Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 39 min
Buscando: "Ni" — 7263 resultados ✕ Limpiar búsqueda
22,340
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1210
Esta semana
RSS
M Alto vulnerabilidad
12/06/2026
[CVE-2026-6961] Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mat…
Mattermost versions 11.6.x
M Alto vulnerabilidad
12/06/2026
[CVE-2026-53981] Cap-go prior to 12.128.2 contains an account takeover vulnerability in its email change mechanism th…
Cap-go prior to 12.128.2 contains an account takeover vulnerability in its email change mechanism that allows an attacker with temporary authenticated session access to change the registered email address without re-authentication such as password or MFA verification. Attackers can redirect verification to an attacker-controlled email address and subsequently perform a password reset to permanentl…
L Alto vulnerabilidad
12/06/2026
[CVE-2026-3840] A vulnerability in Kedro version 1.2.0 allows an attacker to exploit path traversal by providing a c…
A vulnerability in Kedro version 1.2.0 allows an attacker to exploit path traversal by providing a crafted version string. The `_get_versioned_path()` method in `kedro/io/core.py` directly interpolates user-supplied version strings into filesystem paths without sanitization. This enables an attacker to escape the intended versioned dataset directory and access files outside the expected path. The …
A Crítico vulnerabilidad
12/06/2026
[CVE-2026-50086] The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the p…
The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing key without authentication. This is an instance of "CWE-306: Missing Authentication for Critical Function" and "CWE-327: Use of a Broken or Risky Cryptographic Algorithm," and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N (7.5 High).
A Crítico vulnerabilidad
12/06/2026
[CVE-2026-50091] Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same libl…
Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses hard-coded cryptographic keys, which is an instance of "CWE-321: Use of Hard-coded Cryptographic Key" and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (9.1 Critical).
N Alto vulnerabilidad
12/06/2026
[CVE-2026-50011] Netty is a network application framework for development of protocol servers and clients. Prior to v…
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, RedisArrayAggregator pre-allocates ArrayList with initial capacity equal to the RESP array element count declared in an array header. That count is taken from the wire before the corresponding child messages exist. A small malicious header can claim a huge ini…
N Alto vulnerabilidad
12/06/2026
[CVE-2026-47691] Netty is a network application framework for development of protocol servers and clients. Prior to v…
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's `DnsResolveContext` insufficiently validates the bailiwick of NS records, enabling DNS Cache Poisoning. An attacker controlling an authoritative name server for a subdomain can poison the cache for parent domains (like `.co.uk`). In `io.netty.resolver.…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
N Alto vulnerabilidad
12/06/2026
[CVE-2026-48059] Netty is a network application framework for development of protocol servers and clients. Prior to v…
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the HAProxy PROXY protocol v2 codec in netty leaks native or heap memory on every connection when a client sends a syntactically valid header containing nested `PP2_TYPE_SSL` TLVs (type-length-value records) at depth two or greater. The leak occurs on the succ…
N Alto vulnerabilidad
12/06/2026
[CVE-2026-48748] Netty is a network application framework for development of protocol servers and clients. Prior to v…
Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final, a memory exhaustion vulnerability in the Netty HTTP/3 codec allows the creation of an infinite number of blocked streams, which can cause OOM error. Version 4.2.15.Final patches the issue.
M Crítico vulnerabilidad
12/06/2026
[CVE-2026-47131] vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, by combining Buffer.call.call…
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, by combining Buffer.call.call({}.__lookupGetter__, Buffer, "__proto__"), Buffer.call.call({}.__lookupSetter__, Buffer, "__proto__"), and Node.js's ERR_INVALID_ARG_TYPE Error, the host's TypeError constructor can be obtained, which allows the escape from the sandbox. This allows attackers to run arbitrary code. This issue has be…
M Alto vulnerabilidad
12/06/2026
[CVE-2026-12066] A security flaw has been discovered in PbootCMS up to 3.2.12. This vulnerability affects the functio…
A security flaw has been discovered in PbootCMS up to 3.2.12. This vulnerability affects the function retrieve of the file apps/home/controller/MemberController.php of the component Password Handler. The manipulation of the argument username/password/email/checkcode results in weak password recovery. It is possible to launch the attack remotely. The exploit has been released to the public and may …
M Crítico vulnerabilidad
12/06/2026
[CVE-2026-11849] The  iRM-IEI Remote Management developed by IEI Integration Corp has a Hardcoded Credentials vulnera…
The  iRM-IEI Remote Management developed by IEI Integration Corp has a Hardcoded Credentials vulnerability, allowing unauthenticated remote attackers to exploit hard-coded credentials to gain administrative privileges on the database.
A Alto vulnerabilidad
12/06/2026
[CVE-2026-50633] A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can…
A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
A Alto vulnerabilidad
12/06/2026
[CVE-2026-50645] There is no restriction on the amount of attachment headers that a message can contain when being de…
There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncontrolled resource consumption or a denial of service attack. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue by imposing a maximum default of 500 attachments per message.
A Crítico vulnerabilidad
12/06/2026
[CVE-2026-49875] Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory w…
Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
P Alto vulnerabilidad
12/06/2026
[CVE-2026-45169] Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, an…
Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, processing unexpected input could potentially lead to an unexpected service termination, resulting in a localized denial of service (DoS). CyberArk Security Bulletin: CA26-17
M Alto vulnerabilidad
12/06/2026
[CVE-2026-48612] Improper state verification in the OAuth implementation could allow an attacker to manipulate the au…
Improper state verification in the OAuth implementation could allow an attacker to manipulate the authentication flow and cause a victim’s account to be linked to an attacker-controlled account. This can result in unauthorized account linking and potential account takeover.
M Alto vulnerabilidad
12/06/2026
[CVE-2026-47368] A malicious actor with access to the network could exploit a Path Traversal vulnerability found in c…
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to obtain data from such UniFi OS devices or instances.
M Crítico vulnerabilidad
12/06/2026
[CVE-2026-47369] A malicious actor with access to the network and low privileges could exploit an Improper Input Vali…
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.
M Crítico vulnerabilidad
12/06/2026
[CVE-2026-47370] A malicious actor with access to the network and low privileges could exploit an Improper Input Vali…
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to execute a Command Injection within such UniFi OS devices or instances.