Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1012
Esta semana
RSS
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-82855] @hulumi/policies versions before 1.3.2 contain an evidence validation bypass vulnerability in Cloudf…
@hulumi/policies versions before 1.3.2 contain an evidence validation bypass vulnerability in Cloudflare and deployment-governance validators that allows attackers to suppress violations by submitting unrelated compliant evidence. Attackers can use evidence from different zones, hostnames, origins, or repositories to bypass security guardrails for unrelated resources in the same stack.
M Alto vulnerabilidad
29/08/2026
Vulnerabilidad alta en Sudo permite eludir controles de política en llamadas execveat
Sudo versiones hasta 1.9.17p2 no aplica verificaciones de política de intercepción a la llamada del sistema execveat en modo ptrace, permitiendo a usuarios autorizados ejecutar programas prohibidos mediante execveat o fexecve. Esta evasión compromete la aplicación de políticas y el registro de auditoría en servidores Linux/Unix altas en LATAM donde Sudo gestiona privilegios administrativos.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-61792] Weblate is a web-based continuous localization platform used to manage software translations. In ver…
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a project administrator can read files outside their repository through the App store metadata download feature, which resolves attacker-influenced paths without adequately confining them to the repository. This is an incomplete fix for CVE-2026-34242, whose original patch fai…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-80198] Kimai versions before 2.56.0 fail to restrict the config() Twig function in sandboxed invoice and ex…
Kimai versions before 2.56.0 fail to restrict the config() Twig function in sandboxed invoice and export templates, allowing administrators to access arbitrary configuration keys. Attackers with admin privileges can upload malicious templates to exfiltrate server-wide secrets including LDAP bind passwords and SAML private keys into invoice or export documents accessible to lower-privileged users.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-43670] A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts. T…
A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5. Processing maliciously crafted web content may bypass Content Security Policy.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-79774] Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig sandbox escape vulnerability …
Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig sandbox escape vulnerability in System\\Twig\\SecurityPolicy that allows authenticated backend users with template-editing permissions to bypass sandbox restrictions. Attackers can exploit method forwarding through Eloquent models and query builders using methods like saveQuietly(), deleteQuietly(), increment(), decrement(), an…
M Alto vulnerabilidad
18/08/2026
[CVE-2026-45733] Trilium Notes is a cross-platform, hierarchical note taking application focused on building large pe…
Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.103.0, the #iconClass label value is returned raw by getNoteIcon() and inserted without HTML attribute encoding into class attributes in apps/client/src/widgets/quick_search.ts and apps/client/src/services/note_autocomplete.ts, allowing a stored payload to execute …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
18/08/2026
[CVE-2026-75874] Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 …
Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154.
M Crítico vulnerabilidad
18/08/2026
[CVE-2026-74938] Mitigation bypass in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Fire…
Mitigation bypass in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
M Crítico vulnerabilidad
17/08/2026
[CVE-2026-47686] vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, handleException() in lib/setup-sandbo…
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, handleException() in lib/setup-sandbox.js sanitizes SuppressedError.error, SuppressedError.suppressed, and AggregateError.errors but does not sanitize Error.cause, allowing sandbox code to obtain a powerful host object such as process from an embedder-exposed host function that throws an error with that object as its cause and then exe…
M Crítico vulnerabilidad
17/08/2026
Vulnerabilidad crítica en openssl_encrypt: ejecución de plugins sin restricciones de sandbox
Las versiones de openssl_encrypt anteriores a 1.4.0 no aplican restricciones de aislamiento en la ejecución de plugins, permitiendo a atacantes acceder sin límites al sistema de archivos, red, subprocesos y módulos Python. Esta vulnerabilidad afecta directamente a servidores en LATAM que procesan encriptación y ejecutan plugins dinámicos, comprometiendo la confidencialidad e integridad de datos sensibles.
M Crítico vulnerabilidad
17/08/2026
Vulnerabilidad crítica en openssl_encrypt permite evasión de sandbox y ejecución de comandos
Versiones anteriores a 1.4.0 de openssl_encrypt contienen una vulnerabilidad de evasión de sandbox (CVSS 9.8) en el analizador AST DangerousPatternVisitor que no detecta técnicas de traversal de atributos dunder (__class__, __bases__, __subclasses__(), __globals__). Atacantes pueden ejecutar comandos arbitrarios desde código de plugins, comprometiendo servidores en México y Latinoamérica que dependan de esta librería para cifrado y procesamiento de datos sensibles.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-74883] openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbo…
openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbox fails to restrict alternative file access methods like pathlib.Path and io.open. Attackers can import pathlib or io modules to read and write arbitrary files, completely bypassing the restricted_open file access controls.
M Crítico vulnerabilidad
16/08/2026
[CVE-2026-74790] Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter change…
Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to expose members that should be hidden. Attackers can access filtered properties and fields by reusing a TemplateContext after tightening its MemberFilter, bypassing sandbox policies across requests or tenants.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-18428] A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allo…
A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenticated actor with async query access to execute arbitrary code on Apache Spark workers by sending a crafted SQL query to the direct query endpoint.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
11/08/2026
[CVE-2026-69278] Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security f…
Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-54981] Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension al…
Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a security feature locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72781] Craft CMS versions >= 5.0.0-RC1 before 5.10.7 and >= 4.0.0-RC1 before 4.18.3 contain a remote code e…
Craft CMS versions >= 5.0.0-RC1 before 5.10.7 and >= 4.0.0-RC1 before 4.18.3 contain a remote code execution vulnerability in the Twig sandbox mechanism. Because Craft marks the ElementInterface as safe (via the AllowedInSandbox attribute) and the sandbox allowlisting extends to the entire class hierarchy (craft\base\Component up to yii\base\Component), an authenticated attacker with permission to…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-19168] Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacke…
Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
06/08/2026
[CVE-2026-19150] Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacke…
Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)