Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Rti" — 917 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1054
Esta semana
RSS
M Alto vulnerabilidad
07/09/2026
[CVE-2026-79691] Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5…
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-79644] Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5…
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-80164] Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5…
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86428] commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the Attrib…
commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the AttributesExtension when processing distinctly-named attributes. Attackers can submit Markdown with numerous distinct attribute names to cause quadratic-time attribute merging and filtering, consuming disproportionate CPU resources and preventing legitimate requests from completing.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86430] league/commonmark versions before 2.9.1 contain multiple denial of service vulnerabilities in fenced…
league/commonmark versions before 2.9.1 contain multiple denial of service vulnerabilities in fenced code block detection, reference link label lookup, and emphasis delimiter processing that perform super-linear work on crafted input. Attackers can submit specially crafted Markdown with long backtick runs, nested brackets, or delimiter sequences to consume disproportionate CPU time and prevent leg…
M Crítico vulnerabilidad
07/09/2026
Vulnerabilidad crítica en controladores Advantech WISE-6610 permite manipulación de certificados
Se identificó una vulnerabilidad crítica (CVSS 9.9) en múltiples modelos de controladores industriales Advantech WISE-6610 (versión 1.2.1_20251110) que afecta el manejador de eliminación de certificados de estación base. Esta vulnerabilidad permite a atacantes manipular funciones críticas de autenticación en sistemas de control industrial, poniendo en riesgo infraestructuras críticas, plantas de manufactura y sistemas de energía en operación en México y Latinoamérica.
M Alto vulnerabilidad
06/09/2026
Vulnerabilidad alta en Bifrost HTTP transport permite ejecución de código remoto sin autenticación
Bifrost HTTP transport anterior a versión 2.0.0 permite a atacantes no autenticados cargar y ejecutar plugins maliciosos a través de POST /api/plugins cuando la autenticación de gestión está deshabilitada (configuración por defecto). El cargador de objetos compartidos descarga archivos desde URLs HTTP y los ejecuta como librerías dinámicas en Go, comprometiendo completamente servidores en infraestructuras altas de LATAM. Afecta especialmente a plataformas de integración y orquestación de datos sin hardening de seguridad.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
05/09/2026
[CVE-2026-0799] In BPF instructions that load/store a value from/to a scratch memory register the register index is …
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit…
M Alto vulnerabilidad
05/09/2026
Vulnerabilidad alta en Bilibili Desktop: desactivación de verificación TLS y ejecución de código remoto
Bilibili Desktop versión 1.18.0 y anteriores desactiva la verificación de certificados TLS a nivel de proceso y ejecuta configuraciones JavaScript sin firma desde servidores remotos. Un atacante en posición de intermediario de red puede interceptar descargas de configuración, inyectar código JavaScript malicioso con acceso al puente IPC privilegiado, permitiendo ejecución de comandos del sistema y robo de credenciales de sesión.
M Alto vulnerabilidad
05/09/2026
Vulnerabilidad alta de omisión de autenticación en Coolify hasta v4.3.17
Coolify versiones anteriores a 4.3.17 contiene una falla de autenticación en el manejador de callback OAuth que permite a atacantes registrar direcciones de correo de víctimas en proveedores OAuth habilitados para obtener acceso autenticado sin verificar identidades ni requerir contraseña. Empresas que usan Coolify como plataforma de infraestructura o despliegue en México y LATAM corren riesgo de compromiso de cuentas administrativas y acceso no autorizado a recursos altas.
C Informativo vulnerabilidad
04/09/2026
[CVE-2026-18540] undici's retry interceptor can append the body of a ranged retry response to bytes already delivered…
undici's retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier partial response while still presenting the original response's status and headers. This happens when an upstream server delivers part of a body without a trustworthy resume checkpoint, for example a non-success response whose headers were already sent or a partial-content response …
M Alto vulnerabilidad
04/09/2026
Vulnerabilidad alta de SSRF en OpenPanel anterior a 2.3.0 permite acceso no autenticado a metadatos internos
OpenPanel versiones anteriores a 2.3.0 contiene una vulnerabilidad de Server-Side Request Forgery (SSRF) en los endpoints /misc/favicon y /misc/og que permite a atacantes no autenticados forzar al servidor a consultar hosts internos y endpoints de metadatos en la nube. Los atacantes pueden enumerar servicios internos, robar credenciales y acceder a información sensible de infraestructura. Esta vulnerabilidad afecta directamente a empresas en LATAM que utilizan OpenPanel como panel de control, especialmente en entornos de hosting compartido y nubes públicas.
M Alto vulnerabilidad
04/09/2026
Vulnerabilidad de denegación de servicio en SiYuan anteriores a v3.8.2
SiYuan versiones anteriores a v3.8.2 contienen una vulnerabilidad de denegación de servicio en el mecanismo de autenticación básica del servicio de publicación. Atacantes no autenticados pueden enviar múltiples solicitudes de autenticación con nombres de usuario inválidos y únicos para agotar la memoria del servidor y aumentar la carga de sincronización. Esta vulnerabilidad afecta principalmente a empresas en LATAM que utilizan SiYuan para gestión de contenido colaborativo o sistemas de conocimiento compartido.
M Alto vulnerabilidad
04/09/2026
Vulnerabilidad en Fastify anterior a v5.12.2 por validación incompleta de encabezados HTTP
Fastify versiones anteriores a 5.12.2 presentan una validación incompleta de encabezados HTTP case-insensitive en esquemas de rutas. La transformación de minúsculas no se aplica correctamente en dependencias JSON Schema Draft 7, permitiendo que propiedades no normalizadas en el esquema causen comportamiento inesperado o bypass de validaciones. Esto afecta a aplicaciones Node.js en producción que dependen de validación estricta de encabezados para autenticación, autorización o filtrado de solicitudes.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85525] Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a r…
Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a revoked TLS certificate to be accepted as valid, because OCSP responses were not reliably bound to the certificate being validated and definitive verification failures were treated as transient. A man-in-the-middle attacker holding a revoked certificate and its private key for a Snowflake or stage ho…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-85148] SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Un…
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed password to remotely access user hosts.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-85146] SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Un…
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account credentials and passwords for the SmartIT Agent directly from the application source code.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85147] SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Un…
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain a specific password from the source code, which can be used to retrieve the AES encryption key used for communication.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-75034] A flaw was found in Rancher Manager. The SAML assertion replay protection introduced by the fix for …
A flaw was found in Rancher Manager. The SAML assertion replay protection introduced by the fix for CVE-2026-44946 recorded consumed assertion IDs in a per-process cache, so each replica only detected replays that reached the same pod. In a high-availability deployment, an attacker holding a captured assertion could replay it once against every other replica to obtain additional authenticated sess…
M Alto vulnerabilidad
03/09/2026
[CVE-2026-80747] In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Add bounds check fo…
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Add bounds check for CRAT subtype length The CRAT parser validates that the subtype header fits within the image, but does not verify that the advertised subtype length fits. A malformed CRAT table with an oversized length field causes out-of-bounds reads when kfd_parse_subtype() casts the header to specific subtype …