Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ui" — 3495 resultados ✕ Limpiar búsqueda
22,395
Total alertas
4758
Críticas
17006
Altas
8
Ransomware
1254
Esta semana
RSS
M Alto vulnerabilidad
28/08/2026
[CVE-2026-14558] The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions …
The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions and deserialises user-controlled post metadata when rendering submitted posts, allowing users with Editor-level access and above to inject arbitrary PHP objects, which can lead to remote code execution when a suitable POP chain is present on the site.
G Medio vulnerabilidad
28/08/2026
Chromium: CVE-2026-78893 Information leak in QUIC
Microsoft publica advisory de seguridad: Chromium: CVE-2026-78893 Information leak in QUIC.
G Medio vulnerabilidad
28/08/2026
Chromium: CVE-2026-78912 UI misrepresentation in Browser
Microsoft publica advisory de seguridad: Chromium: CVE-2026-78912 UI misrepresentation in Browser.
G Medio vulnerabilidad
28/08/2026
Chromium: CVE-2026-78966 Externally controlled reference in QUIC
Microsoft publica advisory de seguridad: Chromium: CVE-2026-78966 Externally controlled reference in QUIC.
G Medio vulnerabilidad
28/08/2026
Chromium: CVE-2026-78974 UI misrepresentation in Linux Toolkit Theming
Microsoft publica advisory de seguridad: Chromium: CVE-2026-78974 UI misrepresentation in Linux Toolkit Theming.
G Medio vulnerabilidad
28/08/2026
Chromium: CVE-2026-79009 UI misrepresentation in UI
Microsoft publica advisory de seguridad: Chromium: CVE-2026-79009 UI misrepresentation in UI.
G Medio vulnerabilidad
28/08/2026
Chromium: CVE-2026-79011 UI misrepresentation in Browser
Microsoft publica advisory de seguridad: Chromium: CVE-2026-79011 UI misrepresentation in Browser.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
G Medio vulnerabilidad
28/08/2026
Chromium: CVE-2026-79022 UI misrepresentation in Transactions Platform
Microsoft publica advisory de seguridad: Chromium: CVE-2026-79022 UI misrepresentation in Transactions Platform.
G Medio vulnerabilidad
28/08/2026
Chromium: CVE-2026-79098 UI misrepresentation in PermissionElement
Microsoft publica advisory de seguridad: Chromium: CVE-2026-79098 UI misrepresentation in PermissionElement.
G Medio vulnerabilidad
28/08/2026
Chromium: CVE-2026-79108 UI misrepresentation in Web Authentication (Passkeys & Security Keys)
Microsoft publica advisory de seguridad: Chromium: CVE-2026-79108 UI misrepresentation in Web Authentication (Passkeys & Security Keys).
M Alto vulnerabilidad
28/08/2026
[CVE-2026-18324] The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vuln…
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Rich-Text Textarea Field in all versions up to, and including, 1.57.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a use…
M Alto vulnerabilidad
28/08/2026
[CVE-2026-77977] Ebyte gateway product's vendor configuration utility does not require authentication before allowin…
Ebyte gateway product's vendor configuration utility does not require authentication before allowing certain disruptive administrative actions when default credentials remain configured. An unauthenticated attacker on the adjacent network could reboot the device or restore factory settings, resulting in a loss of configuration and service availability.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-75418] A path traversal vulnerability exists in the built-in preview/development web server of Lektor <3.3.…
A path traversal vulnerability exists in the built-in preview/development web server of Lektor
M Alto vulnerabilidad
28/08/2026
[CVE-2026-54083] Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints an…
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. The  ip-customblock  active response script contains a path traversal vulnerability that lets an attacker create or delete arbitrary files on the filesystem as root. The script builds a file path by concatenating the  srcip  field taken from alert JSON directly onto the fixed  /ip…
M Alto vulnerabilidad
28/08/2026
[CVE-2026-54330] Ceph is an open-source distributed storage platform providing object, block, and file storage. In ve…
Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Ceph Object Gateway (RGW) SigV4 handler does not reject requests that carry x-amz-* headers absent from the signed header set, allowing anyone holding a presigned URL to attach arbitrary unsigned x-amz-* headers that RGW will honor. AWS S3 requires every x-amz-…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
27/08/2026
[CVE-2026-81730] Dolibarr 9.0.0 through 23.0.4 saves inbound email attachments under the name supplied in the message…
Dolibarr 9.0.0 through 23.0.4 saves inbound email attachments under the name supplied in the message's MIME headers without reducing it to a safe basename. The global saveAttachment() in htdocs/emailcollector/lib/emailcollector.lib.php builds $filepath = $path . $filename . '.' . $ext and hands it to file_put_contents(), and the private saveAttachment() in htdocs/emailcollector/class/emailcollecto…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-81529] Improper neutralization of delimiters in connection-URL construction allows connection-option inject…
Improper neutralization of delimiters in connection-URL construction allows connection-option injection in the MongoDB C# Driver. When an application passes untrusted text into the driver's connection-URL builder and round-trips the builder back into a client configuration, the untrusted text is serialized without neutralizing the URL/option delimiters and is then re-parsed as authoritative connec…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-81522] A weakness in the MongoDB C++ Driver's handling of caller-supplied namespace identifiers allows spec…
A weakness in the MongoDB C++ Driver's handling of caller-supplied namespace identifiers allows special characters embedded in those identifiers. An application that builds a namespace identifier from untrusted input without validating it may therefore have its operation directed at a different target than intended. This can result in limited unauthorized read and write access to data belonging to…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-54721] Silverstripe UserForms provides a visual form builder for the Silverstripe CMS. From 6.0.0 until 6.4…
Silverstripe UserForms provides a visual form builder for the Silverstripe CMS. From 6.0.0 until 6.4.9, 7.0.7, and 7.1.1, the userform email recipient subject field in the CMS accepts a specially crafted payload that can be interpreted as executable server-side code. An authenticated CMS user with permission to configure a UserForms email recipient can use the subject field to run arbitrary code o…
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-81735] startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::…
startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was given, so startSseAndStreamableHttpMcpServer bound the Streamable HTTP and SSE MCP transports to every interface, and its authentication middleware was optional: middlewares are applied only when a caller supplies them. The @agent-infra/mcp-server-commands and @agent-infra/mcp-ser…