Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
25/08/2026
[CVE-2026-70551] A user who can read an existing remote VCS repository can replace its configured origin or supply an…
A user who can read an existing remote VCS repository can replace its configured origin or supply an absolute VCS data URL.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-55537] PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, JobSubmitRequest.validate_webhoo…
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, JobSubmitRequest.validate_webhook_url() accepts webhook_url when resolution raises socket.gaierror because the exception path uses except socket.gaierror: pass. JobExecutor._send_webhook() later performs a fresh lookup, allowing DNS changes to direct the request to an internal service. This issue is fixed in version 4.6.58.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-55526] PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, spider_tools._host_is_bloc…
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, spider_tools._host_is_blocked() does not resolve ordinary hostnames before scrape_page fetches them. A hostname such as 127.0.0.1.nip.io passes validation and resolves to loopback, permitting internal HTTP access. The fix uses socket.getaddrinfo and fails closed on DNS errors. This issue is fixed in version 1.6.58.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-55525] PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the web_crawl function val…
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the web_crawl function validates only the initial URL before _crawl_with_httpx uses httpx.Client(follow_redirects=True). Redirect targets are not revalidated, so an attacker who influences a crawl target can redirect a public URL to loopback, private network, or cloud metadata services while ALLOW_LOCAL_CRAWL remains disable…
M Alto vulnerabilidad
25/08/2026
Vulnerabilidad alta de falsificación de solicitud en Ech0 anterior a 4.7.3
Ech0 versiones anteriores a 4.7.3 contiene una vulnerabilidad de falsificación de solicitud del lado del servidor (SSRF) en la función fetchPeerConnectInfo que permite a atacantes autenticados acceder a servicios internos y endpoints de metadatos en la nube mediante solicitudes HTTP no validadas. Esta falla afecta principalmente a infraestructuras cloud híbridas en empresas mexicanas y latinoamericanas que utilicen este software para operaciones de conectividad entre pares.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-78682] NLTK before 3.10.3 contains a server-side request forgery vulnerability in nltk.pathsec.urlopen (and…
NLTK before 3.10.3 contains a server-side request forgery vulnerability in nltk.pathsec.urlopen (and callers nltk.data.load, nltk.downloader.Downloader.index/download) when an HTTP proxy is configured. pathsec.urlopen validates the requested hostname locally, but proxy-handler inheritance disables the safe HTTP/HTTPS handlers so the actual fetch is performed by the proxy against a destination that…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-76838] Hi.Events validates a webhook destination only when it is registered, never when it is used. NoInter…
Hi.Events validates a webhook destination only when it is registered, never when it is used. NoInternalUrlRule in backend/app/Validators/Rules/NoInternalUrlRule.php resolves the hostname with gethostbyname() and rejects private and reserved ranges, which any public hostname passes. At dispatch, WebhookDispatchService takes the stored URL and calls it through spatie/laravel-webhook-server without r…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
24/08/2026
[CVE-2026-71366] A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. …
A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. The webhook, Mattermost, Rocket.Chat, and Grafana notification backends use notification template URLs as direct HTTP request targets without validating the target address against private, loopback, or reserved IP ranges. An organization notification administrator can create notification templates p…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-10582] Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRem…
Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRemote, and it inspects the URL text alone. CheckAllowedHTTPURL in config/security/securityConfig.go applies the configured pattern list and then re-checks a canonicalised form of an integer, hex or octal IPv4 host, but it never resolves the hostname and never inspects the address the HTTP client actua…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-75975] fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validat…
fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6 grammar, so invalid trailing text in an authority can be silently discarded and a malformed attacker-controlled host is turned into a different valid IPv6 destination. For example, a bracketed literal with invalid trailing characters is normalized to the unspecified address, whic…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-75899] fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and th…
fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then decodes the parsed hostname a second time during authority recomposition, so a single call to normalize or resolve can turn nested percent-encoded input into a different network destination such as a loopback hostname or address. For example, a doubly encoded host that spells out a loopback name …
M Crítico vulnerabilidad
22/08/2026
Vulnerabilidad crítica SSRF en plugin Mailgun para WordPress permite acceso no autorizado
El plugin Mailgun for WordPress versiones hasta 2.2.0 contiene una vulnerabilidad de Server-Side Request Forgery (SSRF) por validación insuficiente en la función add_list(). Atacantes no autenticados pueden explotar el path traversal mediante claves controladas en $_POST['addresses'] para acceder a recursos internos del servidor. Afecta directamente a sitios WordPress en México y LATAM que utilizan este plugin para gestión de correos transaccionales.
M Alto vulnerabilidad
21/08/2026
[CVE-2026-54457] TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation,…
TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and experimentation. Prior to 2026.6.0, the TensorZero Gateway /internal/object_storage endpoint accepts a caller-supplied JSON storage_path parameter that dynamically overrides the [object_storage] configuration. Selecting the filesystem storage type allows arbitrary files on the gat…
M Alto vulnerabilidad
21/08/2026
[CVE-2026-22681] OpenViking before 0.3.4 contains a server-side request forgery vulnerability that allows authenticat…
OpenViking before 0.3.4 contains a server-side request forgery vulnerability that allows authenticated low-privilege attackers to access internal network services by submitting arbitrary URLs to the resources API endpoint. Attackers can POST a crafted URL to /api/v1/resources, causing the server to issue outbound HEAD and GET requests with redirects enabled to loopback, RFC 1918, link-local, or cl…
M Alto vulnerabilidad
21/08/2026
[CVE-2026-77775] Proxy LLM de Headroom permite redirección no autorizada a servidores upstream
El proxy LLM de Headroom contiene una vulnerabilidad de redirección abierta que permite a clientes no autenticados especificar destinos upstream arbitrarios mediante el encabezado x-headroom-base-url. Un atacante puede redirigir solicitudes de LLM hacia servidores maliciosos bajo su control para interceptar datos sensibles, credenciales de API o prompts confidenciales. Afecta directamente a empresas en LATAM que implementan soluciones de proxy centralizado para modelos de lenguaje en arquitecturas de integración con proveedores cloud.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
21/08/2026
[CVE-2026-50112] SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a template pointing t…
SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a template pointing to an attacker-controlled metalink file containing internal targets. The Secondary Storage VM will retrieve the data and persist it as a template file, which can later be downloaded through normal APIs. RCE on KVM hypervisor via NFS, Metalink files with/without Direct Downloads: An authenticated Cl…
M Alto vulnerabilidad
20/08/2026
[CVE-2026-72848] SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documente…
SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_domain control only to leaf url entries. The loop over url elements filters cross-domain locations, but the loop over nested sitemap elements passes the child loc straight to self.scrape_all([loc.text], "xml"), which reaches WebBaseLoader.scrape_all and an aiohttp GET, with no dom…
M Alto vulnerabilidad
20/08/2026
[CVE-2026-72860] The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues se…
The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues server-side HTTP requests to it, guarding the destination with assertPublicUrl from src/shared/utils/ssrfGuard.js. That guard compares hostname strings only: it resolves no DNS, does not revalidate after a redirect, and its IPv4-mapped IPv6 branch is unreachable. The branch matches ^::ffff:(\d+\.\d+\.…
M Alto vulnerabilidad
20/08/2026
[CVE-2026-69855] Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to di…
Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network.
M Alto vulnerabilidad
20/08/2026
[CVE-2026-69543] Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevat…
Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network.