Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ni" — 7302 resultados ✕ Limpiar búsqueda
22,394
Total alertas
4758
Críticas
17006
Altas
8
Ransomware
1261
Esta semana
RSS
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-101081] A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability affects the function…
A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability affects the function menu_nat_more_asp of the file menu_nat_more.asp of the component Web Administration Service. The manipulation of the argument opt results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
M Alto vulnerabilidad
28/09/2026
[CVE-2026-88805] Incorrect credential cleaning on logout could be used by remote attackers to keep access credentials…
Incorrect credential cleaning on logout could be used by remote attackers to keep access credentials even after the account was logged out. Affected is SUSE Rancher 2.15 before 2.15.2.
M Alto vulnerabilidad
28/09/2026
[CVE-2026-88808] A vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to …
A vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to downstream clusters using its own cluster-admin credentials instead of the ServiceAccount pinned to the deployment. It affects multi-tenancy environments where different tenants share the same downstream clusters, for example different privileged or untrusted teams inside the same organization. This…
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-101077] A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the…
A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp Handler. This manipulation causes missing authentication. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-101076] A vulnerability was detected in Netcore NR289-GE 1.4.5102. This affects the function system of the f…
A vulnerability was detected in Netcore NR289-GE 1.4.5102. This affects the function system of the file /set_ntp_server_ip.cgi of the component CGI Handler. The manipulation of the argument ntp_ip results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Alto vulnerabilidad
28/09/2026
[CVE-2026-93538] A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated clus…
A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated cluster registration, cluster labels supplied by the registering agent, including labels in the reserved management.cattle.io/ namespace such as the cluster display name label, were applied to the resulting upstream Cluster object. Because Fleet resolves GitRepo and Bundle targets from those cluster lab…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-4556] Exam4 is affected by a local privilege escalation vulnerability in the com.extegrity.LogTool privile…
Exam4 is affected by a local privilege escalation vulnerability in the com.extegrity.LogTool privileged helper, which communicates with the application via XPC. The [ConsoleLogHelper copyConsoleIntoFileFromStartDate:] method executes a syslog command using attacker-controlled parameters without proper sanitization, enabling command injection. Successful exploitation allows a local attacker to exec…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-101075] A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The impacted element is the…
A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The impacted element is the function system of the file /location_time.cgi of the component Location Time Handler. The manipulation of the argument mac leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about thi…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-101073] A security flaw has been discovered in Netcore NR289-GE 1.4.5102. Impacted is an unknown function of…
A security flaw has been discovered in Netcore NR289-GE 1.4.5102. Impacted is an unknown function of the file /bin/boa of the component CGI Dispatcher. Performing a manipulation results in improper authentication. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in…
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-101074] A weakness has been identified in Netcore NR289-GE 1.4.5102. The affected element is the function pa…
A weakness has been identified in Netcore NR289-GE 1.4.5102. The affected element is the function password-check of the file /bin/boa of the component Authentication. Executing a manipulation of the argument Username can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-97335] Incorrect authorization in the custom storage volume creation endpoint in Canonical LXD versions 5.0…
Incorrect authorization in the custom storage volume creation endpoint in Canonical LXD versions 5.0.0 and later (fixed in 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create custom volumes in a project to copy, and so read, any custom storage volume from any other project on the server, including its snapshots and configuration. The client does this with a c…
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-87799] Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixe…
Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client that can create instances or custom storage volumes in a project, or a malicious migration source server, to write attacker-controlled files to arbitrary paths on the target host as root, leading to full host compromise. T…
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-90924] Use of default credentials vulnerability in Innotim Software, Telecommunications and Consultancy Tra…
Use of default credentials vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Try Common or Default Usernames and Passwords. This issue affects Logsign SIEM: from 6.4.101 before 6.4.117.
M Alto vulnerabilidad
28/09/2026
[CVE-2026-90925] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Inno…
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Path Traversal. This issue affects Logsign SIEM: from 6.4.101 before 6.4.117.
M Alto vulnerabilidad
28/09/2026
[CVE-2026-90926] Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecom…
Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue affects Logsign SIEM: from 6.4.101 before 6.4.117.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-85185] Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.1…
Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create instances in a project to delete arbitrary files on the host as root. On hosts whose root filesystem is btrfs, the client can also place attacker-controlled content at arbitrary host paths, leading to full …
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-85526] Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authen…
Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace arbitrary files and directories on the host filesystem as root via a crafted subvolumes[].path entry in backup/optimized_header.yaml during a btrfs optimized backup import.
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-101072] A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects the function system …
A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects the function system of the file /ap_ip.cgi of the component CGI Handler. Such manipulation of the argument ip leads to os command injection. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Alto vulnerabilidad
28/09/2026
[CVE-2026-86330] An OS command injection flaw was found in the set_hostname_internal function of NooBaa's cluster_int…
An OS command injection flaw was found in the set_hostname_internal function of NooBaa's cluster_internal_api. This component is responsible for managing the Multi-Cloud Object Gateway in OpenShift Data Foundation. The vulnerability occurs because the hostname parameter is passed directly to a shell command without proper sanitization. An authenticated attacker with administrative privileges can p…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-101066] A vulnerability was determined in dbgate up to 7.3.1. The impacted element is the function createLin…
A vulnerability was determined in dbgate up to 7.3.1. The impacted element is the function createLink of the file packages/api/src/controllers/archive.js of the component Archive Link Creation. This manipulation of the argument linkedFolder causes path traversal. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about …