Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ui" — 3486 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Alto vulnerabilidad
25/09/2026
[CVE-2026-100310] GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the LIBEXTRACT…
GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the LIBEXTRACTOR_PREFIX environment variable without proper privilege checks. A local attacker can exploit this by setting LIBEXTRACTOR_PREFIX to a directory containing a malicious plugin that executes arbitrary code with elevated privileges when loaded by a setuid or setgid program.
M Alto vulnerabilidad
25/09/2026
[CVE-2026-97878] A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Impacted is the function anon…
A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Impacted is the function anonymous of the file /druid/index.html of the component Druid Console. Such manipulation leads to missing authentication. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Alto vulnerabilidad
25/09/2026
[CVE-2026-49850] InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. …
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane exposes Invoices::delete() and Invoices::delete_invoice_tax() as state-changing routes without requiring POST and validating a CSRF token. When an authenticated administrator loads attacker-controlled content that requests an affected route, the application can delete an…
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-39353] InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. …
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2-rc-1, InvoicePlane builds its permitted template list by scanning a PHP template directory that can be written through an administrator-controlled file-write capability. A malicious PHP file placed in the directory is automatically trusted by Mdl_templates and can be selected as publi…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-85750] Piwigo before v16.4.0 is vulnerable to arbitrary file read and remote code execution in image upload…
Piwigo before v16.4.0 is vulnerable to arbitrary file read and remote code execution in image upload handling when using the Imagick library due to insufficient validation and unsafe processing of user-supplied image files. By abusing format confusion (e.g., disguising SVG content as PNG), an attacker can trigger unintended interpretation of embedded SVG elements that reference local files. In mor…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-84884] IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible pla…
IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent format. An authenticated attacker who gains access to the stored credential could recover the password and obtain an administrative REST access token.
M Alto vulnerabilidad
25/09/2026
[CVE-2026-98130] In the Linux kernel, the following vulnerability has been resolved: sctp: fix a TOCTOU race in SCTP…
In the Linux kernel, the following vulnerability has been resolved: sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START The SCTP_CMD_TIMER_START handler checks timer_pending() before calling timer_reduce(). The timer can expire and detach between these operations, causing timer_reduce() to rearm the timer without taking the association reference required for the newly armed timer. The timer callbac…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
25/09/2026
[CVE-2026-98069] In the Linux kernel, the following vulnerability has been resolved: net/rds: acquire the fastpath l…
In the Linux kernel, the following vulnerability has been resolved: net/rds: acquire the fastpath locks in rds_conn_shutdown() rds_conn_shutdown() quiesces the transmit and receive-refill paths by waiting for RDS_IN_XMIT and RDS_RECV_REFILL to be sampled clear, and then runs the transport shutdown and rds_conn_path_reset(). Sampling the bits clear is not the same as owning them: the moment afte…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-98070] In the Linux kernel, the following vulnerability has been resolved: net/rds: acquire RDS_IN_XMIT in…
In the Linux kernel, the following vulnerability has been resolved: net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks() rds_tcp_reset_callbacks() quiesces the transmit path by setting the path state to RDS_CONN_RESETTING and then waiting for RDS_IN_XMIT to be sampled clear before swapping the underlying socket and calling rds_send_path_reset(). Sampling the bit clear is not the same as ow…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-98027] In the Linux kernel, the following vulnerability has been resolved: net: dsa: mv88e6xxx: bound the …
In the Linux kernel, the following vulnerability has been resolved: net: dsa: mv88e6xxx: bound the policy rule dump by the caller's buffer size mv88e6xxx_get_rxnfc() uses rxnfc->rule_cnt as the write index while dumping the policy IDR, clobbering the input value before it has been looked at. That input is the number of entries the caller had room for. ETHTOOL_GRXCLSRLALL requires no CAP_NET_ADM…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-98029] In the Linux kernel, the following vulnerability has been resolved: eth: nfp: bound the ntuple rule…
