Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ui" — 2785 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1052
Esta semana
RSS
M Alto vulnerabilidad
24/09/2026
[CVE-2026-93816] In the Linux kernel, the following vulnerability has been resolved: f2fs: validate inline dentry na…
In the Linux kernel, the following vulnerability has been resolved: f2fs: validate inline dentry name lengths before conversion Inline dentry conversion copies names out of the inline dentry area before checking that each recorded name length fits in the available filename slots. A corrupted image can therefore make the conversion path read past the inline filename storage while building the re…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-93813] In the Linux kernel, the following vulnerability has been resolved: btrfs: tree-checker: validate I…
In the Linux kernel, the following vulnerability has been resolved: btrfs: tree-checker: validate INODE_REF's namelen [BUG] A crafted btrfs image can trigger the following crash: BUG: unable to handle page fault for address: ffffd1dc42884000 #PF: supervisor write access in kernel mode #PF: error_code(0x0002) - not-present page CPU: 9 UID: 0 PID: 1034 Comm: poc Not tainted 7.1.0-rc4-cust…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-91160] OpenWA is a free, open source, self-hosted WhatsApp API gateway. Prior to 0.23.5, the /events WebSoc…
OpenWA is a free, open source, self-hosted WhatsApp API gateway. Prior to 0.23.5, the /events WebSocket gateway delivers the session.qr event to a VIEWER API key that subscribes by event name or through either wildcard subscription form, even though GET /api/sessions/{sessionId}/qr requires the OPERATOR role. When an allowed session is waiting to be paired, the exposed QR lets the key holder link …
M Alto vulnerabilidad
24/09/2026
[CVE-2026-93284] In the Linux kernel, the following vulnerability has been resolved: drm/pagemap: dma-unmap pages be…
In the Linux kernel, the following vulnerability has been resolved: drm/pagemap: dma-unmap pages before handling migration errors drm_pagemap_migrate_unmap_pages() relies on the pages array to determine which pages require DMA unmapping. However, drm_pagemap_migration_unlock_put_pages() clears the array as part of its cleanup, leaving drm_pagemap_migrate_unmap_pages() with no valid page informat…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-88390] An out-of-bounds write vulnerability in jslGetTokenValueAsString() in Espruino 2v29 (commit bffc6d0)…
An out-of-bounds write vulnerability in jslGetTokenValueAsString() in Espruino 2v29 (commit bffc6d0) allows crafted JavaScript input containing an overlong token to trigger a one-byte write beyond the JsLex.token buffer in RELEASE/NO_ASSERT builds. The out-of-bounds write corrupts the adjacent tokenValue pointer, resulting in memory corruption and potentially causing application crashes or denial …
M Alto vulnerabilidad
24/09/2026
[CVE-2026-96744] Improper neutralization of special elements in data query logic in the cache lock implementation of …
Improper neutralization of special elements in data query logic in the cache lock implementation of the MongoDB integration for Laravel can cause a caller-supplied lock owner value to be evaluated as an aggregation expression rather than as a literal value. An authenticated user who can influence the owner value an application uses when acquiring or restoring a lock may take over or prematurely ex…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-96750] MongoDB Compass can interpolate a database name without escaping into the initial input of its embed…
MongoDB Compass can interpolate a database name without escaping into the initial input of its embedded MongoDB shell when a user opens the shell from that database's view. A user with privileges to create databases on a server that a Compass user connects to may, under specific conditions, have content evaluated as shell input within the Compass process, with that process's privileges. This requi…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
24/09/2026
[CVE-2026-88357] nDPI 5.1.0 contains a memory access issue in the DNS dissector and serializer deserialization code. …
nDPI 5.1.0 contains a memory access issue in the DNS dissector and serializer deserialization code. Specially crafted network input can cause byte-buffer addresses at odd offsets to be cast to uint16_t or wider integer pointers and directly dereferenced without alignment checks. This results in undefined behavior and can cause process termination in UBSan-instrumented builds or on strict-alignment…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-75907] The door access control on a Norwegian Cruise Line asset grants entry based only on the credential's…
The door access control on a Norwegian Cruise Line asset grants entry based only on the credential's static 7-byte UID stored on an NTAG212 NFC chip. A UID is a manufacturer serial number sent in the clear on every read and is not intended to be secret or to authenticate the holder. Validating on the UID of the NTAG212 NFC chip alone is identification, not authentication, and the credential has no…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-77874] IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerab…
IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
M Alto vulnerabilidad
24/09/2026
[CVE-2026-95521] A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spe…
A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm to execute an attacker-controlled shell command via popen() while relocating the source file list. This allows arbitrary command execution as the invoking (typically non-root) user, simply by installing, rebuilding, or otherwise processing an…
M Alto vulnerabilidad
24/09/2026
Vulnerabilidad alta en GIMP: ejecución de código remoto mediante archivos GIMPressionist
Se identificó una falla en el procesamiento de archivos de preajustes GIMPressionist en GIMP que permite escritura fuera de límites de memoria. Un atacante podría distribuir archivos maliciosos disfrazados de preajustes legítimos, logrando corrupción de memoria, bloqueos del sistema o ejecución de código arbitrario en equipos de diseñadores y desarrolladores en empresas LATAM. El CVSS 7.8 indica riesgo alto con exposición práctica.
