Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,598
Total alertas
3086
Críticas
10240
Altas
8
Ransomware
1806
Esta semana
RSS
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-20304] As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst …
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20304 are related to improper access control issues that are gr…
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-20272] As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE So…
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20272 are related to issues with improper neutralization of spec…
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-20267] As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE So…
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20267 are related to improper access control issues that ar…
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-9192] An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11…
An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, including administrators.
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-9193] An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Serve…
An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations against the Security database.
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-9195] A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6…
A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a crafted URL to execute arbitrary JavaScript in the administrator's browser session, capture credentials, and perform privileged actions on the administrator's behalf.
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-7329] An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces o…
An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges to administrator. This enables execution of privileged operations and unauthorized data access.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-7557] An improper verification of cryptographic signature vulnerability in the SAML authentication module …
An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled.
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-8709] An improper privilege management vulnerability in the REST API document patch operation of Progress …
An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges and execute privileged operations against the Security database.
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-9190] An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 1…
An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication and authorization checks, hijack a legitimate user's session, or capture credentials. The vulnerability occurs when a crafted HTTP request containing both Content-Length and Transfer-Encoding headers causes a reverse proxy and MarkLo…
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-71289] The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default dock…
The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publishes the amp-manager service's REST API directly to the host network interface (port 8089, e.g. "${ION_MGR_PORT:-8089}:8089/tcp") with cap_add: NET_ADMIN, NET_RAW, SYS_NICE, bypassing the CAM (Configuration and Access Manager) gateway that is otherwise the system's sole authentic…
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-71277] rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the…
rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the Authorization HTTP header is present, and never validates its value against any session, token store, or signature. Any request carrying an arbitrary non-empty Authorization header (e.g. `Authorization: fake`) satisfies the guard, granting access to every endpoint protected only by this request gua…
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-71278] rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/controller/calc_…
rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/controller/calc_rule_router.rs) containing an arbitrary `script` field. This route does not take the AuthToken request guard used elsewhere in the application, making it reachable without authentication. The stored script is subsequently executed via quick_js::Context::eval() in api/src/biz/calc_run_biz.rs with no …
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-71268] OpenPLC Runtime v3's compile_program() function (webserver/openplc.py) parses `(*FILE:path content*)…
OpenPLC Runtime v3's compile_program() function (webserver/openplc.py) parses `(*FILE:path content*)` directives from uploaded Structured Text (.st) program files and writes the referenced content to `os.path.join('./core', file_path)` with no validation that file_path stays within the ./core directory. A crafted .st file containing a directive such as `(*FILE:../../../etc/cron.d/x * * * * root
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-71262] IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to every other controller …
IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to every other controller in the application (DevicesController, CustomersController, TenantsController, etc.), and no global authorization FallbackPolicy is configured in Startup.cs, leaving its Upload/Download/List/Modify/Delete endpoints reachable by unauthenticated remote attackers. The path/filename parameters passed to…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-71263] The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool() (demo/LINUXT…
The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool() (demo/LINUXTCP/port/porttcp.c). The check `if (usTCPFrameBytesLeft > MB_TCP_BUF_SIZE)` uses a strict greater-than comparison instead of greater-than-or-equal against the 263-byte MB_TCP_BUF_SIZE limit. An MBAP frame with a Length field of 264 makes usTCPFrameBytesLeft equal to 263, which passes the flawed check…
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-71267] microtar's mtar_write_file_header() and mtar_write_dir_header() functions (src/microtar.c) copy a ca…
microtar's mtar_write_file_header() and mtar_write_dir_header() functions (src/microtar.c) copy a caller-supplied entry name into the 100-byte `name` field of a stack-allocated mtar_header_t via strcpy(h.name, name), with no check that strlen(name) is less than 100 before the copy. Any application that calls these functions with an externally-influenced filename longer than 99 characters (e.g. whe…
M Crítico vulnerabilidad
05/08/2026
Vulnerabilidad crítica en nanoMODBUS v1.23.0: desbordamiento de búfer en servidor
nanoMODBUS hasta la versión 1.23.0 contiene un desbordamiento de búfer (out-of-bounds write) en la función handle_read_file_record() del servidor Modbus (FC 0x14). La validación de tamaño de solicitud es insuficiente, permitiendo que atacantes remotos causen escritura de memoria fuera de límites a través de múltiples sub-solicitudes acumulativas. Afecta infraestructuras SCADA, sistemas embebidos y dispositivos IoT industriales comunes en manufactura y utilidades de LATAM.
M Crítico vulnerabilidad
05/08/2026
Vulnerabilidad crítica en nanoMODBUS v1.23.0: lectura fuera de límites en identificación de dispositivos
nanoMODBUS hasta la versión 1.23.0 contiene una vulnerabilidad de lectura fuera de los límites de la pila que permite escritura de punteros salvajes en la función nmbs_read_device_identification_basic(). Un campo object_id no validado (0-255) desde la red causa acceso a memoria no inicializada. Afecta sistemas SCADA, HMI y equipos IoT industriales en plantas manufactureras y servicios críticos de LATAM.
M Crítico vulnerabilidad
05/08/2026
Inyección SQL crítica en Inventory-Management-System-PHP permite bypass de autenticación
El sistema de gestión de inventario PHP contiene vulnerabilidades de inyección SQL en los módulos login.php y delete.php debido a la concatenación insegura de parámetros POST sin validación ni uso de consultas parametrizadas. Un atacante puede ejecutar consultas arbitrarias, eludir la autenticación y manipular datos de inventario críticos en sistemas empresariales de LATAM que dependen de este software.