Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,599
Total alertas
3086
Críticas
10241
Altas
8
Ransomware
1807
Esta semana
RSS
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-78209] exceljs-hardened versions before 5.0.0 fail to neutralize leading equals, plus, minus, or at signs i…
exceljs-hardened versions before 5.0.0 fail to neutralize leading equals, plus, minus, or at signs in cell values written to CSV output. Attackers who can influence exported cell values can inject formulas that execute when the CSV file is opened in a spreadsheet application, potentially exfiltrating data or performing other malicious actions.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-78161] A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function report_raw_cbor o…
A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function report_raw_cbor of the file lib/misc/lecp.c of the component LECP CBOR Recording. The manipulation results in out-of-bounds write. The attack can be launched remotely. The exploit has been made public and could be used. The patch is identified as 1d44554a1bb262db63ff4e240152a9deecd99054. It is best practice to apply…
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-78203] Ghostwriter before 7.1.2 fails to validate template ownership in the report template swap endpoint, …
Ghostwriter before 7.1.2 fails to validate template ownership in the report template swap endpoint, allowing attackers to attach client-scoped templates from other clients to their own reports. Attackers can exploit sequential template primary keys to enumerate and attach foreign templates, then generate reports to disclose template contents including letterhead, boilerplate, and methodology text.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-78206] exceljs-hardened before 5.0.0 decompresses all entries from supplied xlsx archives into memory witho…
exceljs-hardened before 5.0.0 decompresses all entries from supplied xlsx archives into memory without limits on entry size, total size, or compression ratio. Attackers can upload highly compressed workbooks that expand to gigabytes in memory, exhausting available resources and causing denial of service.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-78157] A vulnerability was detected in Open5GS 2.8.0. This affects the function pcrf_rx_aar_cb of the file …
A vulnerability was detected in Open5GS 2.8.0. This affects the function pcrf_rx_aar_cb of the file src/pcrf/pcrf-rx-path.c of the component Rx AA-Request Handler. Performing a manipulation results in out-of-bounds read. It is possible to initiate the attack remotely. The patch is named c18dc6938bf63cc7374315d3dca303d92066e746. To fix this issue, it is recommended to deploy a patch.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-78154] A vulnerability was identified in the-momentum open-wearables up to 0.6.2. This impacts the function…
A vulnerability was identified in the-momentum open-wearables up to 0.6.2. This impacts the function redeem_invitation_code of the file backend/app/api/routes/v1/user_invitation_code.py of the component Public Invitation-Code Redemption Endpoint. The manipulation of the argument code leads to missing authentication. Remote exploitation of the attack is possible. The project was informed of the pro…
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-78156] A security vulnerability has been detected in Open5GS 2.8.0. Affected by this issue is the function …
A security vulnerability has been detected in Open5GS 2.8.0. Affected by this issue is the function hss_ogs_diam_s6a_air_cb of the file src/hss/hss-s6a-path.c of the component S6a Authentication-Information-Request Handler. Such manipulation of the argument Visited-PLMN-Id leads to heap-based buffer overflow. The attack may be performed from remote. The name of the patch is a9c82ee0b590d76a581b058…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-78147] A vulnerability was found in ggml-org llama.cpp bec4772f6. The impacted element is the function dese…
A vulnerability was found in ggml-org llama.cpp bec4772f6. The impacted element is the function deserialize_tensor of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component ggml-RPC Server. Performing a manipulation of the argument op/op_params results in deserialization. The attack may be initiated remotely. This vulnerability is distinct from CVE-2026-34159 (GHSA-j8rj-fmpv-wcxw, PR #20908), wh…
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-78143] A vulnerability was determined in code-projects Barangay Resident Profiling Management System 1.0. A…
A vulnerability was determined in code-projects Barangay Resident Profiling Management System 1.0. Affected is an unknown function of the file residents.php of the component Resident Search Functionality. This manipulation of the argument Search causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-78141] A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function formexeCommand of th…
A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function formexeCommand of the file /goform/exeCommand. The manipulation of the argument cmdinput leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-9769] justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial o…
justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During JustHTML() construction, TreeBuilder.finish() unconditionally calls _populate_selectedcontent(), which recursively traverses the DOM tree via _find_elements()/_find_element() without a depth bound. An attacker who can supply HTML for parsing can provide deeply nested elements (e.g.…
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-4671] justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector handl…
justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector handling and linkification. Applications that evaluate attacker-controlled selector strings (via query(), matches(), or selector-based transforms), run selector matching over very large untrusted documents, construct DOM trees from untrusted structure, or enable linkification over attacker-controlled tex…
M Alto vulnerabilidad
Hace 2 días
Vulnerabilidad alta en GitLab CE/EE permite ejecución remota de código
GitLab ha reportado una vulnerabilidad de path traversal en el registro de paquetes que afecta versiones 18.8 a 19.2.1, permitiendo a usuarios autenticados ejecutar código remoto. Esta afecta directamente a empresas en LATAM que utilizan GitLab como plataforma de CI/CD y gestión de repositorios. El CVSS 8.5 indica severidad alta, requiriendo acción inmediata en entornos productivos.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-77115] Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into pop…
Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HTML without escaping them.
