the Networking: HTTP component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-16358] Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 1…
Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-16349] Same-origin policy bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox …
Same-origin policy bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
M Crítico vulnerabilidad
16/07/2026
[CVE-2023-49899] An unauthenticated remote attacker can execute any command on the affected device due to not correct…
An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channel.
M Crítico vulnerabilidad
15/07/2026
[CVE-2026-52842] Lightpanda is a headless browser designed for AI and automation. Prior to 0.3.1, Lightpanda searched…
Lightpanda is a headless browser designed for AI and automation. Prior to 0.3.1, Lightpanda searched for @ across the entire URL string instead of only the authority component when computing a page origin, so a URL such as `http://attacker.com/@victim.com/` was fetched from attacker.com but treated as `http://victim.com`, allowing a complete Same-Origin Policy bypass. This issue is fixed in versio…
M Crítico vulnerabilidad
15/07/2026
[CVE-2026-52843] Lightpanda is a headless browser designed for AI and automation. Prior to 0.2.9, Lightpanda fetch() …
Lightpanda is a headless browser designed for AI and automation. Prior to 0.2.9, Lightpanda fetch() and XMLHttpRequest unconditionally attached session cookies to every HTTP request, ignoring credentials: omit, credentials: same-origin, credentials: include, and XMLHttpRequest.withCredentials, allowing an attacker-controlled origin in a Lightpanda session to issue authenticated cross-origin reques…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
16/06/2026
[CVE-2026-12304] Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Fire…
Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.