Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "OpenSSL" — 82 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
17/08/2026
Vulnerabilidad alta de path traversal en openssl_encrypt anteriores a v1.4.0
openssl_encrypt versiones anteriores a 1.4.0 contienen una vulnerabilidad de path traversal (CVE-2026-74884, CVSS 7.5) en el método _is_safe_path que no sanitiza el parámetro plugin_id, permitiendo a atacantes acceder a directorios arbitrarios fuera del directorio de plugins mediante secuencias como '../'. Empresas en México y LATAM que usen este componente en aplicaciones web o sistemas de gestión de contenido enfrentan riesgo de exposición de información sensible y potencial ejecución de código.
M Crítico vulnerabilidad
17/08/2026
Vulnerabilidad crítica en openssl_encrypt: elusión de sandbox permite ejecución arbitraria de código
Versiones anteriores a 1.4.0 de openssl_encrypt contienen una vulnerabilidad que permite eludir el análisis de seguridad mediante ofuscación de strings, habilitando la importación de módulos peligrosos (sys, shutil, pickle, importlib) para ejecución de código arbitrario. Afecta sistemas de cifrado y aplicaciones que procesan datos sensibles en servidores de LATAM. El CVSS 9.8 indica riesgo crítico con impacto potencial en infraestructuras financieras y gubernamentales.
M Alto vulnerabilidad
17/08/2026
Vulnerabilidad alta en openssl_encrypt: derivación de claves débil permite cracking de contraseñas (CVE-2026-74888)
openssl_encrypt versiones anteriores a 1.4.0 implementan una construcción PBKDF2 no estándar con iteraciones=1 por llamada, debilitando significativamente la derivación de claves. Atacantes pueden comprometer archivos cifrados legacy con esfuerzo computacional reducido. Afecta sistemas que protegen datos financieros, médicos y personales en empresas mexicanas y latinoamericanas que usan esta librería para cifrado de datos en reposo.
M Crítico vulnerabilidad
17/08/2026
Vulnerabilidad crítica en openssl_encrypt anterior a v1.4.0 debilita derivación de claves criptográficas
Las versiones de openssl_encrypt anteriores a 1.4.0 implementan HKDF sin salt y parámetros estáticos en funciones de normalización de claves, reduciendo la entropía en la extracción criptográfica. Atacantes pueden explotar la derivación predecible de claves para comprometer la seguridad en ataques multi-objetivo contra sistemas que procesen transacciones financieras, datos de autenticación o comunicaciones sensibles en empresas mexicanas y latinoamericanas.
M Crítico vulnerabilidad
17/08/2026
Vulnerabilidad crítica en openssl_encrypt anteriores a 1.4.0 permite filtración de secretos
openssl_encrypt en versiones anteriores a 1.4.0 contiene una vulnerabilidad (CVSS 9.8) en la función PublicKeyBundle.from_dict() que procesa datos no verificados sin validar firmas criptográficas. Un atacante puede manipular bundles de claves públicas para cifrar datos con claves controladas por el atacante, exponiendo información sensible en bases de datos, sistemas de pago y plataformas cloud comúnmente utilizadas en LATAM.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-74877] openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the …
openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the revoke_key method that allows authenticated clients to revoke any other client's key. Attackers can revoke arbitrary keys by providing a valid ML-DSA signature, bypassing the intended ownership restriction.
M Crítico vulnerabilidad
17/08/2026
[CVE-2026-74878] openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection …
openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared across workers and is lost on server restart. Attackers can distribute authentication attempts across multiple server instances or retry immediately after a restart to bypass rate limiting protections.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
17/08/2026
[CVE-2026-74879] openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready …
openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready endpoint that returns full database exception strings to unauthenticated callers. Attackers can trigger database errors to extract sensitive information including hostnames, IP addresses, connection parameters, and potentially credentials from exception messages.
M Crítico vulnerabilidad
17/08/2026
[CVE-2026-74880] openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and…
openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server routes. Attackers can extract tokens from server logs, proxy logs, browser history, and HTTP Referer headers to gain unauthorized access.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-74882] openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the enti…
openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the entire RFC 1918 private address space in IntegrityProxyConfig trusted_proxies. Attackers on private networks can forge client certificate headers to bypass mTLS authentication when ProxyAuth validation is relaxed or modified.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-74883] openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbo…
openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbox fails to restrict alternative file access methods like pathlib.Path and io.open. Attackers can import pathlib or io modules to read and write arbitrary files, completely bypassing the restricted_open file access controls.
M Crítico vulnerabilidad
17/08/2026
[CVE-2026-74872] openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirl…
openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob patterns to load .so modules without integrity verification. Attackers can place malicious .so files matching the whirlpool*py313*.so pattern in site-packages directories to achieve native code execution when the module is loaded.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-74874] openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random module for steganographi…
openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random module for steganographic pixel selection in the generate_pseudorandom_sequence function. Attackers who know the password can recover the Mersenne Twister state from approximately 624 outputs and predict pixel locations containing hidden data for extraction.
M Crítico vulnerabilidad
17/08/2026
[CVE-2026-74875] openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema libra…
openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed, allowing malformed metadata to be accepted. Attackers can remove the jsonschema package or supply unknown metadata format versions to bypass all schema checks and process malicious data.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-70454] rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS ce…
rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to intercept encrypted sessions by presenting self-signed or otherwise invalid certificates. Attackers can exploit the failure to validate server TLS certificates against a trusted CA or verify certificate hostname matching to decrypt …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
13/08/2026
[CVE-2026-14456] Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packet…
Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit. Impact summary: A remote peer that can make many Initial packets reach the server listener faster than the application accepts connections, can cause the memory allocated to store …
M Alto vulnerabilidad
03/08/2026
[CVE-2026-41447] FirmaCheck for Windows before 1.3.16 contains a dll hijacking vulnerability that allows local attack…
FirmaCheck for Windows before 1.3.16 contains a dll hijacking vulnerability that allows local attackers to execute arbitrary code by placing a crafted openssl.cnf file in the unvalidated C:\Program Files (x86)\Common Files\SSL\ directory path. Attackers can write a malicious OpenSSL configuration file referencing an attacker-controlled DLL to achieve code execution at startup process privilege lev…
M Crítico vulnerabilidad
01/08/2026
[CVE-2026-66402] FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity valid…
FreeRDP before 3.29.0 (affected versions
L Alto vulnerabilidad
24/07/2026
[CVE-2026-66033] libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vul…
libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM ciphers during handshake. Attackers can exploit the underflow in the expression computing blocksize minus aadlen minus authentication tag length to…
M Crítico vulnerabilidad
23/07/2026
[CVE-2026-15981] The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in a…
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's openssl_verify(), causing an error return value of -1 to be evaluated as truthy and therefore treated as a successful sign…