Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "X" — 16242 resultados ✕ Limpiar búsqueda
22,394
Total alertas
4758
Críticas
17006
Altas
8
Ransomware
1261
Esta semana
RSS
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102132] An administrative import function in Kiteworks Core did not verify that the requesting administrator…
An administrative import function in Kiteworks Core did not verify that the requesting administrator was entitled to create the privileged integration credential being imported. A delegated administrator holding a single narrowly scoped administrative permission could therefore obtain full system administrator privileges, without any action by an existing system administrator.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102120] A privilege escalation vulnerability in Kiteworks could have allowed an attacker who had already obt…
A privilege escalation vulnerability in Kiteworks could have allowed an attacker who had already obtained code execution on one node of a clustered Kiteworks deployment to run operating system commands with elevated privileges on another node of the same cluster. Insufficient input validation in an internal cluster management function let attacker-supplied values reach a privileged execution conte…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102123] A Kiteworks appliance setup interface did not confine a user-supplied file path to its intended dire…
A Kiteworks appliance setup interface did not confine a user-supplied file path to its intended directory, which could allow an unauthenticated attacker to write a file to any location writable by the affected service account, potentially compromising the integrity of the appliance or rendering it unavailable until an operator intervenes. Exploitation requires network access to the affected interf…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102125] The sandbox that isolates document conversion on a Kiteworks appliance did not fully confine the cod…
The sandbox that isolates document conversion on a Kiteworks appliance did not fully confine the code running inside it. Code already executing within that sandbox could potentially escape its confinement and act with the privileges of the service account that runs the application, which could allow an attacker in that position to read or modify application data and configuration, or to disrupt th…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102126] A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an administrator holding …
A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an administrator holding only a single, narrowly scoped delegated permission to store crafted content that later executes arbitrary JavaScript in the authenticated session of a System Administrator who views the affected page. This could have permitted the lower-privileged administrator to escalate to full administrative co…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102116] -A weakness could have allowed an authenticated Kiteworks Email Protection Gateway administrator to …
-A weakness could have allowed an authenticated Kiteworks Email Protection Gateway administrator to write a file outside its intended location and cause the application to execute it, potentially resulting in remote code execution as the underlying service account.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102117] On deployments where the remote-support capability is licensed and enabled, an authenticated System …
On deployments where the remote-support capability is licensed and enabled, an authenticated System Administrator who also possessed the key protecting the submitted data could redirect the underlying system's outbound support connection to a destination of their choosing. That destination could then have operating-system commands executed on the node and receive their output, potentially resultin…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102118] A local privilege escalation vulnerability in Kiteworks could have allowed an attacker with an exist…
A local privilege escalation vulnerability in Kiteworks could have allowed an attacker with an existing shell under a low-privileged service account to escalate to root privileges on the appliance.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102119] A path traversal weakness in an optional, non-default administrative feature allowed an authenticate…
A path traversal weakness in an optional, non-default administrative feature allowed an authenticated administrator to move files to unintended locations outside the feature's designated directory. This could potentially be leveraged to execute arbitrary code on the underlying system.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102112] A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained c…
A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance to escalate to root and run arbitrary commands with the highest privileges. Exploitation requires existing local access to that service account.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102113] A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained c…
A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance to escalate to root. A privileged routine did not safely handle a filesystem path that the lower-privileged account could influence, allowing the attacker to cause a root-owned operation to run arbitrary commands with the high…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102114] A command injection vulnerability in Kiteworks could allow a high-privileged authenticated administr…
A command injection vulnerability in Kiteworks could allow a high-privileged authenticated administrator to execute arbitrary operating-system commands as root on the affected appliance node. Successful exploitation requires an administrative account with elevated privileges.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102108] An authenticated administrator of Kiteworks Email Protection Gateway could submit a crafted serializ…
An authenticated administrator of Kiteworks Email Protection Gateway could submit a crafted serialized object to a cluster management interface that was deserialized without sufficient validation, potentially allowing arbitrary code execution in the context of the gateway service account. Exploitation requires an administrator account holding a specific queue-management privilege.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102109] A SQL injection vulnerability existed in Kiteworks Secure Data Forms, where a value derived from the…
A SQL injection vulnerability existed in Kiteworks Secure Data Forms, where a value derived from the authenticated user's stored account data was incorporated into a database query without proper sanitization. An authenticated user could potentially influence that value to inject SQL. Exploitation requires an authenticated session and applies only to deployments where a specific optional feature i…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102096] Kiteworks Core before version 9.5.0 is vulnerable to OS Command Injection that allows an authenticat…
Kiteworks Core before version 9.5.0 is vulnerable to OS Command Injection that allows an authenticated administrator to upload a configuration package whose contents were not sufficiently validated before being processed. A crafted package could cause the underlying system to execute arbitrary operating-system commands, potentially with elevated privileges, on the affected appliance.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102097] Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Remote Code Execution. Kite…
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Remote Code Execution. Kiteworks Email Protection Gateway allowed an authenticated administrator to import configuration whose contents were not sufficiently validated before being processed. A crafted submission could potentially allow arbitrary commands to be executed on the affected gateway.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102098] Kiteworks Core before version 9.5.0 is vulnerable to SQL Injection. A stored SQL injection vulnerabi…
Kiteworks Core before version 9.5.0 is vulnerable to SQL Injection. A stored SQL injection vulnerability in a Kiteworks administrative reporting feature could allow an authenticated administrator to read sensitive data from the underlying database and to affect the availability of the service. Exploitation requires an existing, authenticated administrative account with access to the affected repor…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102099] Kiteworks Core before version 9.5.0 is vulnerable to Arbitrary File Write. An improper restriction o…
Kiteworks Core before version 9.5.0 is vulnerable to Arbitrary File Write. An improper restriction of a user-supplied file path in a Kiteworks administrative export feature could allow an authenticated administrator to write a file to an arbitrary location on the underlying host, potentially leading to command execution on the appliance. Exploitation requires an existing, authenticated administrat…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102100] Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-Site Scripting. A stored cross-sit…
Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-Site Scripting. A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an authenticated user to submit content that, when later viewed by another user, executes arbitrary JavaScript in that user's authenticated session. This could be used to perform actions on the victim's behalf and may have permitted account ta…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102101] Kiteworks Core before version 9.5.0 is vulnerable to Deserialization of Untrusted Data. A deserializ…
Kiteworks Core before version 9.5.0 is vulnerable to Deserialization of Untrusted Data. A deserialization weakness in Kiteworks Core could, under certain conditions, allow crafted data to be deserialized unsafely, potentially resulting in remote code execution on the appliance. Exploitation depends on an attacker first being able to influence the affected data, so this issue is not exploitable on …