Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ni" — 7314 resultados ✕ Limpiar búsqueda
22,417
Total alertas
4761
Críticas
17025
Altas
8
Ransomware
1263
Esta semana
RSS
M Alto vulnerabilidad
22/09/2026
[CVE-2026-61685] ReactPress is a publishing system for React developers. Prior to version 3.7.0, ReactPress API list …
ReactPress is a publishing system for React developers. Prior to version 3.7.0, ReactPress API list endpoints build TypeORM `QueryBuilder` conditions using unsanitized HTTP query parameter names as SQL column identifiers (e.g. `` `article.${key}` ``). TypeORM parameterizes values but not column names, allowing unauthenticated attackers to inject SQL through crafted query string keys. Version 3.7.0…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-95819] A vulnerability has been found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca…
A vulnerability has been found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca172612c001eb39f6. Affected by this vulnerability is an unknown functionality of the file login.php. Such manipulation of the argument user/pass leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. This product utilizes a rolli…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-18123] IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to cause …
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to cause a denial of service due to the improper use of reflection with externally controlled input.
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-17472] IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to access or modify unau…
IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to access or modify unauthorized resources due to the use of wildcards in RBAC permission definitions.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-17618] IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote unauthenticated at…
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote unauthenticated attacker to view and modify sensitive information and cause a denial of service due to improper authorization.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-95814] Vaultwarden through 1.37.3 omits organization membership status validation from three cipher access-…
Vaultwarden through 1.37.3 omits organization membership status validation from three cipher access-restriction queries, allowing revoked and not-yet-confirmed members to retain read, write, delete, and attachment access to organization ciphers. Attackers with revoked or pending membership can exploit missing status filters in get_user_collections_access_flags, get_group_collections_access_flags, …
M Alto vulnerabilidad
22/09/2026
[CVE-2026-94450] Improper validation of the Destination Connection ID length in s2n-quic 1.88.0 and earlier may allow…
Improper validation of the Destination Connection ID length in s2n-quic 1.88.0 and earlier may allow an unauthenticated remote user to cause a denial of service by shutting down a server endpoint via a single crafted UDP datagram. Only server endpoints specifically configured to send Retry packets are affected. To remediate this issue, users should upgrade to version v1.89.0 or later.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
22/09/2026
[CVE-2026-76712] A vulnerability exists in the Analytics and Location Engine (ALE) that may allow for unauthorized ac…
A vulnerability exists in the Analytics and Location Engine (ALE) that may allow for unauthorized access, information disclosure, or denial of service. An unauthenticated remote attacker could exploit the vulnerable system by sending specially crafted input or intercepting network communications. Successful exploitation could result in the disclosure of sensitive information, bypass of security co…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-76715] A vulnerability in an administrative component of Analytics and Location Engine (ALE) is vulnerable …
A vulnerability in an administrative component of Analytics and Location Engine (ALE) is vulnerable to a man-in-the-middle (MitM) attack. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on the affected appliance.
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-76708] A vulnerability exists in the Analytics and Location Engine (ALE) where the application and underlyi…
A vulnerability exists in the Analytics and Location Engine (ALE) where the application and underlying operating system use default, hard-coded credentials for several administrative and system accounts. An unauthenticated remote attacker could exploit this vulnerability by attempting to log in using these known default credentials. Successful exploitation could result in an attacker gaining unau…
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-76709] A vulnerability exists in the internal administrative component of Analytics and Location Engine (AL…
A vulnerability exists in the internal administrative component of Analytics and Location Engine (ALE). Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to gain unauthorized write access to the file system with elevated privileges, potentially resulting in full system compromise.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-28325] SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code exec…
SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is configured to use a specific communication mode.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-95861] A malicious actor with access to the network could exploit an Uncontrolled Recursion vulnerability f…
A malicious actor with access to the network could exploit an Uncontrolled Recursion vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-95862] A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability foun…
A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-77544] A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability foun…
A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
22/09/2026
[CVE-2026-77555] A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability foun…
A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-77556] A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found…
A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-77558] A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found…
A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-75744] Adobe Experience Manager Forms JEE is affected by a stored Cross-Site Scripting (XSS) vulnerability …
Adobe Experience Manager Forms JEE is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's accoun…
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-75682] Adobe Connect is affected by an Improper Neutralization of Special Elements used in an SQL Command (…
Adobe Connect is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary SQL commands, potentially gaining elevated access or control over the victim's account or session. Exploita…