Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,696
Total alertas
3097
Críticas
10327
Altas
8
Ransomware
1772
Esta semana
RSS
M Alto vulnerabilidad
07/08/2026
Vulnerabilidad alta en Home Assistant Companion permite ejecución de acciones por aplicaciones no autorizadas
Home Assistant Companion (versiones anteriores a 2026.5.3) no valida correctamente las aplicaciones que envían enlaces de etiquetas NFC o QR a través del sistema operativo, permitiendo que cualquier aplicación no confiable en el dispositivo ejecute acciones arbitrarias en la plataforma de automatización. Esto compromete la privacidad y seguridad local de hogares inteligentes en México y Latinoamérica que dependen de este software de código abierto.
M Alto vulnerabilidad
07/08/2026
CVE-2026-66061: Validación insuficiente en Home Assistant iOS permite ejecución de acciones no autorizadas
Home Assistant versiones anteriores a 2026.5.0 presentan una vulnerabilidad alta en la aplicación iOS Companion que permite a aplicaciones no confiables ejecutar acciones mediante enlaces NFC o QR sin validación ni confirmación del usuario. Un atacante podría interceptar o redirigir estas acciones para comprometer dispositivos domóticos, sistemas de control industrial o infraestructura conectada en empresas LATAM. El riesgo es elevado en entornos con múltiples dispositivos IoT altas.
M Crítico vulnerabilidad
07/08/2026
Vulnerabilidad crítica en Kata Containers permite ejecución de código en el host
Kata Containers anterior a versión 4.0.0 es vulnerable a ejecución de código en el host mediante anotaciones de configuración sin validar. Un atacante puede especificar una ruta TOML arbitraria a través de la anotación io.katacontainers.config_path para cargar archivos maliciosos del host. Esta vulnerabilidad afecta infraestructuras containerizadas en datacenters y plataformas cloud de empresas LATAM que ejecuten orquestación con Kubernetes.
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-61808] LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRA…
LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all network interfaces with authentication disabled by default, allowing an unauthenticated network attacker to read indexed document content, upload or delete documents, modify the knowledge graph, cancel pipelines, clear caches, and consume LLM resources. This issue is mitiga…
M Alto vulnerabilidad
07/08/2026
[CVE-2026-62295] HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in J…
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the JSON utility parser in org.hl7.fhir.utilities.json.parser.JsonParser enforces no maximum nesting depth for arrays or objects. As a result, a small but deeply nested, syntactically valid FHIR JSON document can trigger unbounded readArray() or readObject() recursion, raising …
M Alto vulnerabilidad
07/08/2026
[CVE-2026-62296] HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in J…
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, XhtmlParser.java imposes no maximum element nesting depth, so a deeply nested text.div narrative triggers unbounded recursion between parseElementInner() and parseElement(), raising a StackOverflowError. An attacker who can submit FHIR resources containing such narratives can t…
M Alto vulnerabilidad
07/08/2026
Vulnerabilidad alta en gopacket permite denegación de servicio remota en aplicaciones Go
gopacket versión 1.7.0 y anteriores contiene múltiples decodificadores de capas que procesan longitudes, conteos u offsets controlados por el atacante sin validar contra los búferes de paquetes, permitiendo panic remoto. Aplicaciones que utilizan DecodingLayerParser o DecodeFromBytes en infraestructuras de análisis de tráfico, cortafuegos o sistemas de detección de intrusiones en LATAM son susceptibles a denegación de servicio remota.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-48039] Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to…
Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispatch()` at `http_auth_integration.py:272` unconditionally forwards unauthenticated Streamable HTTP requests to downstream MCP tool handlers without issuing a `401` response, allowing any network-reachable caller to invoke MCP tools without authenticatio…
M Alto vulnerabilidad
07/08/2026
[CVE-2026-15972] Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthentic…
Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of service through unbounded connection acceptance on the external gRPC listeners. A remote attacker may exhaust agent file descriptors, goroutines, and memory by opening many incomplete connections, potentially preventing legitimate clients from connecting. This vulnerability, CVE-2026-…
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-71851] crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate…
crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry pseudorandom number generator, seeded from Math.random(), instead of a cryptographically secure source. This generator was introduced in version 3.1.2-4 and remained present in nearly every 3.x release…
M Alto vulnerabilidad
07/08/2026
[CVE-2026-48097] NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a use…
NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 have a command execution vulnerability due to unsafe use of `shell=True` with commands that rely on executable resolution through the `PATH` environment variable. An attacker controlling the execution environment can place malicious executables such as sudo ea…
M Alto vulnerabilidad
07/08/2026
[CVE-2026-48098] NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a use…
NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 execute privileged system commands using `sudo` and `shell=True` directly inside application logic. In environments where passwordless sudo (`NOPASSWD`) is enabled, privileged commands may execute silently without explicit user confirmation. Version 2.0.0 fixe…
M Alto vulnerabilidad
07/08/2026
[CVE-2026-19231] A security flaw has been discovered in SourceCodester Simple Doctors Appointment System 1.0. This vu…
A security flaw has been discovered in SourceCodester Simple Doctors Appointment System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=delete_appointment. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
M Alto vulnerabilidad
07/08/2026
[CVE-2025-71412] Injection of false emergency or status messages over CPDLC may lead to misallocation of resources, o…
Injection of false emergency or status messages over CPDLC may lead to misallocation of resources, operational confusion, and improper response actions by flight crews, traffic controllers, and ground operations. This type of attack can be carried out remotely over radio frequency.
M Alto vulnerabilidad
07/08/2026
[CVE-2026-11430] Grav CMS's scheduler-webhook plugin contains an authentication bypass in the webhook token check. Wh…
Grav CMS's scheduler-webhook plugin contains an authentication bypass in the webhook token check. When the webhook feature is enabled but no webhookToken is configured, a compound conditional short-circuits and skips token validation, so an unauthenticated remote attacker who can reach POST /scheduler/webhook can trigger the operator's already-configured scheduled jobs by sending a single request.…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
07/08/2026
[CVE-2025-63235] In sol commit 373d848 (2024-12-12), the broker does not fully release resources when handling malfor…
In sol commit 373d848 (2024-12-12), the broker does not fully release resources when handling malformed or duplicate CONNECT packets. When clients send invalid CONNECT packets - either due to repeated attempts or failed authentication - the server may silently drop the connection or send a CONNACK but fail to close the session or deallocate internal resources. This behavior allows an attacker to c…
M Alto vulnerabilidad
07/08/2026
[CVE-2025-71409] Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to in…
Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages leading to unexpected or misleading clearances and potential pilot confusion. This type of attack can be carried out remotely over radio frequency.
M Alto vulnerabilidad
07/08/2026
[CVE-2026-64636] An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authe…
An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the panel database.
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-64637] Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated re…
Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.
M Alto vulnerabilidad
07/08/2026
[CVE-2026-19082] Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-…
Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags. copy_string_tags() computes an ASCII EXIF tag's length as `entry->size - 1` to strip the trailing NUL. A zero-count ASCII entry sets `entry->size` to 0, and the derived length reaches i_tags_add() as -1, which is interpreted as a request …