Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1038
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Hace 21 horas
[CVE-2026-78024] Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Server-Si…
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Server-Side Request Forgery (SSRF) vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure, Protection mechanism bypass, Server-side request forgery, and Unauthorized access.
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-69435] Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a …
Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107781] Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a server-side reques…
Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a server-side request forgery and missing authorization vulnerability in the OnlyOffice save callback editUploadOfficeFileById. Unauthenticated attackers can supply arbitrary url and key parameters to make the server fetch internal URLs and overwrite any user's stored file, then read results via queryFileToShowById.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107362] Malcolm file-upload component ships the upstream FilePond PHP server (pqina/filepond-server-php) lar…
Malcolm file-upload component ships the upstream FilePond PHP server (pqina/filepond-server-php) largely unmodified: Dockerfile copies all upstream *.php files and Malcolm only overwrites config.php and submit.php. Upstream index.php exposes a fetch API route that instructs the server to download an arbitrary URL with curl (including FOLLOWLOCATION) and, for HEAD requests, stores the fetched respo…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-20362] A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticate…
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successfu…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-106557] Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @back…
Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @backstage/plugin-techdocs-node package did not sufficiently validate TechDocs Markdown extension configuration. An authenticated user who can register or modify documentation sources may cause a TechDocs build to access resources outside the intended documentation boundary, potentially exposing backend-…
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-102255] A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to …
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106498] Backstage is an open framework for building developer portals. Prior to 3.5.1, 3.6.2, 3.7.2, 3.8.2 a…
Backstage is an open framework for building developer portals. Prior to 3.5.1, 3.6.2, 3.7.2, 3.8.2 and 3.9.1, the @backstage/plugin-catalog-backend package is affected by improper url validation in catalog entity placeholder resolution. An authenticated Backstage user could craft a catalog entity with placeholder directives that reference resources outside the entity's source repository. Under cer…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106459] Backstage is an open framework for building developer portals. From 0.3.0 until 0.3.8, the @backstag…
Backstage is an open framework for building developer portals. From 0.3.0 until 0.3.8, the @backstage/plugin-scaffolder-backend-module-sentry package is affected by improper input validation in sentry scaffolder actions. An authenticated internal user who can execute the affected actions may cause the backend to contact unintended destinations and disclose Sentry integration credentials. Subsequen…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106455] Backstage is an open framework for building developer portals. From 0.11.12 until 1.14.7 and 1.15.5,…
Backstage is an open framework for building developer portals. From 0.11.12 until 1.14.7 and 1.15.5, the @backstage/plugin-techdocs-node package is affected by improper validation of mkdocs plugin configuration in techdocs. An authenticated attacker with control over a TechDocs source repository could cause a documentation build to retrieve and publish data from network locations reachable by the …
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-39728] Unauthenticated Server Side Request Forgery (SSRF) in Instapage Plugin <= 3.7.2 versions.
Unauthenticated Server Side Request Forgery (SSRF) in Instapage Plugin
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-39719] Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versio…
Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105762] Dify is an open-source LLM app development platform. Prior to 1.13.0, the /console/api/remote-files/…
Dify is an open-source LLM app development platform. Prior to 1.13.0, the /console/api/remote-files/upload endpoint in api/controllers/web/remote_files.py accepted an attacker-controlled URL without authentication and caused the Dify server to retrieve it. A remote attacker could use the endpoint to send requests to internal services or cloud metadata endpoints, potentially exposing sensitive data…
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-105636] Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/a…
Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/api/plane/bgtasks/webhook_task.py calls requests.post() without allow_redirects=False and does not validate redirect targets. validate_url() blocks private, loopback, link-local, and reserved addresses in the original webhook URL, but the final URL reached after one or more redirects is not checked. …
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105628] Plane is an open-source project management tool. Prior to 1.4.0, Plane's OAuth avatar synchronizatio…
Plane is an open-source project management tool. Prior to 1.4.0, Plane's OAuth avatar synchronization flow fetches avatar_url from provider user data through a server-side HTTP request without internal IP validation and follows redirects by default. An attacker can provide an avatar URL that redirects to an internal-only resource, such as a metadata endpoint, and Plane uploads the fetched response…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-104977] Plane is an open-source project management tool. Prior to 1.4.0, the fix for CVE-2026-27706 and GHSA…
Plane is an open-source project management tool. Prior to 1.4.0, the fix for CVE-2026-27706 and GHSA-jcc6-f9v6-f7jw, an SSRF in work-item link unfurling shipped in v1.2.2, remains incomplete in the v1.3.1 GA release. Any authenticated project member can make the server fetch attacker-selected internal targets, including cloud metadata at 169.254.169.254, and read the response body returned as the …
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-104973] Plane is an open-source project management tool. Prior to 1.4.0, the fix for CVE-2026-30242 validate…
Plane is an open-source project management tool. Prior to 1.4.0, the fix for CVE-2026-30242 validates webhook IP addresses only when the webhook is created in apps/api/plane/app/serializers/webhook.py. The delivery task in apps/api/plane/bgtasks/webhook_task.py performs a separate DNS resolution when sending the request and does not validate the resolved IP address, allowing DNS rebinding to bypas…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-12171] auto-changelog before 2.6.1 merges configuration from inside the target repository (the .auto-change…
auto-changelog before 2.6.1 merges configuration from inside the target repository (the .auto-changelog file and the auto-changelog key in package.json) into its options, and honors security-sensitive options from that untrusted source. The handlebarsSetup option is passed to require(), so running auto-changelog over attacker-controlled repository content (for example, in a CI workflow that checks…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-92931] CWE-918: Server-Side Request Forgery in the Progress @progress/sitefinity-nextjs-sdk npm package ver…
CWE-918: Server-Side Request Forgery in the Progress @progress/sitefinity-nextjs-sdk npm package versions 15.1.8326 through 15.4.8637 may allow a remote attacker to make server-side requests to an attacker-controlled host, potentially exposing sensitive information.
M Alto vulnerabilidad
Hace 4 días
Vulnerabilidad alta de SSRF en feelec-yishu feelcrm-os 1.0.0
Se identificó una vulnerabilidad de Server-Side Request Forgery (SSRF) en feelcrm-os versión 1.0.0 que permite manipular el parámetro URL en el endpoint getCurlData del controlador GoogleController.class.php. Un atacante remoto puede ejecutar solicitudes no autorizadas desde el servidor afectado hacia sistemas internos o externos, comprometiendo la confidencialidad de datos y la integridad de la infraestructura. El exploit ha sido divulgado públicamente, elevando significativamente el riesgo para empresas mexicanas y latinoamericanas que utilicen este CRM.