Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
14,230
Total alertas
3248
Críticas
10709
Altas
8
Ransomware
983
Esta semana
RSS
M Crítico vulnerabilidad
10/07/2026
[CVE-2026-55500] 9Router is an AI router & token saver. Prior to 0.4.80, the /api/settings/database endpoint allows f…
9Router is an AI router & token saver. Prior to 0.4.80, the /api/settings/database endpoint allows full database export (containing all credentials, API keys, OAuth tokens, and settings) and full database import (complete overwrite) without any authentication requirement beyond the ALWAYS_PROTECTED middleware check, which only validates JWT or CLI token. This issue is fixed in version 0.4.80.
M Alto vulnerabilidad
10/07/2026
[CVE-2026-55501] 9Router is an AI router & token saver. Prior to 0.4.80, the dashboard login rate limiter in src/lib/…
9Router is an AI router & token saver. Prior to 0.4.80, the dashboard login rate limiter in src/lib/auth/loginLimiter.js derives the client identity from the attacker-controlled X-Forwarded-For HTTP header, and src/app/api/auth/login/route.js uses that spoofable value for checkLock and recordFail. A remote attacker can rotate the X-Forwarded-For value on each login attempt to receive a fresh rate-…
M Alto vulnerabilidad
10/07/2026
[CVE-2026-54149] MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.0-lts, MaxKB tool import function…
MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.0-lts, MaxKB tool import functionality in apps/tools/serializers/tool.py and MCP referencing mode in apps/application/chat_pipeline/step/chat_step/impl/base_chat_step.py do not consistently validate MCP transport type, allowing an authenticated user to import a .tool file containing stdio transport with malicious commands and trigg…
G Alto vulnerabilidad
10/07/2026
[CVE-2026-33382] Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request bo…
Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.
M Crítico vulnerabilidad
10/07/2026
[CVE-2026-15143] A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability allow…
A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability allows a remote attacker to supply an arbitrary XML Schema Definition (XSD) string, which is processed without proper restrictions. This can lead to server-side requests to arbitrary URLs or local file reads, potentially resulting in sensitive information disclosure, such as cloud provider credentials or…
M Alto vulnerabilidad
10/07/2026
[CVE-2026-61434] PraisonAI versions before 4.6.78 contain an allowlist bypass vulnerability in shell command executio…
PraisonAI versions before 4.6.78 contain an allowlist bypass vulnerability in shell command execution that allows attackers to execute restricted commands via find's built-in -exec, -execdir, and -delete actions. Attackers can craft find commands with these built-in actions to read blocked files, delete files, or execute non-allowlisted binaries without triggering shell metacharacter filters.
M Alto vulnerabilidad
10/07/2026
[CVE-2026-61437] PraisonAI (pip package praisonaiagents) before 1.6.78 contains an unsafe dynamic module loading vuln…
PraisonAI (pip package praisonaiagents) before 1.6.78 contains an unsafe dynamic module loading vulnerability in AgentFlow._resolve_pydantic_class (src/praisonai-agents/praisonaiagents/workflows/workflows.py). When a workflow step uses a string output_pydantic reference, the framework locates and imports a sibling tools.py from the workflow file's directory via importlib exec_module without sandbo…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
10/07/2026
[CVE-2026-61444] PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the a…
PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated into an f-string without sanitization. Attackers can inject arbitrary Python code that executes when the generated server code runs via subprocess.Popen().
M Alto vulnerabilidad
10/07/2026
[CVE-2026-60091] PraisonAI before 4.6.78 contains an unauthenticated server-side request forgery vulnerability in the…
PraisonAI before 4.6.78 contains an unauthenticated server-side request forgery vulnerability in the Jobs API /api/v1/runs endpoint. The webhook_url parameter is validated at request time but re-resolved at connection time, allowing attackers to use DNS rebinding to reach internal services with a blind SSRF attack.
J Crítico vulnerabilidad
10/07/2026
[CVE-2026-59792] In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project wor…
In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible
J Alto vulnerabilidad
10/07/2026
[CVE-2026-59793] In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integr…
In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration
J Alto vulnerabilidad
10/07/2026
[CVE-2026-59794] In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-re…
In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data
J Alto vulnerabilidad
10/07/2026
[CVE-2026-59795] In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible
In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible
J Alto vulnerabilidad
10/07/2026
[CVE-2026-59796] In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission …
In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks
M Crítico vulnerabilidad
10/07/2026
[CVE-2026-56765] Vikunja before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes s…
Vikunja before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes share hashes to users with read access, enabling permission escalation to admin-level shares. The GetTaskAttachment endpoint performs permission checks against user-supplied task IDs but fetches attachments by sequential ID without verifying ownership, allowing attackers to download and delete all fi…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
K Alto vulnerabilidad
10/07/2026
[CVE-2026-56261] Crawl4AI before 0.8.7 contains a server-side request forgery (SSRF) vulnerability in the Docker API …
Crawl4AI before 0.8.7 contains a server-side request forgery (SSRF) vulnerability in the Docker API server's /crawl/job and /llm/job endpoints, which accept webhook URLs without destination validation. An attacker can supply webhook URLs pointing to private or internal IP ranges, Docker networks, or cloud metadata endpoints (e.g. 169.254.169.254), causing the server to make requests to internal se…
M Alto vulnerabilidad
10/07/2026
[CVE-2026-56279] Capgo before 12.128.2 contains an information disclosure vulnerability in the get_orgs_v7(userid) RP…
Capgo before 12.128.2 contains an information disclosure vulnerability in the get_orgs_v7(userid) RPC function that remains publicly invokable despite intended private access controls. Unauthenticated attackers can supply arbitrary user UUIDs to retrieve foreign users' organization membership, roles, management emails, and billing metadata.
M Alto vulnerabilidad
10/07/2026
[CVE-2026-56305] Capgo before 12.128.2 contains an authentication bypass vulnerability in the password change endpoin…
Capgo before 12.128.2 contains an authentication bypass vulnerability in the password change endpoint that allows attackers to change user passwords without requiring current password confirmation. Attackers with temporary session access can exploit this flaw to permanently lock out legitimate users and achieve full account takeover.
M Alto vulnerabilidad
10/07/2026
[CVE-2026-56254] In @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, the end-to-end encryption scheme distrib…
In @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, the end-to-end encryption scheme distributes the private key to each device that downloads the app. Because the public key can be derived from the private key, an attacker performing a man-in-the-middle attack or compromising the Capgo server can create a validly signed update bundle and cause devices to install an update not produced by …
M Alto vulnerabilidad
10/07/2026
[CVE-2026-29519] Lucee CFML Server versions across the 5.3.x, 6.1.x, 6.2.x, and 7.0.x release lines contain a reflect…
Lucee CFML Server versions across the 5.3.x, 6.1.x, 6.2.x, and 7.0.x release lines contain a reflected cross-site scripting vulnerability in URL path parsing that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser by embedding HTML or JavaScript payloads within the request path. Attackers can craft a malicious URL containing injected script content that i…