Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Openssl" — 32 resultados ✕ Limpiar búsqueda
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1785
Esta semana
RSS
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-62243] Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions through 4…
Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions through 4.1.136.Final disable TLS hostname verification on the SslProvider.OPENSSL client path when a plain (non-extended) X509TrustManager is used and Unsafe-based trust-manager wrapping is unavailable (Java 25+). In this configuration the OpenSSL client does not perform hostname verification, allowing a ma…
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-59825] Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.19 and from…
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.19 and from 4.5.0 until 4.5.12, Mastodon's app/models/concerns/user/ldap_authenticable.rb mutates OpenSSL::SSL::SSLContext::DEFAULT_PARAMS when LDAP authentication uses LDAP_TLS_NO_VERIFY=true, disabling SSL and TLS certificate verification globally for requests made by puma web processes while sidekiq backgro…
M Alto vulnerabilidad
17/08/2026
Vulnerabilidad alta en openssl_encrypt: clave secreta hardcodeada compromete autenticación de API
Versiones de openssl_encrypt anteriores a 1.4.0 contienen una clave secreta predeterminada hardcodeada en la configuración del servidor de telemetría, usada para hash de claves API. Atacantes que conocen este valor pueden falsificar hashes de API para comprometer la autenticación del sistema de telemetría. Esto afecta directamente a infraestructuras en la nube y servidores locales que dependen de esta validación criptográfica.
M Alto vulnerabilidad
17/08/2026
Vulnerabilidad alta en openssl_encrypt: secretos JWT hardcodeados permiten falsificación de tokens
Versiones de openssl_encrypt anteriores a 1.4.0 contienen secretos de firma JWT hardcodeados en config.py que superan validaciones, permitiendo a atacantes con acceso al código fuente forjar tokens válidos para cualquier client_id y acceder sin autorización a APIs de keyserver y telemetría. Afecta especialmente a organizaciones en LATAM que utilizan esta librería en aplicaciones de autenticación y gestión de claves.
M Alto vulnerabilidad
17/08/2026
Vulnerabilidad alta de path traversal en openssl_encrypt anteriores a v1.4.0
openssl_encrypt versiones anteriores a 1.4.0 contienen una vulnerabilidad de path traversal (CVE-2026-74884, CVSS 7.5) en el método _is_safe_path que no sanitiza el parámetro plugin_id, permitiendo a atacantes acceder a directorios arbitrarios fuera del directorio de plugins mediante secuencias como '../'. Empresas en México y LATAM que usen este componente en aplicaciones web o sistemas de gestión de contenido enfrentan riesgo de exposición de información sensible y potencial ejecución de código.
M Alto vulnerabilidad
17/08/2026
Vulnerabilidad alta en openssl_encrypt: derivación de claves débil permite cracking de contraseñas (CVE-2026-74888)
openssl_encrypt versiones anteriores a 1.4.0 implementan una construcción PBKDF2 no estándar con iteraciones=1 por llamada, debilitando significativamente la derivación de claves. Atacantes pueden comprometer archivos cifrados legacy con esfuerzo computacional reducido. Afecta sistemas que protegen datos financieros, médicos y personales en empresas mexicanas y latinoamericanas que usan esta librería para cifrado de datos en reposo.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-74877] openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the …
openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the revoke_key method that allows authenticated clients to revoke any other client's key. Attackers can revoke arbitrary keys by providing a valid ML-DSA signature, bypassing the intended ownership restriction.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
17/08/2026
[CVE-2026-74879] openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready …
openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready endpoint that returns full database exception strings to unauthenticated callers. Attackers can trigger database errors to extract sensitive information including hostnames, IP addresses, connection parameters, and potentially credentials from exception messages.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-74882] openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the enti…
openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the entire RFC 1918 private address space in IntegrityProxyConfig trusted_proxies. Attackers on private networks can forge client certificate headers to bypass mTLS authentication when ProxyAuth validation is relaxed or modified.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-74883] openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbo…
openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbox fails to restrict alternative file access methods like pathlib.Path and io.open. Attackers can import pathlib or io modules to read and write arbitrary files, completely bypassing the restricted_open file access controls.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-74874] openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random module for steganographi…
openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random module for steganographic pixel selection in the generate_pseudorandom_sequence function. Attackers who know the password can recover the Mersenne Twister state from approximately 624 outputs and predict pixel locations containing hidden data for extraction.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-70454] rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS ce…
rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to intercept encrypted sessions by presenting self-signed or otherwise invalid certificates. Attackers can exploit the failure to validate server TLS certificates against a trusted CA or verify certificate hostname matching to decrypt …
M Alto vulnerabilidad
13/08/2026
[CVE-2026-14456] Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packet…
Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit. Impact summary: A remote peer that can make many Initial packets reach the server listener faster than the application accepts connections, can cause the memory allocated to store …
M Alto vulnerabilidad
03/08/2026
[CVE-2026-41447] FirmaCheck for Windows before 1.3.16 contains a dll hijacking vulnerability that allows local attack…
FirmaCheck for Windows before 1.3.16 contains a dll hijacking vulnerability that allows local attackers to execute arbitrary code by placing a crafted openssl.cnf file in the unvalidated C:\Program Files (x86)\Common Files\SSL\ directory path. Attackers can write a malicious OpenSSL configuration file referencing an attacker-controlled DLL to achieve code execution at startup process privilege lev…
L Alto vulnerabilidad
24/07/2026
[CVE-2026-66033] libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vul…
libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM ciphers during handshake. Attackers can exploit the underflow in the expression computing blocksize minus aadlen minus authentication tag length to…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
S Alto vulnerabilidad
17/07/2026
[CVE-2026-45784] rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 until 0.10.80…
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 until 0.10.80, CipherCtxRef::cipher_update_inplace in openssl/src/cipher_ctx.rs incorrectly sized output buffers when used with AES key-wrap-with-padding ciphers EVP_aes_{128,192,256}_wrap_pad. For a non-multiple-of-8 input, OpenSSL writes up to 7 bytes past the end of the caller's buffer or Vec, producing attac…
M Alto vulnerabilidad
13/07/2026
[CVE-2026-58101] Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service via NULL pointer derefer…
Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service via NULL pointer dereference. X509V3_EXT_d2i(ext) returns NULL when an extension's DER value fails to parse. basicC, ia5string, and auth_att dereference its result without a NULL check. keyid_data also dereferences akid->keyid, which is NULL for an empty AKI SEQUENCE (DER 30 00) even when the parse succeeds. A caller inv…
W Alto vulnerabilidad
25/06/2026
[CVE-2026-6331] HMAC zero-length tag forgery in EVP_DigestVerifyFinal, where a zero-length tag could be accepted as …
HMAC zero-length tag forgery in EVP_DigestVerifyFinal, where a zero-length tag could be accepted as valid during HMAC verification. In the OpenSSL-compatibility HMAC verify path the supplied signature length was only checked as not exceeding the MAC length, so a zero-length or otherwise truncated tag could pass verification. The fix requires the supplied tag length to exactly equal the MAC length …
W Alto vulnerabilidad
25/06/2026
[CVE-2026-11310] X.509 trust-chain bypass in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert…
X.509 trust-chain bypass in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert()). This affects only builds with --enable-opensslextra (OPENSSL_EXTRA) and whose application validates certificates by calling X509_verify_cert() with caller-supplied untrusted intermediate certificates; for those users it is critical, otherwise the library is unaffected. In particular, native wol…
W Alto vulnerabilidad
25/06/2026
[CVE-2026-11999] X.509 trust-chain bypass (path-depth exhaustion) in the OpenSSL compatibility certificate verifier (…
X.509 trust-chain bypass (path-depth exhaustion) in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert()). This affects only builds with --enable-opensslextra whose application calls X509_verify_cert() with caller-supplied untrusted intermediates; for those users it is critical, otherwise the library is unaffected. Native wolfSSL TLS/DTLS usage is not impacted. X509_verify_ce…