Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Alto vulnerabilidad
01/10/2026
[CVE-2026-63292] Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server thro…
Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize is raised above the default. Users ar…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-63686] A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.…
A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose conversion partially succeeds then fails. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-57941] Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy…
Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-56153] Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite. This issue affects Ap…
Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-56154] Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:.…
Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...}) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-56449] Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response …
Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-48005] Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server be…
Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck . Users are recommended to upgrade to version 2.4.69, which fixes this issue.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
01/10/2026
[CVE-2026-14316] The revoked-key error path builds a human-readable failure reason using sprintf() into a heap buffer…
The revoked-key error path builds a human-readable failure reason using sprintf() into a heap buffer. The allocated buffer is too small for the final formatted message. When sprintf() writes the full message, it can write past the end of the heap allocation.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-12540] A flaw was found in Foreman. A command injection vulnerability exists in the foreman-rake errors:fet…
A flaw was found in Foreman. A command injection vulnerability exists in the foreman-rake errors:fetch_log task. The request_id parameter is passed to an underlying system command (typically grep) without adequate shell neutralization. While the task is intended to fetch specific log entries, an attacker with sudo permissions to execute this rake task can inject shell metacharacters (such as ;, ",…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-12541] A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump …
A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump and db:import_dump tasks. The application fails to properly sanitize user-supplied input in the destination parameter (during backups) and the file parameter (during imports) before passing them to a Ruby system() call for execution. An attacker with permissions to execute foreman-rake (e.g., via a …
M Alto vulnerabilidad
01/10/2026
[CVE-2026-12544] A flaw was found in Foreman. The foreman-rake initialization logic in /usr/share/foreman/config/sett…
A flaw was found in Foreman. The foreman-rake initialization logic in /usr/share/foreman/config/settings.rb contains a vulnerable code pattern where configuration data is processed through two distinct executable layers. This creates a multi-stage execution chain that allows for both Server-Side Template Injection (SSTI) and insecure deserialization. This vulnerability can lead to remote code exec…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-103921] GraphQL Tools provides utilities for building, stitching, and mocking GraphQL schemas. Prior to 1.1.…
GraphQL Tools provides utilities for building, stitching, and mocking GraphQL schemas. Prior to 1.1.35, the executor-legacy-ws buildWSLegacyExecutor() function hardcodes TLS certificate rejection off for Node.js connections to wss:// endpoints. Applications using the executor directly, or url-loader with SubscriptionProtocol.LEGACY_WS, can therefore accept an attacker-controlled certificate when a…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-12405] A flaw was found in rubygem-foreman_remote_execution. A command injection vulnerability exists in th…
A flaw was found in rubygem-foreman_remote_execution. A command injection vulnerability exists in the Red Hat Satellite API (/api/v2/job_invocations). When a job template has the effective_user property marked as overridable: true, the application fails to properly sanitize the effective_user input provided during the API request. The exploitation does not rely on the content or logic of the Job T…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-12423] A flaw was found in Foreman. The Red Hat Satellite /unattended/provision API endpoint is vulnerable …
A flaw was found in Foreman. The Red Hat Satellite /unattended/provision API endpoint is vulnerable to an authentication bypass due to a semantic logic flaw in host_verifier.rb. The application verifies the database state of a provisioning token rather than its actual presence in the incoming HTTP request. Because a host actively undergoing provisioning has an unexpired token in the database, the …
M Alto vulnerabilidad
01/10/2026
[CVE-2026-101888] The Prime Mover plugin for WordPress before 2.2.1 contains a Zip Slip path traversal vulnerability t…
The Prime Mover plugin for WordPress before 2.2.1 contains a Zip Slip path traversal vulnerability that allows authenticated administrators to write arbitrary files outside the intended extraction directory during migration ZIP import. Attackers can craft ZIP entry names with traversal sequences processed by computeExtractionParameters() and resumableZipExtractor() in utilities/PrimeMoverSystemChe…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
01/10/2026
[CVE-2026-79896] Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parse…
Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parser used by boks_portmux. A remote unauthenticated attacker can submit a malformed ClientHello and terminate boks_portmux. Although the daemon is normally restarted automatically, repeated requests can sustain the service interruption.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-46729] NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener…
NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-47360] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod…
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module.   When SessionCookieRemove changes across internal redirects, the session cookie may still be passed to a backend server. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-12627] Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability …
Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption during client response processing.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-97273] Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce <= 1.1.13 versions.
Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce