Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
Buscando: "Multiple Vendors" — 16643 resultados ✕ Limpiar búsqueda
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1002
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Hace 6 horas
[CVE-2026-108159] AstronRPA through 1.1.6 contains a cross-site scripting vulnerability in the desktop client's smart-…
AstronRPA through 1.1.6 contains a cross-site scripting vulnerability in the desktop client's smart-component chat that allows remote attackers to execute OS commands by abusing unsanitized LLM output rendered via v-html. Attackers can embed prompt-injection content in a web page so the model emits HTML event handlers invoking the unrestricted open-path IPC handler with shell metacharacters, execu…
M Alto vulnerabilidad Nuevo
Hace 6 horas
[CVE-2026-108160] AstronRPA through 1.1.6 contains a download of code without integrity check vulnerability that allow…
AstronRPA through 1.1.6 contains a download of code without integrity check vulnerability that allows network attackers to deliver malicious updates by abusing the desktop client's auto-update mechanism. Attackers positioned between the client and server can serve a malicious update manifest and NSIS installer, which electron-updater installs without signature verification, executing code as the d…
M Alto vulnerabilidad Nuevo
Hace 6 horas
[CVE-2026-55797] Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 2.11.0 until 3.3.15, …
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 2.11.0 until 3.3.15, 3.4.10, 3.5.4, and 3.6.0-rc2, the Argo CD repo-server is vulnerable to command injection when it clones, tests, or fetches an SSH Git repository configured with a proxy URL. The proxy host and port are embedded in an SSH ProxyCommand that is executed through a shell without neutralizing shell metach…
M Alto vulnerabilidad Nuevo
Hace 6 horas
[CVE-2026-108156] LobsterAI 2026.5.27 through 2026.9.23 contains an external control of file path vulnerability in the…
LobsterAI 2026.5.27 through 2026.9.23 contains an external control of file path vulnerability in the skills:delete IPC handler that trusts the openclawSourceDir value from a skill's _meta.json during uninstall. Attackers who convince a user to install a crafted skill can make uninstallation recursively delete arbitrary user-writable directories, such as the home directory, since the security scann…
M Alto vulnerabilidad Nuevo
Hace 6 horas
[CVE-2026-108157] Pingvin Share X from 0.19.0 before 1.22.0 contains an improper authentication vulnerability that all…
Pingvin Share X from 0.19.0 before 1.22.0 contains an improper authentication vulnerability that allows remote unauthenticated attackers to take over accounts by abusing automatic OAuth email linking in OAuthService.signUp(). Attackers can register a victim's unverified email on an enabled OAuth/OIDC provider, exploiting the missing email_verified check in GenericOidcProvider, to sign in as the vi…
M Alto vulnerabilidad Nuevo
Hace 6 horas
[CVE-2026-107815] MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 1…
MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the CONNECT engine's DOS table type used an incorrect boundary check that permitted a one-byte null write beyond a stack buffer at an attacker-controlled offset. An authenticated user able to use the CONNECT engine could cause a crash and potentially remote code e…
M Alto vulnerabilidad Nuevo
Hace 7 horas
[CVE-2026-90983] Use of Client-Side authentication vulnerability in Hayat Health Facilities Inc. (Hayat Hospital) Hay…
Use of Client-Side authentication vulnerability in Hayat Health Facilities Inc. (Hayat Hospital) Hayat Mobile allows Authentication Bypass. This issue affects Hayat Mobile: from 3.3.0 before 3.4.0.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad Nuevo
Hace 7 horas
[CVE-2026-75345] OpENer v2.3.0 / commit 76b95cf contains an out-of-bounds read in the unconnected explicit messaging …
OpENer v2.3.0 / commit 76b95cf contains an out-of-bounds read in the unconnected explicit messaging path. This allows a remote attacker to cause a denial of service.
M Alto vulnerabilidad Nuevo
Hace 7 horas
[CVE-2026-75348] An out-of-bounds read vulnerability exists in EIPStackGroup OpENer v2.3 and master up to commit 76b9…
An out-of-bounds read vulnerability exists in EIPStackGroup OpENer v2.3 and master up to commit 76b95cf in the EtherNet/IP TCP SendRRData Common Packet Format parser. The issue occurs in CreateCommonPacketFormatStructure() when it parses recognized optional socket address information items of type 0x8000 or 0x8001 without first validating that the remaining CPF buffer contains the complete fixed s…
M Alto vulnerabilidad Nuevo
Hace 7 horas
[CVE-2026-75349] EIPStackGroup OpENer v2.3.0/master up to commit 76b95cf contains an out-of-bounds read vulnerability…
EIPStackGroup OpENer v2.3.0/master up to commit 76b95cf contains an out-of-bounds read vulnerability in Connection Manager request parsing. This allows a remote attacker to cause a denial of service.
