Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Rti" — 917 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1052
Esta semana
RSS
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-55634] Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026…
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-definition import endpoint /pimcore-studio/api/class/definition/configuration-view/detail/{id}/import accepts a DataObject field name that is emitted without an identifier allowlist by lib/DataObject/ClassBuilder/FieldDefinitionPropertiesBuilder.php into generated PHP properties and …
M Alto vulnerabilidad
28/08/2026
[CVE-2026-55215] MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL …
MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to versions 3.3.3, 3.4.6, and 3.5.3, when ssl is enabled without a pinned CA or server certificate, MariaDB Connector/Node.js sends credentials before completing certificate fingerprint validation. In lib/cmd/handshake/auth/handshake.js, a server that selects mysql_clear_password as…
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad de SSRF en Budibase backend-core permite eludir restricciones de red
Budibase backend-core omite el rango 100.64.0.0/10 de su lista negra predeterminada de SSRF, permitiendo que usuarios autenticados con permisos de Builder ejecuten consultas REST datasource contra redes internas. Este rango es alta en infraestructuras cloud compartidas (AWS, Google Cloud) donde se asignan direcciones privadas. La vulnerabilidad afecta principalmente a deployments autohospedados sin configuración personalizada de listas negras.
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad SSRF alta en Budibase Server anterior a 3.41.3 expone credenciales de CouchDB
Budibase Server versiones anteriores a 3.41.3 contiene una vulnerabilidad de falsificación de solicitud del lado del servidor (SSRF) en el endpoint de verificación de fuentes de datos. Usuarios con permisos de constructor pueden enviar URLs arbitrarias sin validación, permitiendo a atacantes extraer credenciales internas de CouchDB y obtener acceso total a bases de datos en despliegues en la nube. Esto es alta para empresas LATAM que utilizan Budibase en infraestructura compartida o multitenante.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-42391] An unauthenticated attacker can send an IMAP ID command with a very large number of parameters befor…
An unauthenticated attacker can send an IMAP ID command with a very large number of parameters before logging in, which causes memory and CPU usage to grow disproportionately. The login process can be terminated by the out-of-memory handling, which also terminates all other connections handled by the same process. This can cause degradation or denial of service for IMAP logins. Limit the number of…
M Alto vulnerabilidad
28/08/2026
[CVE-2026-18717] ASE2000 2.35 through 2.37 is vulnerable to an improper certificate validation vulnerability, which m…
ASE2000 2.35 through 2.37 is vulnerable to an improper certificate validation vulnerability, which may allow an attacker to impersonate the trusted peer, complete the TLS handshake, and read or modify protected communications.
M Alto vulnerabilidad
27/08/2026
[CVE-2026-81726] NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass paths…
NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by using raw file operations on caller-controlled paths. Attackers can read or write files outside allowed sandbox roots through TransitionParser, AveragedPerceptron, PerceptronTagger, and maxent parameter APIs when pathsec is enabled.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
27/08/2026
[CVE-2026-81705] openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the pas…
openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the password is supplied via bundled short-option spellings (e.g. -apHunter2) or abbreviated long-option spellings (e.g. --passw). The sanitizer only recognized exact option names, --option=value forms, and tokens starting with -p, so these spellings bypass the redaction chokepoint and the cleartext passwo…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-81683] openssl_encrypt (pip package openssl-encrypt) versions 1.4.8 and earlier store an mTLS client privat…
openssl_encrypt (pip package openssl-encrypt) versions 1.4.8 and earlier store an mTLS client private key in cleartext within a world-readable (0644) SharedPreferences file via the desktop GUI's Settings screen 'combined certificate and private key' PEM field. A local attacker with file system access can read the exposed private key. Version 1.4.9 writes the PEM to a dedicated 0600 file, keeps onl…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-30046] A reachable assertion vulnerability in the NUDM-UECM interface of Open5GS v2.7.6 allows attackers to…
A reachable assertion vulnerability in the NUDM-UECM interface of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted DELETE request.
M Alto vulnerabilidad
27/08/2026
[CVE-2026-30047] A reachable assertion vulnerability in the /nsmf-pdusession/v1/sm-contexts component of Open5GS v2.7…
A reachable assertion vulnerability in the /nsmf-pdusession/v1/sm-contexts component of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted DELETE request.
M Alto vulnerabilidad
27/08/2026
[CVE-2026-47849] Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation …
Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 6902 JSON Patch (application/json-patch+json) requests. Spring Data REST 5.1.0 Spring Data REST 5.0.0 - 5.0.6 Spring Data REST 4.5.0 - 4.5.12 Spring Data REST 4.0.0 - 4.4.15 Spring Data REST 3.7.20 and earlier
M Alto vulnerabilidad
27/08/2026
[CVE-2026-13415] The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing se…
The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing settings via one of its AJAX actions, allowing users with the Editor role (when the administrator has granted the Editor role access to the CMP WordPress plugin before 4.1.18's admin-bar controls) to update arbitrary WordPress options, including options that lead to privilege escalation to Administra…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-81029] OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued to…
OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued token to it. SamlLoginServlet reads the callback request parameter and stores it in the HTTP session without comparing it against any configured or registered destination, and the assertion consumer servlet later formats that stored value into a URL carrying the freshly issued JWT together with the ac…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-80578] In the Linux kernel, the following vulnerability has been resolved: fbdev: core: Fix pointer desync…
In the Linux kernel, the following vulnerability has been resolved: fbdev: core: Fix pointer desynchronization in fb_io_read() In fb_io_read(), if copy_to_user() performs a partial copy (e.g., due to a faulty user buffer), the loop adjusts the chunk size 'c' and updates the remaining 'count'. However, the hardware 'src' pointer has already been eagerly advanced by the original chunk size. If th…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-80528] In the Linux kernel, the following vulnerability has been resolved: ceph: avoid fs reclaim while us…
In the Linux kernel, the following vulnerability has been resolved: ceph: avoid fs reclaim while using current->journal_info handle_reply() stores a `ceph_mds_request` pointer in `current->journal_info` while filling the inode and dentry cache from an MDS reply. An allocation in this section can enter direct reclaim and prune dentries from another filesystem. If this dirties an ext4 inode, ext…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-80521] In the Linux kernel, the following vulnerability has been resolved: af_unix: Unlink scc_entry in un…
In the Linux kernel, the following vulnerability has been resolved: af_unix: Unlink scc_entry in unix_del_edge(). Kyle Zeng reported that GC could free a dead SCC partially. The scenario is as follows: 1) Create two SCCs: X -. A B ^--' 2) Run the following concurrently: 2-1) send() sk-B to sk-B from sk-X 2-2) close() both A and B At 2-1), there is a sm…
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-74746] In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: publish G…
In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: publish GC-visible tuple last nf_flow_table_iterate() only treats original-direction tuple nodes as owning entries. Publishing the original node first lets GC observe and free a flow while flow_offload_add() is still inserting the reply node. Publish the reply node first and the original node last so GC nev…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-16444] Improper neutralization of path traversal sequences in TeamViewer Desktop Clients prior Version 15.8…
Improper neutralization of path traversal sequences in TeamViewer Desktop Clients prior Version 15.81.5 allows an authenticated remote session participant to write files to unintended locations on the local file system via file transfer or virtual file clipboard mechanisms. An attacker can leverage this behavior to achieve arbitrary file write and potentially execute code with the privileges of th…
M Alto vulnerabilidad
25/08/2026
[CVE-2026-65084] NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker coul…
NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, code execution, and escalation of privileges.