Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 25 min
Buscando: "Ni" — 7251 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-79809] An unauthenticated path traversal vulnerability exists in an API endpoint of ClearPass Policy Manage…
An unauthenticated path traversal vulnerability exists in an API endpoint of ClearPass Policy Manager. Successful exploitation of this vulnerability allows an unauthenticated remote attacker to influence authorization decisions and be assigned an unintended role.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-79811] A SQL injection vulnerability in the API of ClearPass Policy Manager could allow a remote authentica…
A SQL injection vulnerability in the API of ClearPass Policy Manager could allow a remote authenticated attacker with administrative privileges to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful exploitation could allow an attacker to execute arbitrary database commands.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-79799] A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an una…
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-79803] A command injection vulnerability exists in the API of ClearPass Policy Manager. Successful exploita…
A command injection vulnerability exists in the API of ClearPass Policy Manager. Successful exploitation could allow an authenticated remote attacker to escalate privileges and gain administrative control of the affected system.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-76747] Buffer overflow vulnerabilities exist in the affected interface of AOS-S. Successful exploitation co…
Buffer overflow vulnerabilities exist in the affected interface of AOS-S. Successful exploitation could allow an unauthenticated remote attacker to expose sensitive memory contents and cause a denial of service on the device.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-76748] A privilege escalation vulnerability exists in the API of AOS-S. Successful exploitation could allow…
A privilege escalation vulnerability exists in the API of AOS-S. Successful exploitation could allow an authenticated read-only user to escalate their privileges and gain administrative access to the affected system.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-76752] Authentication bypass vulnerabilities exist in the web-based management and API interfaces of HPE Ne…
Authentication bypass vulnerabilities exist in the web-based management and API interfaces of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an unauthenticated remote attacker to circumvent existing authentication controls and gain administrative access to the affected system.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-76746] An unauthenticated buffer overflow vulnerability exists in AOS-S. Successful exploitation could allo…
An unauthenticated buffer overflow vulnerability exists in AOS-S. Successful exploitation could allow an unauthenticated adjacent attacker to expose sensitive memory contents and cause a denial of service on the affected device.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-103007] Incorrect Authorization (CWE-863) in Elasticsearch can lead to Privilege Escalation via a delegated …
Incorrect Authorization (CWE-863) in Elasticsearch can lead to Privilege Escalation via a delegated administrative privilege whose scope is not fully enforced during authorization checks. Elasticsearch contains an incorrect authorization weakness in a configurable, non-default privilege that lets an administrator delegate limited role-management capability to another user, scoped to specific indic…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-102406] Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana could lead to cross-tenant data…
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana could lead to cross-tenant data interception. In this context, "tenant" refers to a user or team sharing the same Kibana deployment, not a separate Elastic Cloud organization or customer. Kibana's Fleet package installation process allowed a user holding delegated Fleet package-management privileges, without direct Elasticsearch …
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-102161] An unauthenticated attacker located on an adjacent private network (or any attacker routed through a…
An unauthenticated attacker located on an adjacent private network (or any attacker routed through a reverse proxy/load balancer that forwards client headers) can forge their source IP address and gain administrative session privileges on the CV-CUE backend.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-102162] On affected Arista Wi-Fi access points with captive portal, or application firewall enabled on at le…
On affected Arista Wi-Fi access points with captive portal, or application firewall enabled on at least one SSID, a vulnerability in the wireless gateway service could allow an unauthenticated network-adjacent attacker to send a crafted packet that triggers a stack overflow, resulting in a denial-of-service condition or potentially execute arbitrary code on the device. The wireless gateway service…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-102163] On affected Arista access points with Wireless Intrusion Prevention System (WIPS) active, an unauthe…
On affected Arista access points with Wireless Intrusion Prevention System (WIPS) active, an unauthenticated attacker within radio frequency (RF) proximity can send a crafted frame to crash the sensor service, disabling WIPS monitoring on the access point, or potentially achieve remote code execution. No wireless association or authentication is required.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-101158] A missing input validation vulnerability in the Fileserver upload API allows an authenticated attack…
A missing input validation vulnerability in the Fileserver upload API allows an authenticated attacker with file upload privileges to execute stored cross-site scripting (XSS). Successful exploitation could enable the attacker to hijack another CloudVision user's web session, potentially granting full access to their account and administrative permissions.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-102155] An XML External Entity (XXE) injection vulnerability in the WiFi-server Spectralight application all…
An XML External Entity (XXE) injection vulnerability in the WiFi-server Spectralight application allows any authenticated user to send malicious requests, leading to arbitrary local file disclosure and partial denial of service.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-101153] On affected versions of CloudVision Portal (on-premises) or CloudVision Sensor, a path traversal vul…
On affected versions of CloudVision Portal (on-premises) or CloudVision Sensor, a path traversal vulnerability exists. An authenticated user with sufficient high privileges could exploit this to extract unintended data from the Sensor.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-101154] An authenticated remote attacker with specific permissions can read or write files on the platform f…
An authenticated remote attacker with specific permissions can read or write files on the platform filesystem beyond the intended scope through specially crafted requests and/or crafted file uploads to the Network Provisioning Image Repository.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-101156] A stored cross-site scripting (XSS) vulnerability may allow an authenticated, high-privilege adminis…
A stored cross-site scripting (XSS) vulnerability may allow an authenticated, high-privilege administrator to store malicious content in a configuration. The content may execute in another authenticated user's browser when that user views or compares the affected configuration. Successful exploitation may allow the attacker to act through the victim's authenticated browser session to access sensit…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106442] Hydra is a framework for elegantly configuring complex applications. From 1.3.4 until 1.3.6 and 1.4.…
Hydra is a framework for elegantly configuring complex applications. From 1.3.4 until 1.3.6 and 1.4.0.dev9, the instantiate() target blacklist introduced for CVE-2026-68508 incompletely checks the effective callable selected by the target field. Execution wrappers such as timeit.timeit, executable deserialization through pickle.loads, aliases, callable-returning helpers, generic dispatch, and defe…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-104073] NetBox versions 2.9.5 before 4.7.0 contain a server-side template injection vulnerability that allow…
NetBox versions 2.9.5 before 4.7.0 contain a server-side template injection vulnerability that allows a low-privileged user with the "Can add custom links" permission to steal session cookies and API tokens of other users by exposing the raw Django HttpRequest object to the Jinja2 template context. Attackers can craft a custom link template embedding request.COOKIES['sessionid'] or a user's API to…