Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1023
Esta semana
RSS
M Alto vulnerabilidad
10/09/2026
[CVE-2026-89043] passport-saml-encrypted through 0.1.13 contains an XML signature wrapping vulnerability where signat…
passport-saml-encrypted through 0.1.13 contains an XML signature wrapping vulnerability where signature verification and assertion extraction use independent XPath lookups with no cross-validation. Attackers holding any validly signed SAML message can prepend a forged unsigned assertion that gets accepted as the verified identity while the genuine signature validates against the original assertion…
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-89042] passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional …
passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can post forged SAML responses with arbitrary NameID and attributes to the assertion consumer service endpoint to receive authenticated profiles without valid signatures.
M Alto vulnerabilidad
09/09/2026
[CVE-2023-54355] PocketMine-MP versions before 5.3.1 and 4.23.1 fail to validate that the identityPublicKey in LoginP…
PocketMine-MP versions before 5.3.1 and 4.23.1 fail to validate that the identityPublicKey in LoginPacket uses the required secp384r1 elliptic curve. Attackers can provide LoginPackets with keys using different curves or non-EC key types to pass login verification but trigger an uncaught exception during ECDH key derivation, crashing the server.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69646] Improper verification of cryptographic signature in Skype for Business allows an unauthorized attack…
Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-57098] Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized attack…
Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized attacker to disclose information over a network.
M Alto vulnerabilidad
07/09/2026
Vulnerabilidad en MCUboot y estrategia Direct XIP permite ejecución no autorizada en núcleos secundarios
MCUboot en configuración base no verifica adecuadamente la integridad de imágenes al usar la estrategia Direct XIP, permitiendo que la imagen principal inicie núcleos secundarios (radio, etc.) desde slots sin validar. Esto afecta sistemas embebidos y dispositivos IoT en operaciones altas de LATAM, especialmente en telecomunicaciones e industria.
M Alto vulnerabilidad
05/09/2026
[CVE-2026-52767] YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, HttpSignatureSe…
YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, HttpSignatureService::verifySignature() checks the result of PHP's openssl_verify() with a loose boolean negation - if (!openssl_verify(...)) { throw ... }. PHP's openssl_verify has four possible return values: 1, 0, -1, and "false". The -1 row is the bypass: PHP's truthiness rules make -1 a truthy value, so !(-1)…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85525] Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a r…
Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a revoked TLS certificate to be accepted as valid, because OCSP responses were not reliably bound to the certificate being validated and definitive verification failures were treated as transient. A man-in-the-middle attacker holding a revoked certificate and its private key for a Snowflake or stage ho…
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-80098] Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker t…
Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85393] node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during …
node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage bytes inside the DigestAlgorithm sequence to forge valid signatures for arbitrary messages using low-exponent RSA keys. This is an incomplete fix for CVE-2026-33894.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85394] python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepti…
python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's public key can forge HS256 tokens that pass verification when algorithms are not explicitly restricted. This is an incomplete fix for CVE-2024-33663.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-80465] A vulnerability has been identified in Mendix SAML (Mendix 10 compatible) (All versions < V4.2.3), M…
A vulnerability has been identified in Mendix SAML (Mendix 10 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 11 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 9.24 compatible) (All versions < V3.6.27). Affected versions of the module do not properly validate the SAML response signature. This could allow unauthenticated remote attackers to hijack an account (session) in specific…
M Alto vulnerabilidad
31/08/2026
Vulnerabilidad alta en controlador Phison PS3111-S11 permite falsificación de firmware
El controlador de almacenamiento Phison PS3111-S11 valida firmas RSA utilizando claves públicas embebidas en la imagen del firmware en lugar de almacenamiento inmutable, permitiendo a atacantes generar pares de claves RSA arbitrarios y firmar firmware modificado que el controlador acepta como legítimo. Esta vulnerabilidad afecta directamente a servidores, sistemas de backup y centros de datos en LATAM que utilizan almacenamiento basado en estos controladores, comprometiendo la integridad del firmware de dispositivos de almacenamiento altas.
M Alto vulnerabilidad
30/08/2026
[CVE-2026-82645] AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/vie…
AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint. Supplying a 'token' request parameter waives both the Live::canRestream() access gate and the restream ownership check, causing the endpoint to return any restream's stream_key and stream_url (credentials for external platforms such as YouTube, Facebook…
M Alto vulnerabilidad
29/08/2026
Vulnerabilidad alta en pac4j-oidc: falla en validación de tokens de acceso
pac4j-oidc anterior a versión 6.5.6 no valida correctamente firmas de tokens de acceso, emisores, audiencias ni expiración al extraer roles de Keycloak. Atacantes pueden falsificar tokens con roles administrativos combinados con tokens ID válidos para eludir controles de autorización en aplicaciones que dependen de validación de roles en pac4j. Afecta directamente sistemas de identidad y control de acceso en infraestructuras empresariales de México y LATAM que implementen esta librería.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
29/08/2026
[CVE-2026-82454] The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass i…
The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification. The decodeAppleToken function extracted the 'alg' field from the attacker-supplied JWT header and passed it as the sole allowed algorithm to jwt.verify(). Using jsonwebtoken v8 (which does not validate key/algorithm compatibility), an attacker can set alg=HS256 an…
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-76581] The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions u…
The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. This is due to inconsistent and ambiguous HMAC message construction between the unauthenticated `wdpsso_step1` and `wdpsso_step2` AJAX actions, where step 1 signs and discloses an unseparated concatenation of the token, state, redirect, and domain values, while step 2 ver…
M Alto vulnerabilidad
28/08/2026
[CVE-2026-54330] Ceph is an open-source distributed storage platform providing object, block, and file storage. In ve…
Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Ceph Object Gateway (RGW) SigV4 handler does not reject requests that carry x-amz-* headers absent from the signed header set, allowing anyone holding a presigned URL to attach arbitrary unsigned x-amz-* headers that RGW will honor. AWS S3 requires every x-amz-…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-81714] openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fingerprint matching in…
openssl_encrypt (pip: openssl-encrypt) versions
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-81700] openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.v…
openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that accepts revoked and expired keys by only checking VALIDSIG status without inspecting REVKEYSIG, EXPKEYSIG, or gpg exit codes. Attackers holding compromised-then-revoked signing keys or expired project keys can bypass signature verification to execute malicious plugins in the host…