Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-71183] An authorization vulnerability in Apache DolphinScheduler allows authenticated users to obtain infor…
An authorization vulnerability in Apache DolphinScheduler allows authenticated users to obtain information about data sources they are not authorized to access through the /unauth-datasource and /authed-datasource endpoints. These endpoints fail to enforce the required data source access controls and return sensitive connection information, including data source passwords. As a result, an authe…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-71895] An authorization vulnerability in Apache DolphinScheduler allows authenticated non-admin users to re…
An authorization vulnerability in Apache DolphinScheduler allows authenticated non-admin users to retrieve Kubernetes configuration data intended for administrator-managed cluster configuration. The exposed kubeconfig data contains credentials that may allow users to authenticate directly to the Kubernetes API outside DolphinScheduler. The impact depends on the permissions granted to the disclo…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-66084] An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to modif…
An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to modify task definitions in projects they are not authorized to access through the /dolphinscheduler/projects/{projectCode}/task-definition/{code}/with-upstream endpoint. The endpoint fails to verify that the task definition identified by code belongs to the project specified by projectCode. An authent…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-66087] An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to opera…
An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to operate task instance in projects they are not authorized to access through the  * /dolphinscheduler/projects/{projectCode}/task-instances/{taskInstanceId}/stop * /dolphinscheduler/projects/{projectCode}/task-instances/{taskInstanceId}/savepoint This issue affects Apache DolphinSchedul…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-103309] The GPTranslate WordPress plugin before 2.34.14 does not properly restrict who can store translatio…
The GPTranslate WordPress plugin before 2.34.14 does not properly restrict who can store translations, and does not escape them when outputting them in translated pages, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks when server-side translations are enabled.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-17196] The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Unrestricted File T…
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up to, and including, 6.3.316 via the upload_files function. This is due to missing file type validation in the upload_files function, which reads and applies an attacker-controlled extensions string from _super_elements post meta verbatim as the allowed MIME type map. Thi…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-82627] The Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Inc…
The Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.6.1.1 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object when a third-party integration plu…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-89322] Vault and Vault Enterprise did not consistently evaluate ACL policies against the canonical form of …
Vault and Vault Enterprise did not consistently evaluate ACL policies against the canonical form of resource and policy names. This may allow an authenticated user with delegated permissions to bypass an explicit deny restriction and access a protected resource or assign a denied policy, potentially leading to privilege escalation. This vulnerability (CVE-2026-89322) is fixed in Vault Community Ed…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-107230] The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and async…
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 3.0.14, connection-pool partitioning still omits identity-defining fields for Kerberos, SPNEGO, NTLM, and authenticated proxy connections. Logins without a configured principal, proxy realms, identities sharing a user name, and SOCKS or CONNECT prox…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-107232] The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and async…
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 on 3.x and 2.16.1 on 2.x, the client infers that an HTTP proxy tunnel exists from the last request method rather than the CONNECT result. After a proxy rejects CONNECT, redirect or authentication handlers can write an origin request and its Authoriza…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-105816] Vault and Vault Enterprise did not consistently verify that stored plugin catalog entries reference …
Vault and Vault Enterprise did not consistently verify that stored plugin catalog entries reference binaries within the configured plugin directory. When Vault uses Shamir seals and has an external plugin directory configured, a privileged operator able to restore an Integrated Storage (Raft) snapshot may be able to execute arbitrary code on the Vault host. This vulnerability (CVE-2026-105816) is …
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-76266] In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15 on Linux, a local user who c…
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15 on Linux, a local user who can run commands as the user account running Splunk Enterprise could cause an affected Linux package upgrade to run attacker-controlled operating-system commands with root privileges. The vulnerability is possible because the Linux package maintainer script trusts existing Splunk Enterprise installat…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-107352] Missing authorization checks in Amazon Athena engine version 3 request handling could have allowed a…
Missing authorization checks in Amazon Athena engine version 3 request handling could have allowed an authenticated user to read limited query metadata (AWS account identifiers and SQL statement text) from other AWS accounts. Query results, credentials, and Amazon S3 data were not affected. AWS remediated the issue on September 1, 2026, and has confirmed no customer metadata was accessed. No custo…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-107227] The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and async…
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.2.0 until 3.0.14, WebSocket permessage-deflate decompression is unbounded when compression is enabled. The inbound pipeline aggregates compressed frames before WebSocketClientCompressionHandler inflates them, so webSocketMaxFrameSize and webSocketMaxBufferSiz…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-107161] A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DI…
A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes the size of the buffer needed for a challenge/response field before DIGEST-MD5 quoting is applied, but does not recompute that size when quoting (escaping special characters) makes the value longer. The under-sized buffer is then passed to strcat(), causing a heap-based out-…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-107219] Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 t…
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, agile decryption accepts an attacker-controlled spinCount and performs that many password-key derivation iterations before verifier validation. OpenFile reaches agileDecrypt, which passes the unbounded spinCount to convertPasswdToKey before password verification. When a crafted OLE encrypt…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-107217] Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.0.0 t…
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.0.0 to 2.11.0 in github.com/xuri/excelize/v2 and from 1.1.0 to 1.4.1 in github.com/xuri/excelize, ColumnNameToNumber accumulates a bijective base-26 value in int64 without detecting overflow, allowing an invalid long column name to wrap to zero with no error. ColumnNameToNumber accepts the overflowing na…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-106164] In Progress® Telerik® Document Processing SpreadProcessing library, versions prior to 2026.3.1006, a…
In Progress® Telerik® Document Processing SpreadProcessing library, versions prior to 2026.3.1006, an infinite loop vulnerability exists when importing an XLS file with a specifically-targted corruption, the import timeout is ignored resulting in an unresponsive CPU thread and denial of service.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-96335] Missing Authorization vulnerability in WPMU DEV Forminator allows Exploiting Incorrectly Configured …
Missing Authorization vulnerability in WPMU DEV Forminator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Forminator: from n/a through 1.57.2.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-107214] Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 t…
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, the decryption dispatch performs insufficient structural and parameter validation before standard and agile decryptors slice, index, allocate, and divide using attacker-controlled values. Decrypt passes attacker-controlled EncryptionInfo and EncryptedPackage data into standardDecrypt or ag…