M Alto vulnerabilidad
Hace 2 días
Inyección de comandos alta en Tenda CH22 1.0.0.1 permite acceso remoto no autorizado
Se ha identificado una vulnerabilidad de inyección de comandos en el router Tenda CH22 versión 1.0.0.1 a través de la función formeditFileName del archivo /goform/editFileName. Un atacante remoto puede ejecutar comandos arbitrarios manipulando el parámetro editNameMit sin autenticación previa. El exploit ha sido publicado públicamente, incrementando el riesgo de explotación masiva en infraestructuras de LATAM que utilizan este modelo de router.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 2 días
Vulnerabilidad alta en vas3k TaxHacker permite credenciales hardcodeadas en JWT
Se identificó una vulnerabilidad en vas3k TaxHacker versiones hasta 0.8.2 en el manejador JWT Secret (función envSchema.parse) que permite manipular el parámetro BETTER_AUTH_SECRET, resultando en credenciales hardcodeadas. El ataque es remoto y afecta directamente la autenticación de aplicaciones financieras y de gestión tributaria. Aunque se notificó al desarrollador, no ha respondido con parches disponibles.
M Alto vulnerabilidad
Hace 2 días
Vulnerabilidad de inyección de código en CHIRP permite ejecución remota vía archivos CSV malformados
CHIRP (chirpmyradio) versiones anteriores a 39178db contiene una vulnerabilidad de inyección eval en el controlador Kenwood ITM que permite a atacantes ejecutar código arbitrario mediante archivos CSV especialmente diseñados. Esto afecta a operadores de radiocomunicaciones y empresas que utilizan esta herramienta para configuración de equipos en México y Latinoamérica.
M Alto vulnerabilidad
Hace 2 días
Plugin Security Hardener para WordPress vulnerable a falta de autorización en versiones hasta 2.4.4
El plugin Security Hardener para WordPress contiene una vulnerabilidad de autorización faltante (CVE-2026-16149, CVSS 8.8) en todas las versiones hasta la 2.4.4. La función de protección contra enumeración de usuarios, habilitada por defecto, modifica incorrectamente los permisos en los endpoints /wp/v2/users y /wp/v2/users/, permitiendo acceso no autorizado a información sensible. Este riesgo afecta directamente a sitios de e-commerce, portales corporativos y aplicaciones con datos altas en LATAM que dependen de esta funcionalidad.
M Alto vulnerabilidad
Hace 2 días
Vulnerabilidad alta de inyección de objetos PHP en plugin PPWP para WordPress (CVE-2026-0551)
El plugin Password Protect Pages (PPWP) para WordPress en versiones hasta 1.9.18 es vulnerable a inyección de objetos PHP mediante deserialización insegura del parámetro 'post_protection_roles'. Atacantes autenticados con acceso de Colaborador o superior pueden ejecutar código arbitrario en servidores web. Esta vulnerabilidad afecta principalmente a sitios corporativos y de comercio electrónico en México y LATAM que protegen contenido sensible con este plugin.
M Alto vulnerabilidad
Hace 2 días
Vulnerabilidad alta en docker-socket-proxy permite lectura no autorizada de archivos en contenedores
docker-socket-proxy no valida correctamente los endpoints de lectura en el namespace /containers de la API de Docker cuando la variable CONTAINERS está configurada, permitiendo a atacantes acceder a archivos arbitrarios y descargar sistemas de archivos completos de contenedores. Esta vulnerabilidad afecta directamente a infraestructuras containerizadas en empresas LATAM que ejecutan Docker en entornos multi-inquilino o con segregación insuficiente de permisos.