Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1778
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-75975] fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validat…
fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6 grammar, so invalid trailing text in an authority can be silently discarded and a malformed attacker-controlled host is turned into a different valid IPv6 destination. For example, a bracketed literal with invalid trailing characters is normalized to the unspecified address, whic…
M Alto vulnerabilidad Nuevo
Hace 7 horas
[CVE-2026-78147] A vulnerability was found in ggml-org llama.cpp bec4772f6. The impacted element is the function dese…
A vulnerability was found in ggml-org llama.cpp bec4772f6. The impacted element is the function deserialize_tensor of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component ggml-RPC Server. Performing a manipulation of the argument op/op_params results in deserialization. The attack may be initiated remotely. This vulnerability is distinct from CVE-2026-34159 (GHSA-j8rj-fmpv-wcxw, PR #20908), wh…
M Crítico vulnerabilidad Nuevo
Hace 16 horas
[CVE-2026-7808] justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dange…
justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive sanitization, potentially leading to cross-site scripting. The issues primarily affect advanced usage rather than the default JustHTML(..., sanitize=True) path for ordinary parsed HTML: mutating or reusing sanitization policy objects (including exporte…
M Crítico vulnerabilidad Nuevo
Hace 16 horas
[CVE-2026-5388] justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_valu…
justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Markdown passthrough (html_passthrough=True), and several custom sanitization-policy edge cases. Depending on configuration, an attacker can bypass sanitization to inject active HTML and JavaScript — for example via encoded javascript: URLs, backslash-b…
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-2996] The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to I…
The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.6.21. This is due to a logic flaw in the 'validate_cart_data' function. This makes it possible for unauthenticated attackers to bypass required paid addons and complete purchases at the base product price only, effectively stealing pro…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-63421] Keystone is a content management system for Node.js. Prior to 6.5.3, the findMany resolver in packag…
Keystone is a content management system for Node.js. Prior to 6.5.3, the findMany resolver in packages/core/src/lib/core/queries/resolvers.ts compares the signed take argument directly with graphql.maxTake, allowing a remote unauthenticated GraphQL client to provide a negative take value whose magnitude exceeds the configured bound. The bypass also applies to relationship queries and can return mo…
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-48755] Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation…
Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads to an arbitrary file write on the host, possibly leading to arbitrary command execution. Version 7.1.0 patches the issue.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-48769] Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file w…
Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead to arbitrary command execution as root on the server. Version 7.2.0 patches the issue.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-66785] A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect ne…
A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect network traffic from other connected clusters (peer clusters) by publishing a specially crafted network endpoint. The system fails to properly validate the network subnets provided by the malicious cluster, enabling it to declare arbitrary network ranges. Consequently, all network traffic intended for…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-53587] libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a…
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in set_data in src/libgit2/transports/smart_pkt.c without first verifying that the smart-protocol pkt-line capability buffer contains 14 bytes. A malicious Git serve…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76387] In Splunk Enterprise Security versions below 8.6.1, a user who holds a Splunk Enterprise Security ro…
In Splunk Enterprise Security versions below 8.6.1, a user who holds a Splunk Enterprise Security role that contains the mc_investigation_read capability could inject Search Processing Language (SPL) through Analyst Queue search filters, allowing for access to all relevant data and system integrity available to the scheduled searches that run for that user. The vulnerability is possible because th…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76330] In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user coul…
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an authenticated user into opening a crafted link to Monitoring Console. When the authenticated user opens the link, Splunk Enterprise runs attacker-controlled Search Processing Language (SPL) using the permissions of that user. The injected SPL could access data and perform actions availabl…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76332] In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user coul…
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an authenticated user into opening a crafted link to Analytics Workspace. When the authenticated user opens the link, Splunk Enterprise runs attacker-controlled Search Processing Language (SPL) using the permissions of that user. The injected SPL could access data and perform actions availab…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-17414] IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW95…
IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 Power Systems Firmware is affected by a vulnerability in partition firmware during network boot. An unauthenticated attacker with access to the same network as a partition performing a network boot can prevent that partition from completing its boot sequence. On partitions wher…
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-20318] As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Wo…
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20318 are related to improper input validation issues that ar…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 5 días
Vulnerabilidad alta de deserialización en SPLWare esProc hasta versión 20260507
Se ha identificado una vulnerabilidad de deserialización insegura en SPLWare esProc que afecta la función ObjectInputStream.readUnshared en SocketData.java. Un atacante remoto puede explotar esta falla para ejecutar código arbitrario en sistemas que ejecuten versiones vulnerables, comprometiendo servidores de procesamiento de datos en empresas de LATAM que utilizan esta plataforma de análisis paralelo.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-52876] Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to v…
Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-path-at-time IPC handler in src/ipc/player.js accepts a renderer-controlled filePath without validating its type or location. If the mpv or VLC launch attempts are skipped or fail, the handler passes filePath to Electron's shell.openPath. A compromised renderer can provide the…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-52877] Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to v…
Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-external IPC handler in src/ipc/downloads.js passes a renderer-supplied url directly to Electron's shell.openExternal without validating its protocol. A compromised renderer can submit file: URIs or operating-system-specific custom schemes, causing the host to open local files…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-47629] NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause impr…
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause improper input validation. A successful exploit might lead to denial of service.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-66783] A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for K…
A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a cluster administrator, or any user with permissions to modify the Submariner Custom Resource (CR), to specify an unvalidated image path. This lack of validation enables an attacker to execute arbitrary code with elevated privileges across the entire cluster, in…