Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 41 min
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1009
Esta semana
RSS
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-9209] mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulnerability in the Logi…
mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulnerability in the Login.aspx admin panel handlers, where the runQueryButton postback and exportSqlQuery_Server PageMethod execute caller-supplied SQL against the backing Sybase SQL Anywhere database using DBA/sysadmin privileges with no server-side authentication enforced beyond a client-side sessionStorage flag. Attacke…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106378] Privilege elevation in Sandbox in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote at…
Privilege elevation in Sandbox in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Alto vulnerabilidad
01/10/2026
[CVE-2026-66246] iControl is affected by a Broken Access Control vulnerability, which could allow an attacker to expl…
iControl is affected by a Broken Access Control vulnerability, which could allow an attacker to exploit missing authentication checks or insecure direct object references (IDOR), enabling privilege escalation and the unauthorized modification or deletion of sensitive application data.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102118] A local privilege escalation vulnerability in Kiteworks could have allowed an attacker with an exist…
A local privilege escalation vulnerability in Kiteworks could have allowed an attacker with an existing shell under a low-privileged service account to escalate to root privileges on the appliance.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-53605] Reachy Mini ISO for Wireless contains the necessary files to build a custom Raspberry Pi OS image fo…
Reachy Mini ISO for Wireless contains the necessary files to build a custom Raspberry Pi OS image for the Reachy Mini Wireless robot, using pi-gen. Prior to version 0.2.4, the Reachy Mini Wireless OS image shipped with an overly broad sudoers entry granting the pollen daemon user (uid 1000) passwordless sudo access to /usr/bin/systemctl with no subcommand or argument restriction. This is a local p…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-88808] A vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to …
A vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to downstream clusters using its own cluster-admin credentials instead of the ServiceAccount pinned to the deployment. It affects multi-tenancy environments where different tenants share the same downstream clusters, for example different privileged or untrusted teams inside the same organization. This…
M Alto vulnerabilidad
23/09/2026
Escalada de privilegios alta en ManageEngine OpManager y Firewall Analyzer v12.8.710
ZohoCorp ManageEngine OpManager y Firewall Analyzer versiones 12.8.710 y anteriores contienen una vulnerabilidad de escalada de privilegios (CVSS 8.1) que permite a usuarios autenticados con permisos bajos obtener acceso administrativo mediante la importación maliciosa de perfiles de reportes. Esta vulnerabilidad afecta directamente a empresas en LATAM que utilizan estas herramientas para monitoreo de infraestructura y gestión de firewall.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
21/09/2026
[CVE-2026-77521] MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a …
MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool, skill, or sub-application use SandboxShellBackend, which exposes an execute shell tool without excluding it and omits execute from interrupt_on, so human approval is not required. Untrusted chat or ingested content can therefore cause command execution; source deployments with MAXKB_…
M Alto vulnerabilidad
21/09/2026
Vulnerabilidad alta en CRI-O permite eludir contexto de seguridad en Kubernetes
Una falla en la restauración de puntos de control de CRI-O permite a usuarios con capacidad de crear pods eludir el contexto de seguridad de Kubernetes, reteniendo credenciales, capacidades Linux y configuraciones seccomp del contenedor comprometido. Esto expone infraestructuras containerizadas en México y LATAM a ejecución con privilegios elevados, afectando principalmente plataformas que utilizan Kubernetes en producción con múltiples usuarios o entornos multi-tenant.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-75092] A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided b…
A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository). During RHEL 9 to RHEL 10 upgrades, the actor runs: mysqld --validate-config --log-error-verbosity=2 directly as root in the Leapp actor context, bypassing the packaged MySQL systemd unit that normally starts the daemon as User=mysql. A process compromised as the mysql OS identi…
M Crítico vulnerabilidad
11/09/2026
Vulnerabilidad crítica en Hugo v0.161.0+ permite ejecución de código mediante TailwindCSS
Hugo, generador de sitios estáticos, ejecuta herramientas Node con permisos insuficientemente restringidos desde la versión 0.161.0. TailwindCSS, incluido en la lista de seguridad por defecto, requiere configuraciones altamente permisivas (--allow-addons, --allow-child-process, --allow-worker) que permiten eludir controles de seguridad previos. Esto afecta a empresas en LATAM que alojan sitios web con Hugo y utilizan TailwindCSS para compilación de estilos.