Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
Buscando: "Grafana" — 14 resultados ✕ Limpiar búsqueda
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1002
Esta semana
RSS
M Alto vulnerabilidad
17/09/2026
[CVE-2026-15815] Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin arch…
Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugin archive can chain relative symbolic link entries to escape the plugin installation directory, writing arbitrary files and an executable backend binary outside that directory. The dropped executable runs with the privileges of the Grafana server process, resulting in remote cod…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-14199] Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (syn…
Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who shapes their own attributes to collide with a higher-privileged user's, while th…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-75889] Grafana Alloy’s prometheus.operator.servicemonitors component allows a user who can create or modify…
Grafana Alloy’s prometheus.operator.servicemonitors component allows a user who can create or modify ServiceMonitor resources in a watched namespace to specify an arbitrary local file through bearerTokenFile. Alloy reads the file and sends its contents as a bearer token to an attacker-controlled scrape endpoint. This may disclose files accessible to the Alloy process, including its projected Kuber…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-71366] A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. …
A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. The webhook, Mattermost, Rocket.Chat, and Grafana notification backends use notification template URLs as direct HTTP request targets without validating the target address against private, loopback, or reserved IP ranges. An organization notification administrator can create notification templates p…
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-19516] A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound re…
A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the caller also choose the HTTP method, path, and body. Because the destination is not restricted to the configured Grafana instance, a caller can direct requests at internal, loopback, and link-local network services (including metadata endpoints) and r…
M Crítico vulnerabilidad
01/08/2026
Vulnerabilidad crítica de bypass de autorización en ArcadeDB anterior a v26.7.2
ArcadeDB versiones anteriores a 26.7.2 contienen una vulnerabilidad de bypass de autorización en manejadores HTTP que afecta endpoints de series de tiempo, batch, Prometheus y Grafana. Los atacantes pueden acceder y modificar bases de datos sin permisos autorizados al invocar directamente estos endpoints con parámetros arbitrarios de base de datos. Esta falla impacta empresas en LATAM que usan ArcadeDB para almacenamiento de datos críticos o monitoreo.
M Crítico vulnerabilidad
16/07/2026
[CVE-2026-63087] Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote a…
Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sending a POST request to the internal plugin install endpoint using hardcoded default stack_id and org_id values present in the public source tree. Attackers can leverage the acquired token to authenticate against all internal API endpoints, create arbi…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
15/07/2026
[CVE-2026-15583] A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate…
A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by supplying a crafted X-Grafana-URL request header. This also enables SSRF against arbitrary internal services, including cloud metadata endpoints.
G Alto vulnerabilidad
10/07/2026
[CVE-2026-33382] Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request bo…
Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.
G Alto vulnerabilidad
22/06/2026
[CVE-2026-42127] The public dashboard query endpoint does not limit request body size before processing, allowing una…
The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.
G Alto vulnerabilidad
22/06/2026
[CVE-2026-9029] A user with Editor permissions can place a malicious script in the attribution field of a Geomap pan…
A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting).
G Alto vulnerabilidad
22/06/2026
[CVE-2026-42129] A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach admi…
A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.
G Crítico vulnerabilidad
22/06/2026
[CVE-2026-28381] The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run qu…
The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the data source to read/write files between the local grafana server and the connected Snowflake host.
G Alto vulnerabilidad
13/06/2026
[CVE-2026-11769] We have released version 5.24.0 of the Grafana Operator. This patch includes a MEDIUM severity secur…
We have released version 5.24.0 of the Grafana Operator. This patch includes a MEDIUM severity security fix for a path traversal/privilege escalation vulnerability in the Grafana Operator. ### Summary The Grafana Operator supports loading dashboards & library panels using the jsonnet data templating language. The jsonnet expression is evaluated in the context of the operator manager pod. ### …