Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 48 min
Buscando: "Ui" — 3495 resultados ✕ Limpiar búsqueda
22,395
Total alertas
4758
Críticas
17006
Altas
8
Ransomware
1253
Esta semana
RSS
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-77542] A malicious actor with access to the network and high privileges could exploit an Improper Input Val…
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UID Enterprise Agent to execute a Command Injection on the host device.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-80348] TarsWeb enforces its per-application roles by calling AuthService from individual controller methods…
TarsWeb enforces its per-application roles by calling AuthService from individual controller methods, and four methods in app/controller/patch/PatchController.js make no such call. uploadAndPublish accepts a package upload and then builds and dispatches a deployment task to every server matching the supplied application and module name, while its sibling uploadPatchPackage, which only stores the p…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-19042] A command injection vulnerability in TeamViewer Full Client and Host for Linux prior to version 15.8…
A command injection vulnerability in TeamViewer Full Client and Host for Linux prior to version 15.81.5 allows a remote attacker to execute arbitrary commands in the context of the current user via a specially crafted URL sent through the out-of-session chat feature. Exploitation requires user interaction by clicking the malicious link.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-18331] The Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More plugin …
The Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'frm_user_id' parameter in all versions up to, and including, 6.33.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will …
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-18431] The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and inclu…
The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is installed and active in versions up to, and including, 3.16. This is due to a chain of authorization and input validation weaknesses across the two components that makes it possible for unauthenticated attackers to write attacker-controlled files to the s…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-75797] The AI Engine WordPress plugin before 3.7.2 does not confine a caller-supplied URL when mapping it …
The AI Engine WordPress plugin before 3.7.2 does not confine a caller-supplied URL when mapping it to a local filesystem path before reading the file and forwarding its contents to an external service, allowing users with a subscriber-level account to read arbitrary files from the server and exfiltrate them off-host. Reaching the issue at subscriber level requires a non-default public API feature…
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-58096] LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the…
LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717. Undersized options would trigger an out-of-bounds write. A malicious PPP peer can exploit CVE-2026-58095 and CVE-2026-58096 to crash ppp(8) or potentially execute arbitrary code as root.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
26/08/2026
[CVE-2026-58093] The TIOCSCTTY ioctl handler drops the tty lock in order to acquire the process tree lock. After rea…
The TIOCSCTTY ioctl handler drops the tty lock in order to acquire the process tree lock. After reacquiring the tty lock, the handler did not revalidate the state of the terminal, and could proceed to link a terminal that was concurrently being destroyed to the calling process' session. An unprivileged local user can exploit this race condition to escalate privileges.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-80191] GROWI applies its page-viewer permission check to attachment requests only when the request carries …
GROWI applies its page-viewer permission check to attachment requests only when the request carries an authenticated user. retrieveAttachmentFromIdParam in apps/app/src/server/routes/attachment/get.ts guards the check with a condition requiring the user to be non-null, so a request that carries no session skips the check entirely and the handler returns the file. The routes reached this way, /atta…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-80193] Kimai before 2.62.0 fails to validate create_other_timesheet permission in the QuickEntry controller…
Kimai before 2.62.0 fails to validate create_other_timesheet permission in the QuickEntry controller when creating new timesheets. Authenticated users with view_other_timesheet and edit_other_timesheet permissions can create timesheet records for team members by submitting the QuickEntry form, bypassing authorization checks enforced elsewhere.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-58089] When a process calls execve(2) to execute a setuid or setgid image, hwpmc(4) is supposed to detach P…
When a process calls execve(2) to execute a setuid or setgid image, hwpmc(4) is supposed to detach PMCs owned by unprivileged processes. An inverted check meant that this scenario was not handled properly. An unprivileged local user who has attached PMCs to a process can continue monitoring it after the process executes a setuid or setgid binary, contrary to the intended policy.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-58091] The implementation of this ioctl attempts to acquire locks on all channels in a sync group. If lock…
The implementation of this ioctl attempts to acquire locks on all channels in a sync group. If locking a channel would block, it releases the sync group list lock and sleeps. Upon reawakening, it is possible that the sync group structure is freed, but the implementation did not handle this possibility. On a system with a multiple audio devices, an unprivileged local user can exploit this use-a…
M Crítico vulnerabilidad
25/08/2026
Vulnerabilidad crítica de desbordamiento de búfer en TOTOLINK N600R 4.3.0cu.7647_B20210106
Se ha identificado una vulnerabilidad de desbordamiento de búfer en pila (stack-based buffer overflow) en el controlador CGI del router TOTOLINK N600R versión 4.3.0cu.7647_B20210106. La falla reside en la función setSystemConfig del archivo /cgi-bin/cstecgi.cgi y puede ser explotada remotamente manipulando el parámetro Hostname. Con CVSS 10.0, esta vulnerabilidad permite ejecución de código remoto sin autenticación y afecta a equipos de red en empresas, ISPs y centros de datos en toda Latinoamérica.
