Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1003
Esta semana
RSS
M Alto vulnerabilidad
Hace 4 días
Vulnerabilidad SSRF alta en ChatGPTNextWeb NextChat hasta versión 2.16.1
Se ha identificado una vulnerabilidad de Server-Side Request Forgery (SSRF) en ChatGPTNextWeb NextChat versiones hasta 2.16.1, ubicada en la función proxyHandler del componente Proxy Fallback Handler (app/api/proxy.ts). Un atacante remoto puede manipular el argumento x-base-url para ejecutar solicitudes HTTP arbitrarias desde el servidor afectado, potencialmente comprometiendo datos internos, accediendo a servicios de red privados o saltando controles de seguridad perimetral. La explotación es remota y código de prueba ya está disponible públicamente.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105148] A vulnerability was identified in SciPhi-AI R2R up to 3.6.6. This vulnerability affects unknown code…
A vulnerability was identified in SciPhi-AI R2R up to 3.6.6. This vulnerability affects unknown code of the file py/shared/abstractions/llm.py of the component Retrieval Completion API Endpoint. Such manipulation of the argument generation_config.api_base leads to server-side request forgery. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was c…
M Alto vulnerabilidad
02/10/2026
[CVE-2026-82044] UTMStack before 11.2.16 contains a server-side request forgery vulnerability that allows authenticat…
UTMStack before 11.2.16 contains a server-side request forgery vulnerability that allows authenticated attackers to make the server request arbitrary internal resources by supplying an unvalidated url parameter to the PdfService.downloadPdf() method exposed via GET /api/generate-pdf-report. Attackers can leverage this to force the web-pdf microservice to fetch internal backend endpoints, the OpenS…
M Alto vulnerabilidad
02/10/2026
[CVE-2026-103958] Server-side request forgery in the tool server and remote agent connection handling in Loom for AWS …
Server-side request forgery in the tool server and remote agent connection handling in Loom for AWS before 1.7.0 might allow an authenticated remote user to obtain the credentials of the application's own container role and to read responses from arbitrary internal network locations, via a crafted connection address supplied when registering, updating or testing a tool server or remote agent. T…
M Alto vulnerabilidad
02/10/2026
[CVE-2020-37278] Weaver e-Bridge contains an unauthenticated arbitrary file read vulnerability that allows remote att…
Weaver e-Bridge contains an unauthenticated arbitrary file read vulnerability that allows remote attackers to access arbitrary files on the host system by supplying a file: URL to the downloadUrl parameter of the saveYZJFile endpoint. Attackers can exploit this flaw to read sensitive files such as /etc/passwd or configuration and credential files, and the same endpoint's support for http(s) URLs a…
M Alto vulnerabilidad
02/10/2026
Vulnerabilidad SSRF alta en YesWiki anterior a 4.6.7 permite ataques no autenticados
YesWiki versiones anteriores a 4.6.7 contiene una vulnerabilidad de falsificación de solicitud del lado del servidor (SSRF) que permite a atacantes no autenticados ejecutar solicitudes HTTP a hosts internos y servicios de metadatos en la nube. Los atacantes explotan la ruta pública del buzón de actores de formularios, firmando actividades con sus propias claves mientras inyectan URLs de infraestructura interna en el cuerpo de la solicitud. Esto representa riesgo significativo para wikis corporativas y portales internos en LATAM que expongan esta aplicación a internet.
M Alto vulnerabilidad
02/10/2026
Vulnerabilidad SSRF alta en YesWiki anterior a 4.6.7 permite acceso no autenticado
YesWiki versiones anteriores a 4.6.7 contiene una vulnerabilidad de Server-Side Request Forgery (SSRF) que permite a atacantes no autenticados realizar solicitudes GET desde el servidor afectado. La falla se encuentra en la acción de sincronización de suscripciones de Bazar, donde URLs de actor no validadas permiten dirigir solicitudes a hosts internos, endpoints de metadatos en la nube y almacenar respuestas como entradas Bazar accesibles. Empresas en LATAM que alojan YesWiki (wiki colaborativas, portales de contenido comunitario) enfrentan riesgo de exposición de datos internos, credenciales en metadatos AWS/Azure y movimiento lateral en redes corporativas.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
02/10/2026
[CVE-2026-104120] A security vulnerability has been detected in modelcontextprotocol mcp-server-fetch and mcp-server-e…
A security vulnerability has been detected in modelcontextprotocol mcp-server-fetch and mcp-server-everything up to 2026.6.4. Affected is the function fetch_url of the file mcp_server_fetch/server.py of the component Fetch Tool. The manipulation of the argument url/path leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed publicly and may be us…
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-56660] GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of…
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler in UpdateCE.php downloads a ZIP archive and extracts its contents into the web root without validating file types or extraction paths. Because PHP files are written into a web-accessible directory, an attacker who can cause a malicious archive to b…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-56661] GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of…
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler fetches a user-supplied URL with file_get_contents() after only format validation (FILTER_VALIDATE_URL) — there is no validation of the request destination. An attacker who can submit the form can make the server issue requests to arbitrary destina…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-55232] Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stor…
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, Vvveb's SSRF guard resolves a host with an IPv4-only function and never inspects IPv6, so any host that lacks an A record passes a private-range check. Editor oEmbed proxy fetches an attacker-supplied URL server side and reflects a response body, so an authenticated adm…
M Alto vulnerabilidad
01/10/2026
Vulnerabilidad SSRF alta en Budibase 3.41.0 afecta generación de tablas con IA
Budibase versiones hasta 3.41.0 contiene una vulnerabilidad de Server-Side Request Forgery (SSRF) en la función de generación de tablas con IA. Usuarios autenticados pueden explotar la función uploadUrl en fileUtils.ts para enviar solicitudes a URLs internas, obteniendo acceso a recursos sensibles del servidor. El impacto afecta especialmente a empresas en LATAM que usan Budibase en entornos productivos sin aislamiento de red adecuado.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-103082] Server-Side Request Forgery (SSRF) vulnerability in LA-Studio LA-Studio Element Kit for Elementor la…
Server-Side Request Forgery (SSRF) vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Server Side Request Forgery.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.6.2.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-103530] A vulnerability was detected in decolua 9Router up to 0.5.55. The affected element is the function f…
A vulnerability was detected in decolua 9Router up to 0.5.55. The affected element is the function fetch of the file src/shared/utils/ssrfGuard.js of the component Search Endpoint. Performing a manipulation of the argument provider_options.baseUrl results in server-side request forgery. The attack can be initiated remotely. Applying a patch is the recommended action to fix this issue.
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-102102] Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery…
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise unintended network destinations. The requests are triggered while the gateway retrieves…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-102103] Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery…
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise unintended network destinations. The requests are triggered while the gateway retrieves…
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-102104] Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery…
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise unintended network destinations. The requests are triggered while the gateway performs …
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-102105] Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery…
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise unintended network destinations. The requests are triggered while the gateway renders m…
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-102095] Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery…
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery. Kiteworks Email Protection Gateway performed server-side fetches of URLs contained in the message content it processed, without adequately restricting the fetch destination. A remote, unauthenticated sender could craft a message that caused the gateway to issue requests to internal services and cl…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102091] Kiteworks Secure Data Forms before version 9.5.0 is vulnerable to Server-Side Request Forgery that c…
Kiteworks Secure Data Forms before version 9.5.0 is vulnerable to Server-Side Request Forgery that could allow an unauthenticated, remote attacker to make the server issue arbitrary outbound network requests and read back the responses. This could potentially be used to reach internal-only services or other network-restricted resources.