Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 43 min
Buscando: "Nsa" — 406 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-88869] AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scriptin…
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the AD_Server plugin's log.php endpoint that fails to escape the label parameter before storage. An unauthenticated attacker can inject malicious HTML through the label parameter, which is later rendered unsanitized in the admin Ad Types report using jQuery .html(), allowing execu…
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-77770] The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does…
The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validated transaction before deleting site options whose names come from unauthenticated request input, allowing any visitor to delete arbitrary options, which can lock every administrator out of the dashboard or deactivate every miniOrange 2FA WordPress plugin before 6.3.1, miniOran…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-78623] The Okta Access Gateway does not sanitize SAML assertion values before interpolating them into datab…
The Okta Access Gateway does not sanitize SAML assertion values before interpolating them into database queries in the advanced mode datastore configuration. The unsanitized values are substituted directly into the query string prior to preparation, resulting in unintended SQL execution against the configured backend database.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-73316] XenForo before 2.3.13 contains a payment replay vulnerability in the PayPal REST payment provider th…
XenForo before 2.3.13 contains a payment replay vulnerability in the PayPal REST payment provider that allows attackers to process the same webhook payload multiple times by exploiting a missing duplicate transaction ID check. Attackers can replay a valid webhook payload to trigger duplicate payment events, resulting in repeated subscription activations and unauthorized account upgrades.
M Alto vulnerabilidad
08/09/2026
Vulnerabilidad alta en PX4 Autopilot 1.17.0 y anteriores: use-after-free en módulo load_mon
PX4 Autopilot versiones hasta 1.17.0 contiene una vulnerabilidad use-after-free en el módulo load_mon que permite a atacantes ejecutar comandos maliciosos a través de shells PXH o MAVLink, causando corrupción de memoria. Esta falla afecta directamente sistemas de vehículos autónomos, drones industriales y equipos de defensa en operaciones altas en LATAM, siendo explotable sin autenticación en entornos accesibles.
M Alto vulnerabilidad
05/09/2026
[CVE-2026-19887] The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up…
The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.1 via deserialization of untrusted input in the Telecom EDY payment callback (usces_action_acting_transaction). Unauthenticated attackers can store arbitrary 'reserve' key/value pairs as order metadata during a public checkout, then invoke the callback with an attacker-chose…
M Alto vulnerabilidad
04/09/2026
[CVE-2026-18175] IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due t…
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due to improper authorization in the DDM target dispatcher.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-85672] zerox 1.1.20 contains an OS command injection vulnerability in the file download mechanism where the…
zerox 1.1.20 contains an OS command injection vulnerability in the file download mechanism where the temporary file extension derived from document URLs is interpolated unsanitized into shell commands executed by poppler utilities. Attackers can craft document URLs with malicious file extensions containing command substitution syntax to execute arbitrary OS commands before document processing occu…
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85425] MOOS-IvP iSay through 24.8.1 contains a remote code execution vulnerability in the SAY_MOOS variable…
MOOS-IvP iSay through 24.8.1 contains a remote code execution vulnerability in the SAY_MOOS variable handler that passes unsanitized text to a shell command. Attackers can publish SAY_MOOS messages containing backticks or command substitution syntax to execute arbitrary commands as the iSay process user.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85047] Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82…
Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85160] AVideo through commit c91b5975d contains a cross-site request forgery and path traversal vulnerabili…
AVideo through commit c91b5975d contains a cross-site request forgery and path traversal vulnerability in stopLive.php that allows attackers to delete directories by exploiting missing token validation and unsanitized key parameter concatenation. Attackers can craft an image tag with a traversal payload like key=../../videos to trigger recursive deletion of the videos directory when an admin visit…
M Alto vulnerabilidad
02/09/2026
Vulnerabilidad alta de RCE en DSpace 8.x, 9.x y 10.x afecta repositorios digitales
DSpace, software de código abierto ampliamente utilizado en universidades y instituciones públicas de LATAM para gestionar repositorios digitales, es vulnerable a ejecución remota de código (RCE) mediante plantillas Velocity en mensajes COAR Notify/LDN. Las versiones afectadas son 8.0-rc1 a 8.3, 9.0-rc1 a 9.2, y 10-rc1. Un atacante no autenticado podría ejecutar código arbitrario en el servidor con privilegios del proceso DSpace, comprometiendo la integridad de acervos académicos y datos sensibles.
