Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "X" — 7585 resultados ✕ Limpiar búsqueda
13,539
Total alertas
3075
Críticas
10192
Altas
8
Ransomware
1800
Esta semana
RSS
M Alto vulnerabilidad
Hace 3 días
Inyección de comandos en BOSH CLI para Windows en Cloud Foundry permite ejecución remota
Una vulnerabilidad de inyección de comandos (CVE-2026-47827, CVSS 7.5) afecta la herramienta BOSH CLI en entornos Windows dentro de Cloud Foundry, permitiendo a atacantes remotos ejecutar comandos arbitrarios del sistema. Esta exposición impacta directamente plataformas de orquestación de contenedores y servicios cloud en empresas de LATAM que utilizan Cloud Foundry como infraestructura de aplicaciones altas.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-63046] Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in …
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache InLong. Agent Installer's ModuleManager executes arbitrary shell commands via ExcuteLinux.exeCmd() with no filtering or whitelist validation. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1]/[2] to solve …
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-61400] Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in…
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache CloudStack's run and get diagnostics functionality for the system VMs and virtual routers. An authenticated user holding the permissions required to invoke either `getDiagnosticsData` or `runDiagnostics` can achieve arbitrary command execution on the system VM and/or Virtual Router instance…
M Alto vulnerabilidad
Hace 3 días
Vulnerabilidad alta de bypass de autenticación en ArchitectPanel de FuyaWeb (CVE-2026-16323)
Se ha identificado una vulnerabilidad de tipo Execution After Redirect (EAR) en ArchitectPanel Web Admin Panel de FuyaWeb Internet and Informatics Services que permite eludir mecanismos de autenticación. La vulnerabilidad afecta versiones hasta el 28072026 y representa un riesgo alta para organizaciones en México y Latinoamérica que utilizan esta plataforma de administración web, comprometiendo el acceso a paneles de control y datos sensibles.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-18781] The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not v…
The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not validate the final name of an uploaded file after stripping characters from it, allowing unauthenticated users to defeat its file type restrictions and execute arbitrary code on the server.
M Alto vulnerabilidad
Hace 3 días
Vulnerabilidad XSS almacenado alta en WPForms Pro para WordPress
El complemento WPForms Pro para WordPress es vulnerable a inyección de scripts almacenados en campos de texto simple y párrafo (versiones hasta 2.0.0.2) debido a sanitización insuficiente. Atacantes no autenticados pueden inyectar código malicioso que se ejecuta cuando usuarios acceden a páginas comprometidas. Este riesgo es alta para sitios comerciales, de servicios y gobierno en LATAM que dependen de formularios para captura de datos.
M Alto vulnerabilidad
Hace 3 días
Vulnerabilidad alta en Multicluster Engine (MCE) permite eliminar clústeres sin autorización
Se identificó un fallo en el componente clusterclaims-controller de Multicluster Engine (MCE) que permite a usuarios con permisos estándar manipular el campo `spec.namespace` para especificar y eliminar cualquier ManagedCluster, incluyendo el hub local-cluster o clústeres de otros inquilinos. La ausencia de validación de propiedad (ownership check) expone infraestructuras multiclúster en entornos empresariales de México y LATAM a pérdida de disponibilidad y movimientos laterales entre tenants.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-77642] tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signatu…
tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for most Tor roles, but potentially major for directory authorities. This is TROVE-2026-019.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-72818] The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and app…
The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+(?:[.\-][a-z0-9]+)* is unbounded. Input consisting of many alternating label separators can be partitioned in exponentially many ways, and because the branch also requires a trailing top-level domain t…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-72848] SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documente…
SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_domain control only to leaf url entries. The loop over url elements filters cross-domain locations, but the loop over nested sitemap elements passes the child loc straight to self.scrape_all([loc.text], "xml"), which reaches WebBaseLoader.scrape_all and an aiohttp GET, with no dom…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-69419] Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to exe…
Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-55765] CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. …
CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG embedded cleartext role passwords in `ALTER ROLE` and `CREATE ROLE` statements generated by SetUserPassword in pkg/management/postgres/utils/roles.go and appendPasswordOption in internal/management/controller/roles/postgres.go. When pg_stat_statements was pr…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-49436] LinkAce is a self-hosted archive to collect website links. Prior to version 2.5.7, the Bulk Link API…
LinkAce is a self-hosted archive to collect website links. Prior to version 2.5.7, the Bulk Link API endpoint (`POST /api/v2/bulk/links`) accepts URLs without any format validation, allowing an authenticated user to store a `javascript:` URI. The stored URI is later rendered verbatim as an `href` in Blade templates, and clicking it executes arbitrary JavaScript in the victim's browser — exfiltrati…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-46355] BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton exposed /bigbluebu…
BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton exposed /bigbluebutton/api/handleJoinExistingUser through bigbluebutton-web/grails-app/controllers/org/bigbluebutton/web/controllers/ApiController.groovy. A requester able to supply an existingUserID for an active participant could reuse that participant's session and impersonate the participant in the same meeting b…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-46682] BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton allowed authentica…
BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton allowed authenticated moderators to inject SQL through the meetingId and userId values used by refreshBreakoutRoomsVisibleForUsers in akka-bbb-apps/src/main/scala/org/bigbluebutton/core/db/BreakoutRoomUserDAO.scala. The method interpolated those values into breakout room visibility queries, allowing arbitrary SQL exe…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-49217] Mailu is a mail server as a set of Docker images. Prior to version 2024.06.52, a missing authorizati…
Mailu is a mail server as a set of Docker images. Prior to version 2024.06.52, a missing authorization check in the Mailu admin REST API allows any unauthenticated attacker to remove any potential IP restriction or update the comment field from any existing user token provided the REST API is enabled. Upgrade to Mailu 2024.06.52 to receive a patch or, as a workaround, turn the REST API off.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-19442] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtua…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtual SCSI (vSCSI) initiator driver. Successful exploitation may result in denial of service, privilege escalation, or full compromise of the client LPAR kernel.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-19446] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthenticated attacker can send a cr…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthenticated attacker can send a crafted UDP packet to a reachable RPC service, resulting in complete system unavailability and requiring an LPAR restart.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-19449] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a vulnerability in cmdnim that may allow an unpriv…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a vulnerability in cmdnim that may allow an unprivileged local user to executes the payload as root.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-18832] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap-based buffer overflow.