Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ni" — 4231 resultados ✕ Limpiar búsqueda
13,696
Total alertas
3097
Críticas
10327
Altas
8
Ransomware
1751
Esta semana
RSS
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72543] An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows una…
An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to retrieve any contact record via the getcontact Parse cloud function. The function executes with useMasterKey and performs no authentication or authorization checks before returning the requested contact object. An attacker can enumerate and read all contact records i…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-50237] A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog …
A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant can plant a ProjectHelmChartRepository with an arbitrary URL that the console pod fetches server-side, bypassing tenant egress restrictions. Combined with catalog metadata poisoning and admin-mediated chart installation, this enables privilege escalation.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72533] An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privi…
An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypass Docker proxy authorization checks via non-canonical URL normalization, defeating all authorization middleware. The proxy endpoint fails to normalize request paths before applying access controls, allowing crafted requests to be interpreted differently by the proxy and the autho…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72534] A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an atta…
A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token to gain superuser privileges by provisioning a SCIM group that matches an existing administrator group by name. The SCIM group ingest function adopts any existing group by name and replaces its membership without validating the source scope against t…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72536] A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remo…
A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to manipulate any tenant Stripe subscription via the stripeCreateIntent GraphQL mutation. The mutation lacks authentication and authorization checks, exposing Stripe payment intent creation to unauthenticated callers. An attacker can create payment intents and alter billing for any tena…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72537] A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an atta…
A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token to take over any user account including superusers by provisioning a SCIM user that matches an existing local user by username. The SCIM user ingest function adopts pre-existing local accounts by username without validating scope boundaries. An attac…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72693] `openvt -u` is intended to identify the owner of the current VT and then execute `login` as that use…
`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the documented `kbrequest`/init usage, the ownership test in `authenticate_user()` relies on `stat("/proc//fd/0")`. `stat()` on `/proc//fd/0` follows the symlink to the underlying TTY device node. As a result, `buf.st_uid` reflects the owner of the TTY node …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
11/08/2026
[CVE-2026-15562] A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or …
A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or :4447) and complete an Upgrade: jboss-remoting handshake can cause OOM errors that degrade requests server-wide, leading to denial of service.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-15565] A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint witho…
A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint without authentication on any @ServerEndpoint class that has any @OnMessage method. This allows an attacker to cause Denial of Service attack without authentication and using only a standard WebSocket handshake.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-15555] A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicat…
A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via the JBoss Marshalling River unmarshaller with no class filtering — enabling RCE via deserialization gadget chains on every cluster node.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-15556] A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion …
A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML response and auth as any principal with any roles on the protected application.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-15561] A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and cou…
A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the listener, and achieving Denial of Service.
M Medio vulnerabilidad
11/08/2026
CVE-2026-63512 Microsoft SharePoint Server Tampering Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-63512 Microsoft SharePoint Server Tampering Vulnerability. Tipo: Manipulación (Tampering).
M Medio vulnerabilidad
11/08/2026
CVE-2026-61928 Windows Hello Tampering Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-61928 Windows Hello Tampering Vulnerability. Tipo: Manipulación (Tampering).
M Medio vulnerabilidad
11/08/2026
CVE-2026-62702 Windows Graphics Kernel Denial of Service Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-62702 Windows Graphics Kernel Denial of Service Vulnerability. Tipo: Denegación de Servicio (DoS).

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
11/08/2026
CVE-2026-62699 Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-62699 Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution Vulnerability. Tipo: Ejecución Remota de Código (RCE).
M Medio vulnerabilidad
11/08/2026
CVE-2026-62750 Windows HTTP Protocol Stack Tampering Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-62750 Windows HTTP Protocol Stack Tampering Vulnerability. Tipo: Manipulación (Tampering).
R Medio vulnerabilidad
11/08/2026
CVE-2026-62912 Microsoft Exchange Server Denial of Service Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-62912 Microsoft Exchange Server Denial of Service Vulnerability. Tipo: Denegación de Servicio (DoS).
M Medio vulnerabilidad
11/08/2026
CVE-2026-65785 Windows DHCP Client Denial of Service Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-65785 Windows DHCP Client Denial of Service Vulnerability. Tipo: Denegación de Servicio (DoS).
M Medio vulnerabilidad
11/08/2026
CVE-2026-68819 Windows Network File System Denial of Service Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-68819 Windows Network File System Denial of Service Vulnerability. Tipo: Denegación de Servicio (DoS).