Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 47 min
Buscando: "X" — 16249 resultados ✕ Limpiar búsqueda
22,395
Total alertas
4758
Críticas
17006
Altas
8
Ransomware
1253
Esta semana
RSS
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-79538] metatool-ai MetaMCP up to and including 2.4.22 is vulnerable to Code Execution in the internal MCP i…
metatool-ai MetaMCP up to and including 2.4.22 is vulnerable to Code Execution in the internal MCP inspector proxy endpoint GET /mcp-proxy/server/stdio (createTransport, STDIO branch, routers/mcp-proxy/server.ts).
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-76721] Buffer overflow vulnerability exists in the affected interface of HPE Networking Instant ON that cou…
Buffer overflow vulnerability exists in the affected interface of HPE Networking Instant ON that could allow an unauthenticated remote attacker to run arbitrary code on the underlying host. Successful exploitation could allow an attacker to execute arbitrary code as a privileged user on the underlying operating system.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-76722] Uncontrolled Format string vulnerabilities exist in the affected interface of HPE Networking Instant…
Uncontrolled Format string vulnerabilities exist in the affected interface of HPE Networking Instant ON APs that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation could result in a Denial-of-service or potential remote code execution.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-76723] Buffer overflow vulnerabilities exist in the affected interface of HPE Networking Instant ON APS tha…
Buffer overflow vulnerabilities exist in the affected interface of HPE Networking Instant ON APS that could allow an unauthenticated adjacent attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-76724] A command injection vulnerability exists in CLI of the affected HPE Networking Instant ON APs that c…
A command injection vulnerability exists in CLI of the affected HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to perform command injection by sending specially crafted packets. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-76725] A vulnerability has been identified in a management protocol of HPE Networking Instant ON APs that c…
A vulnerability has been identified in a management protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing authentication controls. Successful exploitation could result in a complete bypass of security restrictions, potentially leading to remote code execution with elevated privileges.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-76726] An authentication bypass vulnerability in the API endpoint of HPE Networking Instant ON could allow …
An authentication bypass vulnerability in the API endpoint of HPE Networking Instant ON could allow an unauthenticated remote attacker to bypass network access controls if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to obtain unauthorized access to restricted networks.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
29/09/2026
[CVE-2026-76727] Command injection vulnerabilities exist in the affected interface of HPE Networking Instant ON that …
Command injection vulnerabilities exist in the affected interface of HPE Networking Instant ON that could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-76728] A vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated re…
A vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to conduct a server-side request forgery (SSRF) attack. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-61519] Liberu CRM 0.9.1 before 10.0.0 contains a broken access control vulnerability that allows any user h…
Liberu CRM 0.9.1 before 10.0.0 contains a broken access control vulnerability that allows any user holding a pending team invitation to invite additional attacker-controlled accounts with elevated privileges by exploiting a flawed authorization predicate in TeamPolicy::addTeamMember() that grants invitation rights based solely on the existence of a pending invitation email match. Attackers can sen…
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-39117] An issue in AltumCode 66Uptime before v.54.0.0 and 66Uptime ping-servers plugin before v.2.0.0 allow…
An issue in AltumCode 66Uptime before v.54.0.0 and 66Uptime ping-servers plugin before v.2.0.0 allows a remote attacker to execute arbitrary code via the index.php
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-53988] Dockhand before 1.0.40 contains an authentication bypass vulnerability in its git webhook endpoints …
Dockhand before 1.0.40 contains an authentication bypass vulnerability in its git webhook endpoints that allows unauthenticated remote attackers to trigger arbitrary stack redeployments by exploiting a null webhook secret guard condition. Attackers can enumerate sequential stack IDs and send unsigned webhook requests to force git clone and docker compose operations, enabling denial of service or, …
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102875] VLC media player before 3.0.24 contains a path traversal vulnerability in the skins2 ThemeLoader tha…
VLC media player before 3.0.24 contains a path traversal vulnerability in the skins2 ThemeLoader that fails to validate member names in .vlt skin archives. Attackers can craft malicious skin files with path traversal sequences to write arbitrary files with VLC user privileges, enabling code execution through Lua script injection.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102878] mcp-chrome-bridge through 1.0.31 contains an origin validation error in the native-server HTTP API t…
mcp-chrome-bridge through 1.0.31 contains an origin validation error in the native-server HTTP API that allows attackers to bypass CORS restrictions. Attackers can craft malicious web pages that make cross-origin requests to the local server and invoke browser automation tools including script execution, page content reading, and screenshot capture.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102327] Incorrect authorization in WebView in Google Chrome on on Android prior to 154.0.8037.92 allowed a r…
Incorrect authorization in WebView in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102328] Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute ar…
Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-102331] Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote atta…
Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102321] Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute ar…
Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102323] Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute ar…
Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102324] Use after free in PictureInPicture in Google Chrome prior to 154.0.8037.92 allowed a remote attacker…
Use after free in PictureInPicture in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)