M Alto vulnerabilidad
24/09/2026
Vulnerabilidad alta en MasterStudy LMS permite ejecución de código PHP arbitrario
El plugin MasterStudy LMS para WordPress anterior a la versión 3.7.50 no valida correctamente los parámetros de configuración de estilo de visualización, permitiendo que usuarios con rol de Colaborador o superior incluyan y ejecuten archivos PHP arbitrarios en el servidor. Esta vulnerabilidad afecta principalmente a instituciones educativas y plataformas de capacitación en LATAM que utilizan este plugin para gestión de cursos en línea, comprometiendo la confidencialidad e integridad de datos de estudiantes y contenido académico.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-94183] Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page…
Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page enters fullscreen mode while the app is running in the background. A remote attacker can exploit this via a specially crafted website to render fake UI elements, such as a spoofed address bar, misleading the user about the origin of displayed content and increasing the risk of phishing.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-86064] Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-o…
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /log WebSocket route configured in config/node/api.yaml and registered by network/api/api.go does not require authentication. The first client message is parsed as a logger Profile in network/api/logs/logSender.go and applied process-wide through Profile.Apply, allowing a remote client to ch…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
23/09/2026
[CVE-2026-84486] A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Four debug views t…
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Four debug views that trigger the internal task, dependency, and workflow schedulers are configured to allow any user (including unauthenticated clients) and are routed in production builds because their URL include is not gated on the debug setting. An unauthenticated remote attacker can repeatedly invoke these endp…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-77423] JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine bu…
JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in less viewer passes user-controlled search and display-filter patterns from getPattern(boolean doDisplayPattern) in builtins/src/main/java/org/jline/builtins/Less.java directly to Java's backtracking regular expression engine and repeatedly applies them to file content. A nested-quantifier exp…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-77422] JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine bu…
JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in grep command in builtins/src/main/java/org/jline/builtins/PosixCommands.java accepts a user-controlled regular expression in grep(...) and, unless line-regexp mode is used, automatically adds a dot-star prefix and suffix before compiling it with Java's backtracking regular expression engine. …
M Alto vulnerabilidad
23/09/2026
[CVE-2026-76086] Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/integra…
Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/integrations/form-settings control panel action in IntegrationsController::actionFormSettings is reachable without the required form integration permissions and passes request-supplied settings to a configured integration. An authenticated attacker can replace outbound host properties such as apiUrl while …
M Alto vulnerabilidad
23/09/2026
[CVE-2026-19888] Missing validation of a mandatory attribute in the SCRAM client-final-message parser in PgBouncer th…
Missing validation of a mandatory attribute in the SCRAM client-final-message parser in PgBouncer through 1.25.2 allows an unauthenticated remote attacker to crash the process. A malformed message can make the parser report success while leaving a required value unset, which is then dereferenced as a NULL pointer. The crash occurs before any credential is verified, so no valid account is required.…