M Alto vulnerabilidad Nuevo
Hace 7 horas
[CVE-2026-75346] An out-of-bounds read vulnerability exists in EIPStackGroup OpENer v2.3 and master through commit 76…
An out-of-bounds read vulnerability exists in EIPStackGroup OpENer v2.3 and master through commit 76b95cf in the server-side CIP SetAttributeList service. This allows a remote attacker to cause a denial of service
M Alto vulnerabilidad Nuevo
Hace 7 horas
[CVE-2026-107813] Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, the api/cluster r…
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, the api/cluster router exposes node and namespace mutation operations and cluster-wide Nginx reload or restart operations with AuthRequired but without RequireSecureSession. An authenticated OTP-enabled user possessing a stolen or persisted JWT can therefore perform node CRUD, read or replace node credentials, chang…
M Alto vulnerabilidad Nuevo
Hace 7 horas
[CVE-2026-107814] MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 1…
MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, MariaDB RPM packages created the dedicated mysql service account with the database data directory as its home directory. A database user with the FILE privilege could write startup dot-files such as .bash_profile into $HOME, and those files could execute when an a…
M Alto vulnerabilidad Nuevo
Hace 7 horas
[CVE-2026-108113] ILIAS before 9.24, 10.12, and 11.5 contains an unrestricted file upload vulnerability in QTI questio…
ILIAS before 9.24, 10.12, and 11.5 contains an unrestricted file upload vulnerability in QTI question import image handling (ilQtiMatImageSecurity) that allows authenticated authors to write executable files. Attackers with question pool import rights can import a crafted archive writing a .htaccess and PHP file to the web-served image directory, achieving remote code execution as the web server u…
M Alto vulnerabilidad Nuevo
Hace 7 horas
[CVE-2026-107807] Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, Nginx UI accepts …
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, Nginx UI accepts the Node.Secret master credential through the node_secret query parameter in HTTP and WebSocket authentication paths instead of requiring the X-Node-Secret header. The credential can consequently appear in access logs, proxy logs, browser history, Referer headers, configuration URLs, and deployment …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad Nuevo
Hace 7 horas
[CVE-2026-107808] Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, POST /api/login c…
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, POST /api/login checks EnabledOTP but does not require a WebAuthn assertion when EnabledPasskey is true and no TOTP secret is configured. A passkey-only account is therefore issued a session after password verification, despite Enabled2FA reporting that the account has a second factor. An attacker who obtains the pa…
M Alto vulnerabilidad Nuevo
Hace 7 horas
[CVE-2026-107809] Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, AuthRequired acce…
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, AuthRequired accepts a browser-managed token cookie as an API credential after the front end stores the JWT in that cookie. Because management endpoints do not universally require a CSRF token or perform Origin or Referer validation, a remote attacker can induce a logged-in administrator's browser to submit authenti…
M Alto vulnerabilidad Nuevo
Hace 7 horas
[CVE-2026-107810] Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, internal/backup/r…
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, internal/backup/restore.go extracts inner archives before applying the restore_nginx and restore_nginx_ui flags and permits symlinks targeting the live Nginx configuration path. An authenticated user who can create and restore backups can craft a valid backup that places a symlink in the staging tree and then writes…
M Alto vulnerabilidad Nuevo
Hace 7 horas
[CVE-2026-107811] Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, ordinary authenti…
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, ordinary authenticated users can access /api/nodes and /api/nodes/:id, whose responses serialize the node token field. The same token is accepted as X-Node-Secret by AuthRequired and maps the request to initUser, allowing the user to impersonate a trusted node against a reachable cluster member. This cross-node auth…
M Alto vulnerabilidad Nuevo
Hace 7 horas
[CVE-2026-107812] Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, the self-upgrade …
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, the self-upgrade mechanism validates a downloaded binary only with a same-origin digest obtained from the same upgrade mirror. A compromised mirror or network attacker able to alter both responses can supply a malicious executable and matching digest. An operator-triggered upgrade is required, and the application in…