M Alto vulnerabilidad
02/09/2026
Exposición de datos sensibles sin autenticación en WooCommerce Product Attachment ≤ 2.3.3
WooCommerce Product Attachment versión 2.3.3 y anteriores contiene una vulnerabilidad que permite a atacantes acceder a datos sensibles sin requerir autenticación, con puntuación CVSS 7.5. Esta exposición afecta principalmente a tiendas en línea operadas en México y Latinoamérica que utilizan este plugin en WordPress. El riesgo se amplifica en entornos de comercio electrónico que manejan información de clientes, productos o transacciones.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84202] ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, allowing arbitrary c…
ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, allowing arbitrary code execution through Python object construction tags. Attackers can craft malicious model repositories with poisoned configuration files that execute code when loaded by users.
M Alto vulnerabilidad
01/09/2026
Vulnerabilidad SSRF alta en Kyverno anterior a 1.18.0 permite inyección de solicitudes HTTP
Kyverno antes de la versión 1.18.0 contiene una vulnerabilidad de falsificación de solicitud del lado del servidor (SSRF) en apiCall.service.url que permite a usuarios autenticados enviar peticiones HTTP arbitrarias mediante inyección de entrada controlada por el usuario a través de sustitución de variables. Los atacantes pueden comprometer servicios internos, endpoints de metadatos en la nube y direcciones loopback, con datos de respuesta reflejados en mensajes de error de admisión. Esta vulnerabilidad afecta directamente a plataformas Kubernetes en producción en LATAM.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
01/09/2026
Vulnerabilidad de XSS almacenado en LibreNMS 26.4.0 mediante integración Oxidized
LibreNMS versiones hasta 26.4.0 procesa sin sanitización campos JSON (nombre, IP, modelo, autor, mensaje de commit) desde la URL de integración Oxidized configurable por administrador, permitiendo inyección de XSS persistente. Un atacante que controle el servidor Oxidized puede ejecutar scripts maliciosos en el navegador de usuarios que accedan a la página de configuración de dispositivos. Esta vulnerabilidad afecta directamente a proveedores de servicios de red y administradores de infraestructura en LATAM que usan LibreNMS con Oxidized integrado.
M Crítico vulnerabilidad
31/08/2026
Vulnerabilidad crítica en @hulumi/drift permite ejecución de planes maliciosos sin validación
Las versiones de @hulumi/drift anteriores a 1.3.2 aceptan planes de ejecución externos sin validar su procedencia, permitiendo que entrada de reconciliación no confiable sea tratada como confiable. Atacantes pueden inyectar planes maliciosos que eludan controles de seguridad para ejecutar operaciones de reconciliación no autorizadas, afectando sistemas de procesamiento de datos en empresas de México y LATAM con puntuación CVSS 9.8.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82861] @hulumi/policies versions before 1.3.2 contain a parent spoof bypass vulnerability that allows attac…
@hulumi/policies versions before 1.3.2 contain a parent spoof bypass vulnerability that allows attackers to submit spoofed SecureBucket parent evidence during policy evaluation. Attackers can bypass security policy checks by providing falsified evidence, causing the validator to miss unsafe bucket configurations.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82862] Hulumi versions before v1.3.2 resolve the threat-model helper script from an unsafe root, allowing w…
Hulumi versions before v1.3.2 resolve the threat-model helper script from an unsafe root, allowing workspace files to shadow the intended helper script. Attackers can place malicious files in the workspace to execute arbitrary code during local skill execution.
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-82854] Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.siz…
Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter. When an application passes a custom envelope object with a size property containing CRLF characters to sendMail(), the value is concatenated into the SMTP MAIL FROM command (as SIZE=...) without sanitization, allowing injection of arbitrary SMTP commands such as RCPT TO to silently add …