Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1045
Esta semana
RSS
M Alto vulnerabilidad
17/09/2026
[CVE-2026-76834] b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901 where the s…
b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901 where the serialized-array object check in param_check_serialized_array() fails to reject payloads with negative integer array keys. Unauthenticated attackers can submit crafted serialized PHP objects via POST requests to htsrv/call_plugin.php that bypass validation and reach unserialize(), instantiating arbit…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92785] Angel through 3.3.0 deserializes untrusted setAlgoMetrics payload using Kryo without class registrat…
Angel through 3.3.0 deserializes untrusted setAlgoMetrics payload using Kryo without class registration or allowlist validation. Unauthenticated network attackers can instantiate arbitrary classes or exhaust coordinator memory by sending crafted serialized objects to the master RPC endpoint.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-20340] A vulnerability in Cisco Secure FMC Software could allow an authenticated, remote attacker to execut…
A vulnerability in Cisco Secure FMC Software could allow an authenticated, remote attacker to execute arbitrary commands at the root privilege level. This vulnerability is due to unsecured deserialization of web-management user-controlled data. An attacker could exploit this vulnerability by authenticating to the device and sending a crafted HTTP payload. A successful exploit could allow t…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-20341] A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software cou…
A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software could allow an authenticated, remote attacker to obtain root privileges. This vulnerability is due to unsecured deserialization of untrusted data over the sftunnel management connection. An attacker could exploit this vulnerability by sending crafted sftunnel remote procedure calls (RPCs). A su…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-20211] A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary comm…
A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid high-privileged administrative credentials. This vulnerability is due to insecure deserialization of Java objects by the affected software. An attacker could exploit this vul…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-20242] A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (…
A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary commands as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream from a host that is configured in the external database access list. An attacke…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-20307] A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, rem…
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least low-privileged administrative credentials. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream.…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-70416] Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerabil…
Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
M Crítico vulnerabilidad
16/09/2026
[CVE-2025-59953] LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in ver…
LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior to version 0.10.2, the LMdeploy implements an rpc server (AsyncRPCServer in zmq_rpc.py) for supporting the RPC communications. In its core functionality call_and_response(), I found it will directly use the pickles.loads() to deserialize the received messages without any sanitiz…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-91939] Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes r…
Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can exploit PHP object injection through crafted serialized payloads to trigger gadget chains and achieve database manipulation or code execution.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-11729] IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3…
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code in client applications due to unsafe deserialization that enables JNDI injection attacks.
M Crítico vulnerabilidad
15/09/2026
[CVE-2023-54398] Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.fi…
Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageServlet component that allows remote unauthenticated attackers to execute arbitrary OS commands by sending a serialized payload via POST request. Attackers can exploit the doAction method, which passes raw HTTP request body data directly to ObjectInputStream.readObject() without f…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-13293] IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3…
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote authenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-17156] IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a …
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to insecure deserialization.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-17416] IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a …
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to insecure deserialization.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
14/09/2026
[CVE-2026-61701] Laravel MagicLink creates links for authentication without a password or for accessing private conte…
Laravel MagicLink creates links for authentication without a password or for accessing private content. From 2.0.0 until 2.25.1, MagicLink stores serialized action objects in the magic_links.action database column and deserializes them through src/MagicLink.php and src/Actions/ResponseAction.php without sufficient integrity protection, while an unsafe legacy unserialize() fallback remains reachabl…
M Crítico vulnerabilidad
14/09/2026
Vulnerabilidad crítica de ejecución remota de código en LightLLM hasta versión 1.2.0
LightLLM versiones anteriores a 1.2.1 contiene una vulnerabilidad de ejecución remota de código (RCE) en el endpoint WebSocket /visual_register del Config Server sin autenticación. Un atacante con acceso a la red puede enviar un payload malicioso serializado con método __reduce__ a pickle.loads() para ejecutar código arbitrario con privilegios del proceso Config Server. Este riesgo afecta directamente a infraestructuras de IA/ML en empresas de México y LATAM que ejecuten LightLLM en entornos de producción o desarrollo expuestos a la red interna o internet.
M Alto vulnerabilidad
13/09/2026
Vulnerabilidad alta en ESPnet permite ejecución arbitraria de código en modelos entrenados
ESPnet anterior a versión 202609 deserializa puntos de control de modelos preentrenados usando torch.load sin validación (weights_only=False), permitiendo ejecución de código arbitrario desde archivos maliciosos. Atacantes pueden crear archivos de punto de control comprometidos que ejecutan código durante la carga en procesos de inicialización o ajuste fino, comprometiendo sistemas de procesamiento de voz e IA en empresas LATAM que dependan de esta librería.
M Crítico vulnerabilidad
12/09/2026
Vulnerabilidad crítica de ejecución remota de código en The Events Calendar para WordPress hasta versión 6.17.4
The Events Calendar plugin para WordPress es vulnerable a ejecución remota de código (RCE) en todas las versiones hasta 6.17.4. La falla reside en la función is_safe_widget_instance que puede ser eludida mediante métodos mágicos de PHP durante el pre-parseo, permitiendo a atacantes no autenticados ejecutar código arbitrario. Empresas en LATAM que operan sitios WordPress con este plugin están expuestas a compromisos críticos de integridad y disponibilidad.
M Alto vulnerabilidad
12/09/2026
Vulnerabilidad alta de inyección de objetos PHP en plugin Tutor LMS para WordPress
El plugin Tutor LMS (versiones ≤4.0.7) contiene una vulnerabilidad de inyección de objetos PHP en el manejador AJAX `tutor_save_withdraw_account` que permite a atacantes no autenticados ejecutar código mediante el parámetro `withdraw_method_field`. Afecta principalmente a plataformas de educación en línea y cursos corporativos en LATAM que dependen de este plugin en WordPress. El riesgo es alta (CVSS 8.8) al carecer de validación de capacidades/roles, confiando solo en nonce.