Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1003
Esta semana
RSS
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-103041] LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pick…
LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Attackers can send crafted serialized objects to exposed cache methods to execute arbitrary code with service privileges.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-100308] Deserialization of untrusted data in the model loading component in Amazon GluonTS before 0.17.0 mig…
Deserialization of untrusted data in the model loading component in Amazon GluonTS before 0.17.0 might allow context-dependent attackers to execute arbitrary operating system commands with the privileges of the loading process via a crafted serialized model directory. To remediate this issue, users should upgrade to version 0.17.0 or later.
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-82384] Deserialization of Untrusted Data in Apache Roller 6.1.5 allows an unauthenticated remote attacker t…
Deserialization of Untrusted Data in Apache Roller 6.1.5 allows an unauthenticated remote attacker to cause deserialization of attacker-controlled bytes, because the XML-RPC endpoint accepts vendor extension types that are deserialized during request parsing, before authentication. The servlet is mapped unconditionally, so parsing occurs even when the global XML-RPC feature is set to disabled; no …
M Alto vulnerabilidad
27/09/2026
Vulnerabilidad alta de deserialización insegura en MONAI anterior a v1.6.0
MONAI antes de la versión 1.6.0 contiene una vulnerabilidad de deserialización insegura en la clase NumpyReader que utiliza numpy.load con allow_pickle=True sin validación, permitiendo a atacantes ejecutar código arbitrario mediante archivos .npy y .npz maliciosos en pipelines de datos estándar. Esta vulnerabilidad afecta especialmente a organizaciones en LATAM que utilizan MONAI en aplicaciones de análisis médico, investigación biomédica e inteligencia artificial sin restricciones en el origen de los datos de entrenamiento.
M Alto vulnerabilidad
27/09/2026
Vulnerabilidad alta de deserialización en MONAI anterior a 1.5.2 permite ejecución remota de código
MONAI versions anteriores a la 1.5.2 contiene una vulnerabilidad de deserialización de datos no confiables en la función algo_from_pickle que procesa archivos .pkl sin validación. Un atacante puede ejecutar código arbitrario mediante un archivo pickle manipulado si la aplicación lo procesa. Esta vulnerabilidad afecta directamente plataformas de análisis de imágenes médicas 3D en instituciones sanitarias y centros de investigación de LATAM.
M Alto vulnerabilidad
27/09/2026
[CVE-2026-100841] In MONAI 1.6.0, PersistentDataset (monai/data/dataset.py) explicitly rejects the combination track_m…
In MONAI 1.6.0, PersistentDataset (monai/data/dataset.py) explicitly rejects the combination track_meta=True with weights_only=True, forcing users who cache MetaTensors (the default tensor type in MONAI >= 1.0) to run torch.load(hashfile, weights_only=False). Related cache helpers in monai/data/utils.py also call pickle.loads on cached content and derive cache keys with hashlib.md5. As a result, a…
M Alto vulnerabilidad
27/09/2026
[CVE-2026-100843] MONAI versions before 1.6.0 contain a remote code execution vulnerability in the algo_from_pickle() …
MONAI versions before 1.6.0 contain a remote code execution vulnerability in the algo_from_pickle() function due to unsafe pickle.loads() deserialization in monai/auto3dseg/utils.py. Attackers can craft malicious pickle files that execute arbitrary system commands when deserialized by the vulnerable function.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
25/09/2026
[CVE-2026-84862] IBM Guardium Data Protection 12.2 is vulnerable to insecure deserialization in the Quartz JDBC job s…
IBM Guardium Data Protection 12.2 is vulnerable to insecure deserialization in the Quartz JDBC job store. An authenticated attacker could exploit this vulnerability to execute arbitrary code on the affected system.
M Alto vulnerabilidad
25/09/2026
[CVE-2026-97865] A security flaw has been discovered in Open-Web-Analytics up to 1.8.1. Affected is the function Even…
A security flaw has been discovered in Open-Web-Analytics up to 1.8.1. Affected is the function Event::loadFromArray of the file queue.php of the component Remote Event Queue Endpoint. Performing a manipulation results in deserialization. The attack can be initiated remotely. Upgrading to version 1.8.2 is able to address this issue. The patch is named 78c1222ec0e2119d84684032da1541120a2cdd23. The …
M Alto vulnerabilidad
24/09/2026
[CVE-2026-82093] IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute a…
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to unsafe deserialization of untrusted data.
M Alto vulnerabilidad
24/09/2026
Vulnerabilidad de deserialización en plugin wpForo Forum WordPress anterior a v3.1.6
El plugin wpForo Forum para WordPress anterior a la versión 3.1.6 permite a usuarios autenticados con nivel Subscriber o superior inyectar objetos PHP maliciosos mediante campos de perfil sin validar durante la deserialización. La vulnerabilidad se amplifica si otros plugins wpForo instalados contienen cadenas de Property-Oriented Programming (POP) que pueden ser explotadas para ejecución de código remoto. Afecta principalmente a sitios empresariales en LATAM que utilizan este plugin para comunidades o foros internos.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-95603] Shop manager PHP Object Injection in Reycob Product Import Export <= 2.3.0 versions.
Shop manager PHP Object Injection in Reycob Product Import Export
M Alto vulnerabilidad
23/09/2026
[CVE-2026-96775] MLflow's dspy flavor, versions >= 2.0, applies the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False securi…
MLflow's dspy flavor, versions >= 2.0, applies the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control only when the model_path ends in .pkl, which allows a remote attacker to execute arbitrary code via a crafted MLmodel artifact.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-96804] MLflow's statsmodel flavor, versions 2.1.0 to 3.14.0, omits the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=…
MLflow's statsmodel flavor, versions 2.1.0 to 3.14.0, omits the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control entirely in _load_model(), which allows a remote attacker to execute arbitrary code via a crafted MLmodel artifact.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-18490] IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to unauthenticated remote…
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to unauthenticated remote code execution via Java native deserialization on the PayDir Business Rules Manager RMI SSL endpoint (BrmRMISSLServerSocketFactory.java:95, EP8). An adjacent-network attacker can deliver a crafted serialized payload to achieve arbitrary code execution, exposing all PayDir credentials and enabling m…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
23/09/2026
[CVE-2026-96560] LightLLM through 1.2.0 contains a remote code execution vulnerability in the KV-transfer worker when…
LightLLM through 1.2.0 contains a remote code execution vulnerability in the KV-transfer worker when started with --pd_trans_mode nccl, which exposes an unauthenticated RPyC control channel that deserializes attacker-supplied data. Attackers can send malicious pickled objects to the exposed RPyC ThreadedServer to execute arbitrary code with the privileges of the LightLLM service account.
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-18163] IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execut…
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper deserialization of untrusted data.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-17637] IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow an adjacent-network attacke…
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow an adjacent-network attacker to execute arbitrary code due to deserialization of untrusted data.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-67615] openEQUELLA before 2026.1.0 contains an authenticated remote code execution vulnerability that allow…
openEQUELLA before 2026.1.0 contains an authenticated remote code execution vulnerability that allows any authenticated non-guest user to execute arbitrary code by exploiting Java deserialization in the HTTP invoker endpoint at /invoker/*. Attackers can bypass the class-name denylist enforced by PluginAwareObjectInputStream by nesting a serialized payload inside a java.security.SignedObject, causi…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-28325] SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code exec…
SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is configured to use a specific communication mode.