Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Rti" — 573 resultados ✕ Limpiar búsqueda
13,566
Total alertas
3081
Críticas
10213
Altas
8
Ransomware
1783
Esta semana
RSS
E Alto vulnerabilidad
14/07/2026
[CVE-2024-7708] For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer…
For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. This is particularly the case for 100-Continue, but any request where the network is slow can leak.
F Medio vulnerabilidad
14/07/2026
Buffer overread in authd and wad daemon
Fortinet PSIRT publica advisory de seguridad: Buffer overread in authd and wad daemon. Tipo: Vulnerabilidad de seguridad. Producto afectado: Fortios.
F Medio vulnerabilidad
14/07/2026
Cross-Site Scripting in Domain parameter
Fortinet PSIRT publica advisory de seguridad: Cross-Site Scripting in Domain parameter. Tipo: Cross-Site Scripting (XSS). Producto afectado: Fortisiem.
F Medio vulnerabilidad
14/07/2026
Header injection in Web Filter warning page
Fortinet PSIRT publica advisory de seguridad: Header injection in Web Filter warning page. Tipo: Vulnerabilidad de seguridad. Producto afectado: Fortios.
F Crítico vulnerabilidad
14/07/2026
Header injection in captive portal authentication form
Fortinet PSIRT publica advisory de seguridad: Header injection in captive portal authentication form. Tipo: Vulnerabilidad de seguridad. Producto afectado: Fortios.
F Crítico vulnerabilidad
14/07/2026
Missed certificate verification in AD Connector communication with FortiClient EMS
Fortinet PSIRT publica advisory de seguridad: Missed certificate verification in AD Connector communication with FortiClient EMS. Tipo: Vulnerabilidad de seguridad. Producto afectado: Forticlient.
F Crítico vulnerabilidad
14/07/2026
Out of bounds read in GUI
Fortinet PSIRT publica advisory de seguridad: Out of bounds read in GUI. Tipo: Vulnerabilidad de seguridad. Producto afectado: Fortiauthenticator.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
F Crítico vulnerabilidad
14/07/2026
Path traversal in CLI command allows deletion of root file system
Fortinet PSIRT publica advisory de seguridad: Path traversal in CLI command allows deletion of root file system. Tipo: Path Traversal. Producto afectado: Fortios.
F Medio vulnerabilidad
14/07/2026
SSL-VPN Reflected XSS
Fortinet PSIRT publica advisory de seguridad: SSL-VPN Reflected XSS. Tipo: Cross-Site Scripting (XSS). Producto afectado: Fortios.
F Alto vulnerabilidad
14/07/2026
Stack Buffer Overflow in Log Report
Fortinet PSIRT publica advisory de seguridad: Stack Buffer Overflow in Log Report. Tipo: Desbordamiento de Búfer. Producto afectado: Fortios.
F Medio vulnerabilidad
14/07/2026
Supers override fails to properly override supervisor address
Fortinet PSIRT publica advisory de seguridad: Supers override fails to properly override supervisor address. Tipo: Vulnerabilidad de seguridad. Producto afectado: Fortisiem.
F Crítico vulnerabilidad
14/07/2026
Unauthenticated VNC access exposed on all interfaces
Fortinet PSIRT publica advisory de seguridad: Unauthenticated VNC access exposed on all interfaces. Tipo: Vulnerabilidad de seguridad. Producto afectado: Fortisandbox.
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-58102] Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bounds read via a long certi…
Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bounds read via a long certificate extension OID in hv_exts. When building the extension hash (via extensions(), extensions_by_long_name(), extensions_by_oid(), or has_extension_oid()), the code passes OBJ_obj2txt()'s return value as the hash-key length; because that value is the OID's full text length rather than the bytes w…
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-59801] 9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote a…
9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact with provider management API endpoints by sending requests without any credentials due to missing authentication middleware in the Next.js API routes under src/app/api/providers/*. Attackers can enumerate, create, modify, or delete provider connections to expose partial credenti…
M Alto vulnerabilidad
13/07/2026
[CVE-2026-15683] Lorex 2K Indoor Wi-Fi Security Camera Device Management Server Improper Certificate Validation Vulne…
Lorex 2K Indoor Wi-Fi Security Camera Device Management Server Improper Certificate Validation Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Lorex 2K Indoor Wi-Fi Security Cameras. User interaction is not required to exploit this vulnerability. The specific flaw exists within the device management functionality. The issu…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
13/07/2026
[CVE-2026-55773] CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained …
CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. In versions prior to 2.3.6, 3.4.1 and 4.9.0, under certain circumstances, improper input handling could allow Cedar-expression injection via unescaped toCedarExpr(). The toCedarExpr() method on Cedar Value types does not escape special characters (" or \) when converting val…
M Alto vulnerabilidad
13/07/2026
[CVE-2026-9492] The MBStorage DRAM lighting control module within Gigabyte Control Center (GCC) developed by GIGABYT…
The MBStorage DRAM lighting control module within Gigabyte Control Center (GCC) developed by GIGABYTE Technology has an Improper Access Control vulnerability. Authenticated local attackers can send specific IOCTL commands through the driver MyPortIO_x64.sys bundled with the module, thereby arbitrarily reading and writing physical memory and obtaining kernel-level privileges.
M Alto vulnerabilidad
11/07/2026
[CVE-2026-13353] The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress i…
The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.0.1 via the 'MappedFields' parameter. This is due to missing capability checks on the AJAX handlers for install_addon, saveMappedFields, and StartImport, combined with the plugin nonce being exposed to any authenticated us…
O Alto vulnerabilidad
10/07/2026
[CVE-2026-52747] ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS …
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Prior to 3.0.16, the multipart/form-data request body parser in libmodsecurity silently removes embedded line breaks from non-file form-field values before exporting them to ARGS and ARGS_POST because src/request_body_processor/multipart.cc overwrites reserved bytes in m_reserve instead o…
M Alto vulnerabilidad
10/07/2026
[CVE-2026-55789] Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's …
Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's self-hosted SAML application IdP built the signed SAML response and assertion by string-substituting user-controlled profile attributes such as name, email, and custom attribute-mapping values into element-text placeholders of a SAML XML template using samlify 2.10.0, which left those placeholders u…