M Alto vulnerabilidad
25/08/2026
Inyección de comandos alta en TOTOLIK N600R 4.3.0cu.7647_B20210106
Se detectó una vulnerabilidad de inyección de comandos en routers TOTOLINK N600R versión 4.3.0cu.7647_B20210106 a través del parámetro ntp_server en /cgi-bin/cstecgi.cgi. Un atacante remoto puede ejecutar comandos arbitrarios sin autenticación, comprometiendo completamente el dispositivo. Esta vulnerabilidad afecta especialmente a PyMEs y centros de datos en LATAM que usan estos equipos como punto de acceso o pasarela de red.
M Alto vulnerabilidad
25/08/2026
Vulnerabilidad alta de buffer overflow en BlueZ afecta stack Bluetooth de Linux
Una vulnerabilidad de desbordamiento de búfer en la pila Bluetooth de Linux (BlueZ) permite a atacantes remotos dentro del rango de radio enviar paquetes Extended Inquiry Response (EIR) malformados que causan bloqueos del servicio bluetoothd. Afecta servidores Linux, dispositivos IoT y sistemas embebidos comunes en infraestructura LATAM, con potencial de denegación de servicio y ejecución de código remoto.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
25/08/2026
Vulnerabilidad crítica de traversal de directorios en DB-GPT permite ejecución de código remoto
DB-GPT construye rutas de destino para habilidades cargadas usando nombres de archivo sin validación, permitiendo ataques de traversal de directorios. Un atacante puede escribir archivos fuera del directorio designado e inyectar código malicioso. Afecta infraestructuras de IA/ML en empresas mexicanas y latinoamericanas que utilizan esta plataforma para procesamiento de datos.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-79245] Use after free in UI in Google Chrome prior to 152.0.7977.65 allowed a local attacker who had compro…
Use after free in UI in Google Chrome prior to 152.0.7977.65 allowed a local attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)
M Alto vulnerabilidad
25/08/2026
[CVE-2026-79183] Use after free in Accessibility in Google Chrome prior to 152.0.7977.65 allowed a remote attacker le…
Use after free in Accessibility in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High)
M Alto vulnerabilidad
25/08/2026
[CVE-2026-74932] The WP Fastest Cache WordPress plugin before 1.5.1 does not validate the Host header before using it…
The WP Fastest Cache WordPress plugin before 1.5.1 does not validate the Host header before using it to build the URLs of the asset files it embeds in the pages it caches, and does not include that header in the cache key, allowing unauthenticated attackers to poison cached pages with references to a server they control and have arbitrary JavaScript run for every subsequent visitor.
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-45018] Chainlit is a Python framework for building production-ready conversational AI applications. From 2.…
Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint without requiring authentication. For stdio transport, the endpoint accepts a user-controlled fullCommand string. The validate_mcp_command() function in backend/chai…