Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 10 min
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1740
Esta semana
RSS
M Alto vulnerabilidad
04/08/2026
[CVE-2026-47613] NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of …
NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a restricted directory by supplying a crafted local path in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure.
M Alto vulnerabilidad
04/08/2026
[CVE-2026-47614] NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request for…
NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.
M Alto vulnerabilidad
04/08/2026
[CVE-2026-47615] NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request for…
NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery by supplying a crafted URL in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure.
M Alto vulnerabilidad
04/08/2026
[CVE-2026-18830] Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remot…
Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute configured tools bypassing model invocation and security controls via crafted content blocks in conversation messages. AWS has addressed this issue. No customer action is required.
M Alto vulnerabilidad
04/08/2026
[CVE-2026-24253] NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds writ…
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service and data tampering.
M Alto vulnerabilidad
04/08/2026
[CVE-2026-18788] A security flaw has been discovered in Trippo ResponsiveFilemanager up to 9.14.0. The impacted eleme…
A security flaw has been discovered in Trippo ResponsiveFilemanager up to 9.14.0. The impacted element is an unknown function of the file filemanager/dialog.php. The manipulation results in unrestricted upload. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in…
M Alto vulnerabilidad
04/08/2026
[CVE-2026-56848] A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly whil…
A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
04/08/2026
[CVE-2026-18787] A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. The affected element is the function r…
A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. The affected element is the function remove_rule of the file /usr/share/gl-ngx/oui-rpc.lua of the component RPC Endpoint. The manipulation of the argument args.id leads to command injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this d…
M Alto vulnerabilidad
04/08/2026
[CVE-2026-15307] An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups …
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse the right-hand-side value as a raster by passing it to the `django.contrib.gis.gdal.GDALRaster` constructor. Any value used in a spatial lookup against a `GeometryField` or `RasterField` reaches this constructor, including untrusted input, for example a spatial-field filter subm…
M Alto vulnerabilidad
04/08/2026
[CVE-2026-69100] LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execu…
LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database template fields without compilation restrictions or whitelisting. Attackers can write or influence the script field via message template endpoints to execute arbitrary Groovy code and OS commands on the backend …
M Alto vulnerabilidad
04/08/2026
[CVE-2026-25292] Memory Corruption when processing untrusted user input in the fastboot command handler for audio fra…
Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.
M Alto vulnerabilidad
04/08/2026
[CVE-2026-24083] Memory Corruption while processing IOCTL device driver requests with invalid arguments.
Memory Corruption while processing IOCTL device driver requests with invalid arguments.
M Alto vulnerabilidad
04/08/2026
[CVE-2026-24084] Weak configuration when UE does not verify the consistency of its additional security capabilities w…
Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.
M Alto vulnerabilidad
04/08/2026
[CVE-2026-25288] Transient DOS when processing a short target wake time channel usage response frame with insufficien…
Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.
M Alto vulnerabilidad
04/08/2026
[CVE-2026-24079] Cryptographic Issue while processing registration requests with malformed or missing authentication …
Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
04/08/2026
[CVE-2026-24080] Memory Corruption when handling malformed request parameters in the fingerprint TA.
Memory Corruption when handling malformed request parameters in the fingerprint TA.
M Alto vulnerabilidad
04/08/2026
[CVE-2026-21366] Memory corruption while processing a packet with a size close to the maximum allowed value.
Memory corruption while processing a packet with a size close to the maximum allowed value.
M Alto vulnerabilidad
04/08/2026
[CVE-2026-67195] Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attacke…
Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary operating system commands by submitting crafted expression strings to the PolarsVirtualServer backend, which passes client-supplied input directly to Python's eval() with only __builtins__={} cleared. Attackers can exploit Python object attribute traversal through the interpr…
M Alto vulnerabilidad
04/08/2026
[CVE-2026-67198] Perspective 5.0.0 contains a denial-of-service vulnerability in the VirtualServer protocol dispatche…
Perspective 5.0.0 contains a denial-of-service vulnerability in the VirtualServer protocol dispatcher that allows unauthenticated remote attackers to crash the server process by sending malformed or incomplete protobuf messages. Attackers can send well-formed requests such as ViewToArrowReq with no viewport set or MakeTableReq with no data field to trigger unwrap() calls on None values at nine dis…
M Alto vulnerabilidad
04/08/2026
[CVE-2026-67200] Perspective 5.0.0 contains a path traversal vulnerability that allows unauthenticated remote attacke…
Perspective 5.0.0 contains a path traversal vulnerability that allows unauthenticated remote attackers to read arbitrary files from the server filesystem by including literal ../ segments in HTTP request URL paths. Attackers can bypass the insufficient query-string-stripping sanitization to traverse outside the configured asset root directory and retrieve sensitive files such as system credentials…