Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1002
Esta semana
RSS
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-82973] Improper neutralization of CRLF sequences in IMAP command construction in psyb0t/docker-mailbox befo…
Improper neutralization of CRLF sequences in IMAP command construction in psyb0t/docker-mailbox before 0.4.13 allows a remote unauthenticated attacker, when bearer-token authentication is not configured, to inject additional IMAP commands into an authenticated upstream mailbox connection via crafted folder, UID, or search values.
M Crítico vulnerabilidad
26/09/2026
[CVE-2026-100717] froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl reje…
froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return and line feed characters only in the path, query and fragment components returned by parse_url, and never inspects the userinfo (user:pass@) components. This is an incomplete fix for GHSA-c3p2. An authenticated low-privilege customer with subdomain-create rights (no admin or chan…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-91839] A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager. The nm-fo…
A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager. The nm-fortisslvpn-service improperly handles carriage-return/line-feed (CR/LF) characters in VPN connection profile credentials. A local unprivileged user can exploit this by crafting a malicious VPN profile to inject additional configuration directives. This can lead to arbitrary code execution with root p…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-91840] A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unprivileged user to esca…
A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unprivileged user to escalate privileges to root. By injecting a newline character into the VPN username field, an attacker can manipulate the vpnc configuration to execute an arbitrary program with root privileges when the malicious VPN connection is activated.
M Alto vulnerabilidad
25/09/2026
[CVE-2026-91841] A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager. A local unprivileged user …
A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by injecting a newline character into the CA-File path. This manipulation allows the user to execute arbitrary commands as the root user, leading to local privilege escalation.
M Alto vulnerabilidad
24/09/2026
[CVE-2026-61815] zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear librar…
zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading messages in Internet Message Format RFC 822. Prior to version 3.0.6 and 4.0.2, CRLF (carriage-return / line-feed) header injection (CWE-93) affecting any application that uses this library to build or forward MIME messages with an attacker-influenced attachment filename. Attachment f…
M Alto vulnerabilidad
21/09/2026
[CVE-2026-55159] luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-blocker for OpenWrt that works with…
luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-blocker for OpenWrt that works with dnsmasq, smartdns, or unbound. Prior to 1.2.4-2, the luci.adblock-fast.setCronEntry RPC method accepts an entry argument containing carriage-return or line-feed characters and serializes it into /etc/crontabs/root as though it were one logical line. An authenticated delegated user with the luci-app…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93576] Netty netty-codec-smtp — SMTP command-name field is not CRLF-validated (incomplete fix of CVE-2025-5…
Netty netty-codec-smtp — SMTP command-name field is not CRLF-validated (incomplete fix of CVE-2025-59419)
M Alto vulnerabilidad
18/09/2026
Vulnerabilidad alta en Synology DSM: inyección CRLF permite lectura/escritura de archivos
Una falla de neutralización de secuencias CRLF en la API de usuarios de Synology DiskStation Manager (DSM) afecta versiones previas a 7.2.1-69057-10, 7.2.2-72806-7 y 7.3.2-86009-2. Usuarios remotos autenticados pueden leer/escribir archivos arbitrarios y provocar denegación de servicio tras reinicio del sistema. Impacta infraestructuras de almacenamiento en PYMES y centros de datos de la región.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-90819] A weakness has been identified in a2aproject a2a-java 1.2.0. The affected element is the function Ba…
A weakness has been identified in a2aproject a2a-java 1.2.0. The affected element is the function BasePushNotificationSender.dispatchNotification of the file server-common/src/main/java/org/a2aproject/sdk/server/tasks/BasePushNotificationSender.java of the component Authorization Header Construction. This manipulation causes http response splitting. The attack can be initiated remotely. Upgrading …
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-90937] froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowi…
froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives. Attackers can supply URLs containing literal newlines that are written verbatim into vhost config files during cron rebuild, enabling web server configuration corruption, denial of service, or hijacking of HTTP …
M Alto vulnerabilidad
04/09/2026
[CVE-2026-48019] Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vuln…
Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony Mailer and Symfony Mime handle certain character sequences, may allow an unauthenticated attacker to interfere with outbound email processing in applications that send mail to user-supplied addresses. This issue has been patche…
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-75925] Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker…
Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted by the local service are written to a file later consumed by a privileged subprocess, without line-ending sequences being neutralized, which allows additional directives to be introduced into that file. The configuration interface…
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-84372] Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 un…
Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replication connections reparses an already serialized RESP buffer in AbstractAggregateConnection::write() by splitting it with explode("\r\n") instead of honoring RESP length prefixes. Attacker-controlled keys or values containing CRLF s…
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-82854] Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.siz…
Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter. When an application passes a custom envelope object with a size property containing CRLF characters to sendMail(), the value is concatenated into the SMTP MAIL FROM command (as SIZE=...) without sanitization, allowing injection of arbitrary SMTP commands such as RCPT TO to silently add …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-47890] Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Event…
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
M Alto vulnerabilidad
26/08/2026
[CVE-2026-54511] LogTape is an unobtrusive logging library. Prior to 1.3.11, 2.0.14, and 2.1.5, the @logtape/syslog p…
LogTape is an unobtrusive logging library. Prior to 1.3.11, 2.0.14, and 2.1.5, the @logtape/syslog package's escapeStructuredDataValue() function in packages/syslog/src/syslog.ts does not neutralize C0 control characters from U+0000 through U+001F in structured data values, and formatStructuredData() inserts property keys without validating the RFC 5424 SD-NAME grammar. When includeStructuredData …
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-77549] A malicious actor with access to the network and under certain conditions could exploit an Improper …
A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances.
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-77550] A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequen…
A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances.
M Crítico vulnerabilidad
10/08/2026
Inyección de comandos OS en crontab-ui v0.4.2 permite ejecución remota sin autenticación
Una vulnerabilidad crítica de inyección de comandos en crontab-ui afecta todas las versiones hasta la 0.4.2, permitiendo a atacantes no autenticados inyectar trabajos cron arbitrarios mediante solicitudes GET manipuladas al parámetro env_vars. Esta exposición es de alto riesgo para empresas en LATAM que usan este componente en infraestructuras de automatización, facilitando compromiso de servidores, exfiltración de datos y movimiento lateral en redes corporativas.