Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
Buscando: "X" — 10452 resultados ✕ Limpiar búsqueda
14,078
Total alertas
3213
Críticas
10592
Altas
8
Ransomware
1064
Esta semana
RSS
H Crítico vulnerabilidad
03/07/2026
[CVE-2026-8924] A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that byp…
A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains.
H Crítico vulnerabilidad
03/07/2026
[CVE-2026-8925] The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice…
The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer twice.
H Crítico vulnerabilidad
03/07/2026
[CVE-2026-10536] A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dep…
A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during …
H Alto vulnerabilidad
03/07/2026
[CVE-2026-11352] An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote de…
An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client. Because the helper function discards zero-length UDP datagrams before counting them toward the per-call packet budget, a connected QUIC peer can continuously stream empty datagrams to indefinitely stall the client.
H Crítico vulnerabilidad
03/07/2026
[CVE-2026-11564] libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if …
libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle that first uses default native CA trust can continue trusting the native platform store after the application switches that same handle to custom CA material for a later transfer.
H Alto vulnerabilidad
03/07/2026
[CVE-2026-11586] By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound …
By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a malicious server can exhaust all available memory by flooding curl with rapid, sequential PING messages.
H Crítico vulnerabilidad
03/07/2026
[CVE-2026-11856] Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** auth…
Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header field meant for `hostA`, to `hostB`.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
03/07/2026
[CVE-2026-9725] The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Ar…
The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.5.2 This is due to insufficient path validation in the store_design_data() function, which constructs a filesystem path from the user-supplied 'nbd_item_key' POST parameter sanitized only with sanitize_text_field() — which does not strip path…
M Alto vulnerabilidad
03/07/2026
[CVE-2026-13040] The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cro…
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'real_val__' parameter in all versions up to, and including, 9.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injecte…
M Alto vulnerabilidad
03/07/2026
[CVE-2026-14327] The AR for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to…
The AR for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.40 via the 'file' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires an attacker to first obtain a valid nonce and secure nonce via the publ…
M Crítico vulnerabilidad
03/07/2026
[CVE-2026-13768] Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user t…
Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function which returns connection information for all Gardyn Home Kit and Studio devices. Access to this key also allows a malicious user to execute arbitrary commands on a specific connected device and may allow the malicious user to pivot to other devices on the…
W Alto vulnerabilidad
03/07/2026
[CVE-2026-13383] An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authe…
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.This vulnerability affects Fireware OS 12.1 up to and including 12.12 and 2025.1 up to and including 2026.2.
W Alto vulnerabilidad
03/07/2026
[CVE-2026-13384] An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authen…
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.This vulnerability affects Fireware OS 12.1 up to and including 12.12 and 2025.1 up to and including 2026.2.
W Alto vulnerabilidad
03/07/2026
[CVE-2026-13053] An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated pr…
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CLI command. This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2.
W Alto vulnerabilidad
03/07/2026
[CVE-2026-13054] A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged a…
A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged authenticated attacker to write arbitrary files on the Firebox's filesystem. This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
02/07/2026
[CVE-2026-54998] Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privil…
Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
L Alto vulnerabilidad
02/07/2026
[CVE-2026-50721] Libreswan, via the function RSA_authenticate_hash_signature_raw_rsa(), did not correctly verify the …
Libreswan, via the function RSA_authenticate_hash_signature_raw_rsa(), did not correctly verify the length of the authentication hash when the SIG payload of an IKEv1 packet was encoded using PKCS #1 RSA Encryption as per RFC 2313. A remote attacker can use a variation on the Bleichenbacher attack to forge the SIG payload when small public exponents are being used (e.g., e=3), which could lead to …
L Alto vulnerabilidad
02/07/2026
[CVE-2026-50722] Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly verif…
Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly verify the DER encoding of the ASN.1 digest when the IKEv2 AUTH payload was encoded using RSASSA-PKCS1-v1_5 (RFC 8017). A remote attacker can use a variation on the Bleichenbacher attack to forge the AUTH payload when small public exponents are used (e.g., e=3), leading to impersonation. Additionally, a …
L Alto vulnerabilidad
02/07/2026
[CVE-2026-12413] An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Contin…
An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued exploitation would cause a denial of service. The function reassemble_v2_incoming_fragments() would ignore unknown outer payloads but still store these in a fixed size array msg_digest.digest[PAYLIMIT]. An off-by-one error in the assertion PASSERT(logger, md->digest_roof < elemsof(md->digest)) c…
M Alto vulnerabilidad
02/07/2026
[CVE-2026-58460] react-native-receive-sharing-intent contains a path traversal vulnerability that allows a co-residen…
react-native-receive-sharing-intent contains a path traversal vulnerability that allows a co-resident malicious application to write files outside the intended cache directory by supplying a crafted _display_name value containing dot-dot path components through a malicious ContentProvider. Attackers can fire an explicit ACTION_SEND intent at the consuming app's exported share-receiver activity to …