Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,395
Total alertas
4758
Críticas
17006
Altas
8
Ransomware
1254
Esta semana
RSS
K Crítico vulnerabilidad
10/06/2026
[CVE-2026-53475] A flaw was found in assisted-migration-agent. The application hardcodes insecure Transport Layer Sec…
A flaw was found in assisted-migration-agent. The application hardcodes insecure Transport Layer Security (TLS) connections when communicating with vCenter. This vulnerability allows a Man-in-the-Middle (MITM) attacker to intercept and harvest vCenter administrator credentials. This can lead to unauthorized access to vCenter.
K Crítico vulnerabilidad
10/06/2026
[CVE-2026-53476] A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local…
A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local area network (LAN), can exploit a path traversal vulnerability. By crafting a specially designed gzipped tarball, the attacker can bypass security checks and write arbitrary files to the system. This could ultimately lead to the execution of unauthorized code on the appliance.
M Alto vulnerabilidad
10/06/2026
[CVE-2026-53689] libnfs through 6.0.2 before 55c18ea does not validate a string size, leading to an integer overflow …
libnfs through 6.0.2 before 55c18ea does not validate a string size, leading to an integer overflow during a connection to a crafted NFS server. This occurs in libnfs_zdr_string in lib/libnfs-zdr.c.
M Alto vulnerabilidad
10/06/2026
[CVE-2026-6090] A potential authentication bypass was reported in Lenovo Smart Connect for Windows that could allow …
A potential authentication bypass was reported in Lenovo Smart Connect for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges.
M Alto vulnerabilidad
10/06/2026
[CVE-2026-8637] A potential uncontrolled search path vulnerability was reported in the LanSchool Classic client appl…
A potential uncontrolled search path vulnerability was reported in the LanSchool Classic client application that could allow a local authenticated user to execute arbitrary code with elevated privileges.
K Crítico vulnerabilidad
10/06/2026
[CVE-2026-53469] A flaw was found in migration-planner. An authenticated user can exploit this vulnerability by sendi…
A flaw was found in migration-planner. An authenticated user can exploit this vulnerability by sending a DELETE request to the /api/v1/sources route, which lacks proper authorization and filtering. This allows for the destruction of all customer data, including sources, agents, and assessments, leading to a critical loss of availability and integrity across the entire SaaS platform.
K Crítico vulnerabilidad
10/06/2026
[CVE-2026-53470] A flaw was found in migration-planner. An authenticated attacker could exploit an improper access co…
A flaw was found in migration-planner. An authenticated attacker could exploit an improper access control vulnerability in the `/api/v1/sources/{id}/image-url` endpoint. This flaw allows the attacker to bypass an ownership check and obtain presigned S3 URLs for Open Virtual Appliance (OVA) images belonging to other users. Consequently, the attacker can download OVA images containing sensitive info…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
K Crítico vulnerabilidad
10/06/2026
[CVE-2026-53471] A flaw was found in migration-planner. The agent-API middleware processes JSON Web Tokens (JWTs) for…
A flaw was found in migration-planner. The agent-API middleware processes JSON Web Tokens (JWTs) for authentication, but its UpdateSourceInventory and UpdateAgentStatus handlers fail to validate the source_id claim within these tokens against the requested source ID. This oversight allows an authenticated attacker with a valid agent token to manipulate data across different tenants, leading to a c…
K Alto vulnerabilidad
10/06/2026
[CVE-2026-53473] A flaw was found in migration-planner-ui-app. An attacker can register a malicious discovery agent w…
A flaw was found in migration-planner-ui-app. An attacker can register a malicious discovery agent with a specially crafted credentialUrl containing JavaScript code. When an organizational user clicks this link in the user interface, the embedded malicious code executes within the user's browser session. This cross-site scripting (XSS) vulnerability allows the attacker to compromise the victim's R…
K Crítico vulnerabilidad
10/06/2026
[CVE-2026-53474] A flaw was found in migration-planner. A remote authenticated attacker could exploit this vulnerabil…
A flaw was found in migration-planner. A remote authenticated attacker could exploit this vulnerability by uploading a specially crafted RVTools .xlsx file. Due to improper input sanitization, malicious SQL embedded within a spreadsheet cell is executed when cluster names are processed. This SQL Injection allows for arbitrary file reading on the system, potentially exposing sensitive information s…
M Alto vulnerabilidad
10/06/2026
[CVE-2026-45564] Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8…
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POST /config/versions////save interpolates the URL-path configver parameter directly into a config-version path that ends up at os.system(f"dos2unix -q {cfg}"). configver is not run through EscapedString (Pydantic doesn't validate path segments declar…
M Crítico vulnerabilidad
10/06/2026
[CVE-2026-45550] Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8…
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PUT /smon/check (app/routes/smon/routes.py:117-138) gates only on roxywi_common.check_user_group_for_flask() — which validates that the caller has some group, not that the target check_id belongs to it. The downstream SQL update functions update_smon, update_smonHttp, update_smonTc…
M Crítico vulnerabilidad
10/06/2026
[CVE-2026-45552] Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8…
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the install blueprint declares only bp.before_request → @jwt_required() (app/routes/install/routes.py:36-39). The individual endpoints install_exporter, install_waf, install_geoip, check_geoip, get_exporter_version, and get_task_status are not wrapped in page_for_admin and do not c…
M Crítico vulnerabilidad
10/06/2026
[CVE-2026-45556] Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8…
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POST /waf///rule//save accepts a config_file_name form field that is passed straight through to config_mod.master_slave_upload_and_restart(...) as the destination path. The validation chain (_replace_config_path_to_correct → check_is_conf) only requires…
M Crítico vulnerabilidad
10/06/2026
[CVE-2026-45558] Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8…
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the HAProxy section-save endpoints (POST /api/service/haproxy//section/ and the PUT / global / defaults variants) accept a JSON option field that is not validated, not escaped, and is rendered verbatim into the generated HAProxy configuration via the sectio…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
10/06/2026
[CVE-2026-45549] Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8…
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, agent_action (app/routes/smon/agent_routes.py:166-179) has decorators @bp.post('/agent/action/') and @jwt_required() only — no role check, no group ownership check on the server_ip form field. Any authenticated user, including role 4 (guest), can start, stop, or restart the…
M Alto vulnerabilidad
10/06/2026
[CVE-2026-9758] Improper comparison with the certificates trusted list in S2OPC allows an attacker well-formed untru…
Improper comparison with the certificates trusted list in S2OPC allows an attacker well-formed untrusted certificate to be considered trusted
N Alto vulnerabilidad
10/06/2026
[CVE-2026-52758] Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user…
Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied values directly into SQL queries without escaping or parameterization. Remote attackers can inject arbitrary SQL via the BSim network query protocol to read, modify, or delete data in the PostgreSQL database.
J Alto vulnerabilidad
10/06/2026
[CVE-2026-53435] In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins …
In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows them to handle HTTP requests afterwards. This can be used to impersonate any user and send HTTP requests on their behalf, up to and including use of the Script Cons…
N Alto vulnerabilidad
10/06/2026
[CVE-2026-52750] Ghidra before 12.1 contains a command injection vulnerability in URL annotation handling on Windows …
Ghidra before 12.1 contains a command injection vulnerability in URL annotation handling on Windows where cmd.exe metacharacters are not properly escaped. Attackers can execute arbitrary commands under the Ghidra user's privileges by embedding malicious URLs in program comments that victims click.