Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ui" — 3495 resultados ✕ Limpiar búsqueda
22,394
Total alertas
4758
Críticas
17006
Altas
8
Ransomware
1258
Esta semana
RSS
M Alto vulnerabilidad
03/09/2026
[CVE-2026-64200] There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied …
There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read a past the end of an allocated heap buffer during string conversion.  Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-64195] There is an out-of-bounds write vulnerability in DASYLab due to lack of proper validation of user-su…
There is an out-of-bounds write vulnerability in DASYLab due to lack of proper validation of user-supplied data. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-64196] There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied…
There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated heap. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-83959] Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in…
Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
G Medio vulnerabilidad
03/09/2026
Chromium: CVE-2026-84356 UI misrepresentation in FullScreen
Microsoft publica advisory de seguridad: Chromium: CVE-2026-84356 UI misrepresentation in FullScreen.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-84847] Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions.
Unauthenticated Broken Access Control in Quick Event Manager
M Alto vulnerabilidad
03/09/2026
[CVE-2026-84848] Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager <= 9.17 versions.
Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
03/09/2026
[CVE-2026-81776] Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 3.8.8 versions.
Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX
M Alto vulnerabilidad
03/09/2026
[CVE-2026-83961] ColdFusion is affected by an Improper Authentication vulnerability that could result in privilege es…
ColdFusion is affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain limited read and write access. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-55658] Gardens v2 is a modular governance framework that enables communities to create and manage multiple …
Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. In 3e595f3 and prior, when a streaming proposal is funded, the cluster of streaming contracts moves real pool funds into the proposal's StreamingEscrow to back the Superfluid constant flow agreement (the CFA deposit, plus a 0.5 per…
M Alto vulnerabilidad
03/09/2026
[CVE-2026-80741] In the Linux kernel, the following vulnerability has been resolved: drm/log: Fix out-of-bounds read…
In the Linux kernel, the following vulnerability has been resolved: drm/log: Fix out-of-bounds read on empty message length drm_log_draw_kmsg_record() accesses s[len - 1] to strip the trailing newline, but len is unsigned int. If len is 0, the subtraction wraps to UINT_MAX, causing an out-of-bounds read. Add an early return when len is 0.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-76642] util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running …
util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation…
M Alto vulnerabilidad
03/09/2026
Vulnerabilidad en fast-uri permite validación incorrecta de autoridades en URL
fast-uri acepta hosts con corchetes de autoridad desbalanceados o mal posicionados sin generar error, lo que permite que URLs malformadas se procesen incorrectamente. Esto afecta aplicaciones Node.js que utilizan esta librería para parsear URLs, potencialmente permitiendo evasión de validaciones de seguridad en servidores web, proxies y clientes HTTP. El riesgo es alta en empresas LATAM que procesan URLs no confiables sin validación adicional.
M Crítico vulnerabilidad
02/09/2026
Vulnerabilidad crítica en Submariner: inyección de configuración en modo cert-auth
Se identificó una falla en Submariner que permite inyección de configuración arbitraria en modo autenticación por certificados. Un cluster malicioso puede explotar esta vulnerabilidad publicando un CableName con saltos de línea y directivas de ipsec.conf sin validación previa, comprometiendo la seguridad de redes híbridas y multi-cluster. El impacto afecta directamente a empresas en LATAM con infraestructuras Kubernetes distribuidas en cloud público y privado.
M Crítico vulnerabilidad
02/09/2026
Vulnerabilidad crítica en Joro framework: exposición de API local sin autenticación
Joro, un framework de pruebas web, presenta una vulnerabilidad crítica (CVSS 9.6) en versiones anteriores a 1.1.1 que expone una API local sin autenticación en 127.0.0.1:9090 con política CORS permisiva. Un atacante puede ejecutar JavaScript malicioso desde cualquier sitio visitado para cargar plugins nativos y comprometer completamente el sistema. Esta exposición afecta principalmente a equipos de seguridad y desarrolladores que utilizan Joro para análisis de aplicaciones web en infraestructuras empresariales de LATAM.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
02/09/2026
[CVE-2026-52831] Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.4…
Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.4, the Nuclio controller builds a curl invocation string for each cron trigger and stores it as the args of a Kubernetes CronJob container (/bin/sh, -c, ). Two fields in the trigger specification flow into this string without adequate sanitization: event.headers keys and event.body. This iss…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-52833] Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5…
Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5, Nuclio's Java runtime generates a build.gradle file during function builds using Go's text/template package. The template renders runtimeAttributes.repositories[] values with the {{ . }} action, which performs no escaping. An attacker can embed a closing brace (}) to break out of the repositories …
M Alto vulnerabilidad
02/09/2026
[CVE-2026-53635] Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commi…
Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 59bb6d6, the view function set_course_mode_price() at lms/djangoapps/instructor/views/instructor_dashboard.py:430 is decorated only with @login_required and performs no course-level permission check. Any authenticated user — including a learner account with zero course roles — can issue a single P…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84837] A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing th…
A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing the path or filename of a tarball processed by `rpmbuild -t*` to include shell metacharacters. This is particularly relevant in automated build or continuous integration (CI) workflows that ingest externally supplied artifact names. Successful exploitation allows for arbitrary command execution with t…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84838] A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to e…
A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to execute arbitrary commands. This occurs when rpmuncompress processes a specially crafted archive filename containing shell metacharacters, which are not properly escaped before being passed to shell command strings. Successful exploitation requires user interaction, where a user or automated workflow…