Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 40 min
Buscando: "Ui" — 3488 resultados ✕ Limpiar búsqueda
22,345
Total alertas
4745
Críticas
16970
Altas
8
Ransomware
1213
Esta semana
RSS
G Medio vulnerabilidad
14/09/2026
Chromium CVE-2026-87583: UI misrepresentation in Passwords
Microsoft publica advisory de seguridad: Chromium CVE-2026-87583: UI misrepresentation in Passwords.
G Medio vulnerabilidad
14/09/2026
Chromium CVE-2026-87501: UI misrepresentation in Passwords
Microsoft publica advisory de seguridad: Chromium CVE-2026-87501: UI misrepresentation in Passwords.
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-90942] Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /…
Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it. Attackers can use the exposed private key to forge JWT tokens for any user in any organization, including global administrators.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-73494] blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0…
blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and from 1.0.0-M1 until 1.0.0-M42, five HTTP/1.1 conformance laxities in the hand-written Java parser under http/src/main/java/org/http4s/blaze/http/parser/ can cause blaze to derive a different request boundary than a stricter fronting intermediary. A default BlazeServerBuilder accepts inval…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-54180] backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of …
backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, the Update, Delete, and Reorder operations resolve records from the unscoped model query instead of the query configured through addClause() or addBaseClause(). An authenticated user who knows or…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-54182] backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of …
backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 4.1.70, 5.6.2, 6.8.13, and 7.0.36, Backpack\CRUD\Stats::makeCurlRequest in src/Stats.php is reached from BackpackServiceProvider::boot() and constructs a shell command with a URL influenced by the HTTP Host header, which i…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-54175] backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of …
backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 6.8.11 and 7.0.34, MyAccountController::postAccountInfoForm in src/app/Http/Controllers/MyAccountController.php at POST /admin/edit-account-info passes request data from $request->except(['_token']) to the user model inste…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
14/09/2026
[CVE-2026-54178] backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of …
backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 6.8.12 and 7.0.35, HasUploadFields::uploadMultipleFilesToDisk in src/app/Models/Traits/HasUploadFields.php trusts disk-relative paths from clear_[] and passes them to Storage::disk()->delete without confirming t…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-19499] Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of th…
Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding. Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the int…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-55416] Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026…
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, an authenticated user with reports_config permission can place attacker-controlled SQL fragments in the sql, from, where, and groupby fields of a Custom Reports configuration processed by bundles/CustomReportsBundle/src/Tool/Adapter/Sql.php. The buildQueryString() method concatenates these val…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-55072] Pimcore is an Open Source Data & Experience Management Platform. Prior to 2026.1.5, an authenticated…
Pimcore is an Open Source Data & Experience Management Platform. Prior to 2026.1.5, an authenticated user with the objects permission can submit a malicious ClassDefinition UID because the name and ID validation expressions in models/DataObject/ClassDefinition.php validate only the beginning of each value. When a data object of that class containing a Block field is loaded, Block::load in models/D…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-57124] PraisonAI is a multi-agent teams system. Prior to 4.6.59, the default UI host applications expose PO…
PraisonAI is a multi-agent teams system. Prior to 4.6.59, the default UI host applications expose POST /api/mcp/connect without mandatory authentication and accept caller-controlled command and args values that PraisonAIUI passes to StdioMCPClient to start a local process. Because the UI commands bind to 0.0.0.0 by default, a reachable unauthenticated client can execute commands as the UI service …
M Alto vulnerabilidad
14/09/2026
[CVE-2026-82427] Description A topology's `topology.blobstore.map` lets the submitter choose a local name for each b…
Description A topology's `topology.blobstore.map` lets the submitter choose a local name for each blob that the supervisor localises. That name was used to build a path under the topology's working directory without normalisation, in both `AsyncLocalizer` and `Container.createBlobstoreLinks`, and the symlink helper force-deletes whatever already exists at the target before creating the link. A s…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-82429] Description The setuid-root `worker-launcher` binary adjusts ownership and permissions of worker di…
Description The setuid-root `worker-launcher` binary adjusts ownership and permissions of worker directories by walking the tree with FTS and calling `lchown` and `chmod` on each entry's full pathname while running with an effective uid of 0. Both syscalls re-resolve the path at the time of the call, after FTS has classified the entry, and the trees being walked are owned and writable by the untr…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-82430] Description When launching a Docker or OCI worker, the setuid-root `worker-launcher` first changes …
Description When launching a Docker or OCI worker, the setuid-root `worker-launcher` first changes ownership of the entire worker directory to the untrusted topology user, and only afterwards reads and acts on the command file that the supervisor wrote into that same directory. The file is opened without `O_NOFOLLOW` and without re-verifying its owner, so between the ownership change and the read…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-57125] PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.59 and praisonaiagents 1.6.59, the u…
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.59 and praisonaiagents 1.6.59, the unauthenticated POST /api/v1/runs Jobs API accepts attacker-controlled agent_yaml, and the approve field can mark execute_command as YAML-approved before @require_approval checks critical tools. This chain allows a remote caller to cause a configured language model agent to invoke arbitrary operating…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-90948] A flaw was found in GIMP's ICO file loader. When processing an ICO file containing an embedded PNG i…
A flaw was found in GIMP's ICO file loader. When processing an ICO file containing an embedded PNG image, an integer overflow can occur during the calculation of the required buffer size. This leads to an undersized buffer being allocated, causing a heap-based buffer overflow when the decoded pixel data is written. A remote attacker could exploit this by crafting a malicious ICO file, which, when …
M Alto vulnerabilidad
14/09/2026
[CVE-2026-73236] Incorrect Authorization vulnerability in Apache Syncope. Delegated administration security checks…
Incorrect Authorization vulnerability in Apache Syncope. Delegated administration security checks are based on Realm hierarchy and enforced via prefix matches. Due to incorrect implementation, two sibling Realms whose names begin with the same string cannot be correctly distinguished, resulting in incorrect authorization. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, fro…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-90937] froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowi…
froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives. Attackers can supply URLs containing literal newlines that are written verbatim into vhost config files during cron rebuild, enabling web server configuration corruption, denial of service, or hijacking of HTTP …
M Crítico vulnerabilidad
14/09/2026
Vulnerabilidad crítica en Bifrost permite ejecución remota de código sin autenticación
Bifrost permite registrar clientes MCP a través de su API de gestión sin requerir handshake MCP ni autenticación cuando governance.auth_config.is_enabled=false (configuración por defecto). Un atacante puede ejecutar comandos arbitrarios como el usuario del proceso Bifrost mediante una única solicitud POST /api/mcp/client no autenticada, comprometiendo completamente servidores y gateways en empresas de LATAM que usen esta solución.