Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1045
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Hace 14 horas
[CVE-2026-107808] Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, POST /api/login c…
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, POST /api/login checks EnabledOTP but does not require a WebAuthn assertion when EnabledPasskey is true and no TOTP secret is configured. A passkey-only account is therefore issued a session after password verification, despite Enabled2FA reporting that the account has a second factor. An attacker who obtains the pa…
M Crítico vulnerabilidad
30/09/2026
Bypass de autenticación por inyección LDAP en Apache MINA SSHD afecta múltiples versiones
Apache MINA SSHD, biblioteca Java para SSH, contiene una vulnerabilidad crítica (CVSS 9.1) en su componente opcional sshd-ldap que permite eludir autenticación mediante inyección LDAP. Las versiones afectadas incluyen 1.2.0 a 2.19.0 y 3.0.0-M1 a 3.0.0-M5. Empresas en LATAM que integren LDAP para autenticación SSH en servidores están expuestas a acceso no autorizado.
M Crítico vulnerabilidad
30/09/2026
Omisión de autenticación en Apache MINA SSHD 2.0.0 a 3.0.0-M5 (CVE-2026-77185)
Apache MINA SSHD, librería Java para implementar servidores SSH, contiene una vulnerabilidad crítica (CVSS 9.1) que permite eludir la autenticación en configuraciones específicas de autenticación asincrónica. Afecta principalmente a servidores SSH personalizados en entornos de infraestructura crítica, plataformas de acceso remoto y soluciones de integración en LATAM. La explotación podría comprometer la integridad de sistemas de gestión de infraestructura, bases de datos y servidores de aplicaciones.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-19292] Re-pairing with a legitimate device can use a lower security level than previous making brute-forcin…
Re-pairing with a legitimate device can use a lower security level than previous making brute-forcing the LTK easier. See V4 in the BLERP paper linked below.
M Alto vulnerabilidad
28/07/2026
[CVE-2026-62427] [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabiliti…
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To manage the system, sysctl and platform operations are used by the control domain or a possible Xenstore domain. Some of these operations may not be executed in parallel, so a system-wide lock each is used. The way those locks are acquired is, however, not providing …
M Crítico vulnerabilidad
01/07/2026
[CVE-2026-10539] A Control-M/Server communication command does not sufficiently filter or sanitize user-supplied inpu…
A Control-M/Server communication command does not sufficiently filter or sanitize user-supplied input. Under certain conditions, this issue may allow an unauthenticated attacker to execute unauthorized commands on the affected server, potentially leading to compromise of the server.  This vulnerability affects Control-M/Server versions 9.0.20.x to 9.0.21.200 (included) and potentially earlier u…
S Alto vulnerabilidad
29/06/2026
[CVE-2026-41052] Improper privilege handling could be used by users with Project Owner role to escalate privileges, i…
Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher versions 2.14 before 2.14.2, 2.13 before 2.13.6, and 2.12 before 2.12.10.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
08/06/2026
[CVE-2026-25555] OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the API key aut…
OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the API key authentication middleware that allows unauthenticated attackers to gain admin access by supplying an empty X-Api-Key header value. Attackers can exploit the middleware's comparison of the supplied header against an empty AdminApiKey default string to access the admin console and all API endpoints witho…