Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ui" — 3495 resultados ✕ Limpiar búsqueda
22,394
Total alertas
4758
Críticas
17006
Altas
8
Ransomware
1258
Esta semana
RSS
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84675] OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows attackers able…
OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows attackers able to control build environment variable values to execute arbitrary commands on the agent running the build.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84670] Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict the classes that can b…
Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict the classes that can be instantiated when deserializing cached performance reports stored in the build directory on the Jenkins controller, allowing attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-78689] Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list p…
Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can trigger it when an affected NGINX configuration passes an externally controlled XML namespace prefix list to that method. Both the njs and the QuickJS (qjs) engines are affected. A crafted prefix list cau…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-78222] A vulnerability exists in NGINX JavaScript where a malformed HTTP response received by ngx.fetch() c…
A vulnerability exists in NGINX JavaScript where a malformed HTTP response received by ngx.fetch() can crash an NGINX worker when trusted JavaScript reads Response.statusText. Exploitation requires control or influence over the fetched HTTP response. Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system. There is no control plane exposure; th…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-78410] A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pi…
A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode…
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-53611] Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained Go binary…
Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained Go binary that fronts a fleet of routers over SSH and exposes ping / traceroute / BGP lookups through a gRPC (ConnectRPC) API, an embedded SvelteKit web UI, and a lg-cli client. Prior to version 1.3.5, there is an OS Command Injection vulnerability resulting from an unanchored regular expression in the input…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-66842] BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrat…
BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrative user accounts through an undisclosed request to Traffic Management User Interface (TMUI). Impact: This vulnerability may allow an authenticated attacker with network access to the BIG-IP management interface to escalate privileges by creating administrative accounts on the BIG-IP system. Th…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
02/09/2026
[CVE-2026-18058] The mobile Smart Connect dashboard UI was subject to manipulation by 3rd party apps. When paired wit…
The mobile Smart Connect dashboard UI was subject to manipulation by 3rd party apps. When paired with a phishing attack, this manipulation could result in escalated privileges of an attacker within the system.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-18329] Description NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a js_access …
Description NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a js_access handler performs asynchronous request body processing and an exception is thrown during asynchronous access-control evaluation before an explicit access denial is returned. An unauthenticated attacker can exploit this vulnerability by sending a crafted HTTP request that triggers an error condition i…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-78604] Incorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent can lead to local p…
Incorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent can lead to local privilege escalation via Replace Binaries (CAPEC-642). On Windows systems where Elastic Agent is installed in unprivileged mode, resources used by the agent service are created with access controls broader than required. A local user could take advantage of this to cause the service to execute code o…
M Alto vulnerabilidad
02/09/2026
Vulnerabilidad CSRF en Simply Schedule Appointments <= 1.6.12.23 permite acciones no autorizadas
Se ha identificado una vulnerabilidad de Falsificación de Solicitud Entre Sitios (CSRF) sin autenticación en Simply Schedule Appointments en versiones hasta 1.6.12.23. Esta vulnerabilidad permite a atacantes realizar acciones no autorizadas en nombre de usuarios legítimos, afectando principalmente a empresas de servicios, clínicas y consultorías en LATAM que utilizan este plugin para gestionar citas. Con un CVSS de 8.8, representa un riesgo alto para la integridad de datos y la continuidad operativa.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-81769] Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation…
Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation. This issue affects Booking Hub: from n/a through 1.3.1.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-19219] In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog …
In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog request parameters used by the RadEditor file browser may allow an attacker who has obtained certain application encryption key material to alter the folders the file browser reads from, writes to, and uploads into, potentially resulting in remote code execution.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-18672] In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient validation of client-supplied s…
In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient validation of client-supplied state in RadImageEditor may allow an attacker to influence which file is returned by the control's image cache, potentially exposing file contents outside the intended image directories.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-81737] The FAQ Builder AYS WordPress plugin before 1.8.5 does not sanitize or escape content submitted by u…
The FAQ Builder AYS WordPress plugin before 1.8.5 does not sanitize or escape content submitted by unauthenticated visitors before storing it and outputting it in an admin area page, and the escaping it does apply is undone by a subsequent decoding step, leading to Stored XSS which will execute in the context of a logged in administrator.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
02/09/2026
[CVE-2026-19723] The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properl…
The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properly escape a value taken from the incoming request before outputting it in an inline JavaScript event handler, leading to Reflected Cross-Site Scripting which is triggered when a user interacts with the affected button. Exploitation requires the Social Media Share Buttons & Social Sharing Icons WordPr…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-19116] The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from b…
The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from being deserialized when a submitted post is reopened in its frontend editing form, allowing authenticated users with subscriber-level access and above to perform PHP Object Injection, which may lead to remote code execution when a suitable gadget chain is present on the site.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84700] PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the cl…
PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the client port plus 2000 (e.g. 11221 when the default client port 9221 is used) that does not authenticate incoming requests. Although requirepass is intended to gate replication — a slave presents it as masterauth inside its MetaSync request — only the MetaSync handler (HandleMetaSyncRequest) validates …
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84696] Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique comm…
Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over the ATA interface with absent or defeatable authentication mechanisms. Attackers can bypass the weak CRC-16 based unlock handshake or exploit builds with no VUC lock to read and write controller memory and raw flash, persisting implants across power cycles.
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-84699] Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local ac…
Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access.