In the Linux kernel, the following vulnerability has been resolved: eth: nfp: bound the ntuple rule dump by the caller's buffer size nfp_net_get_fs_loc() dumps every entry of nn->fs.list into rule_locs[] without consulting cmd->rule_cnt, which is how many entries the caller had room for. ETHTOOL_GRXCLSRLALL requires no CAP_NET_ADMIN and the ioctl sizes the buffer from the rule_cnt userspace pas…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-98030] In the Linux kernel, the following vulnerability has been resolved: net: dsa: bcm_sf2: bound the CF…
In the Linux kernel, the following vulnerability has been resolved: net: dsa: bcm_sf2: bound the CFP rule dump by the caller's buffer size bcm_sf2_cfp_rule_get_all() walks the whole cfp.unique bitmap into rule_locs[] without consulting nfc->rule_cnt, which is how many entries the caller had room for. ETHTOOL_GRXCLSRLALL requires no CAP_NET_ADMIN and the ioctl sizes the buffer from the rule_cnt …
M Alto vulnerabilidad
25/09/2026
[CVE-2026-97953] In the Linux kernel, the following vulnerability has been resolved: net: stmmac: fix TX descriptor …
In the Linux kernel, the following vulnerability has been resolved: net: stmmac: fix TX descriptor availability check for TSO traffic stmmac_tso_xmit() estimates the number of free TX descriptors required by a TSO skb as: (skb->len - proto_hdr_len) / TSO_MAX_BUFF_SIZE + 1 which assumes the payload is split into TSO_MAX_BUFF_SIZE chunks. This underestimates the descriptors actually consumed by…
M Alto vulnerabilidad
25/09/2026
Vulnerabilidad alta en Rojo: DNS Rebinding permite lectura de código fuente y ejecución de programas
La API HTTP de Rojo (puerto 34872 por defecto) carece de validación de encabezados Host/Origin, permitiendo ataques de DNS Rebinding. Un atacante puede leer todo el código fuente del proyecto, escribir código malicioso en disco y ejecutar programas locales sin interacción del usuario. Afecta principalmente a desarrolladores que usan Rojo en máquinas con acceso a internet y a servidores de desarrollo expuestos en redes corporativas de LATAM.
M Alto vulnerabilidad
25/09/2026
[CVE-2026-97602] In the Linux kernel, the following vulnerability has been resolved: inet: frags: invalidate queues …
In the Linux kernel, the following vulnerability has been resolved: inet: frags: invalidate queues before flushing them fqdir_pre_exit() flushes the skbs from incomplete queues without changing their completion state. A fragment which found a queue before high_thresh was cleared can then acquire the queue lock and reuse stale reassembly metadata. A queue concurrently killed after fqdir->dead is …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
25/09/2026
[CVE-2026-97531] In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Skip vport under…
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Skip vport under deletion in report ID acquisition qla24xx_report_id_acquisition() format-1 handling walks ha->vp_list under vport_slock, takes a vref_count on the matching vport and calls qla_update_host_map() to register its port id. A vport teardown via qla24xx_vport_delete() sets VPORT_DELETE, then qla24xx_di…
M Alto vulnerabilidad
25/09/2026
Vulnerabilidad XSD alta en Themify Builder para WordPress afecta sitios sin autenticación
El plugin Themify Builder para WordPress (versiones hasta 7.8.1) es vulnerable a inyección de scripts almacenados (Stored XSS) a través del parámetro 'css[fonts]' sin validación adecuada. Atacantes no autenticados pueden inyectar código malicioso que se ejecuta cuando usuarios acceden a páginas comprometidas, comprometiendo datos de administradores y visitantes en sitios empresariales de México y LATAM que usen este plugin.
M Alto vulnerabilidad
25/09/2026
Vulnerabilidad XLS almacenado en User Profile Builder para WordPress (CVE-2026-95866)
El plugin User Profile Builder para WordPress es vulnerable a inyección de scripts entre sitios (XLS) a través del campo de avatar en versiones hasta 4.0.2. Atacantes no autenticados pueden ejecutar código malicioso en páginas del sitio afectando a todos los visitantes. El riesgo es alta en sitios con registro público de usuarios.
M Alto vulnerabilidad
25/09/2026
[CVE-2026-93303] The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to S…
The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via 'form_data' Rich Text Field via Draft Save/Resume in all versions up to, and including, 2.10.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will …
M Alto vulnerabilidad
25/09/2026
[CVE-2026-62062] Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows Cross Site Reque…
Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows Cross Site Request Forgery. This issue affects Elementor Website Builder: from n/a through 4.3.1.