Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Quest" — 1674 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1055
Esta semana
RSS
M Alto vulnerabilidad
18/09/2026
[CVE-2026-61833] zot is a container image and artifact registry based on the Open Container Initiative Distribution S…
zot is a container image and artifact registry based on the Open Container Initiative Distribution Specification. Prior to 2.1.18, the bearer authentication handler in pkg/api/authn.go maps every HTTP method other than GET and HEAD to the push action, so DELETE requests are not checked for the distinct delete permission. Bearer-authenticated requests also bypass the fine-grained DistSpecAuthzHandl…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-46655] virtio-win provides Windows paravirtualized drivers for QEMU and KVM. From mm210 until mm320, the Vi…
virtio-win provides Windows paravirtualized drivers for QEMU and KVM. From mm210 until mm320, the Viosock driver permits a low-privilege local process to submit an IOCTL_SELECT request with attacker-controlled VIRTIO_VSOCK_SELECT.Fdss[*].fd_count values that overflow the 32-bit sum used by VIOSockSelect for bounds checking. The wrapped sum can pass the FD_SETSIZE check even though an individual de…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-54148] http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0…
http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest does not compare the uri parameter in an Authorization: Digest response with the actual request URL. An attacker who captures a valid Digest authentication response can replay it against another URL served by the same realm, bypassing the per-r…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-10744] IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denia…
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to an integer overflow in MQINQ request validation.
M Alto vulnerabilidad
18/09/2026
[CVE-2025-14753] IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system. An…
IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93565] ### Summary `RtspMethods.valueOf()` silently strips trailing control bytes (any character with code…
### Summary `RtspMethods.valueOf()` silently strips trailing control bytes (any character with code point
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93568] HTTP/2 and HTTP/3 Extended CONNECT requests are downgraded as regular CONNECT requests
HTTP/2 and HTTP/3 Extended CONNECT requests are downgraded as regular CONNECT requests

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93569] HTTP/1 absolute-form Host mismatch is translated to HTTP/2 :authority, overriding the request-target…
HTTP/1 absolute-form Host mismatch is translated to HTTP/2 :authority, overriding the request-target authority
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93592] vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and …
vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attackers to crash the engine by submitting negative token IDs. A single request with a negative token ID triggers a CUDA device-side assertion that poisons the GPU context, causing all subsequent requests to fail until the process restarts.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93491] A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vul…
A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1 requests on a single connection and withholding reads. This action causes the methodOverflowQueue to grow without limit, leading to unbounded heap memory consumption and a denial of service due to memory exhaustion.
M Alto vulnerabilidad
18/09/2026
Vulnerabilidad de bypass de autenticación en Quarkus HTTP (CVE-2026-87743)
Se identificó una falla alta en el módulo de seguridad HTTP de Quarkus que permite a atacantes no autenticados eludir controles de autorización mediante manipulación de rutas. Un adversario puede crafted URLs que el validador de seguridad interpreta como públicas, pero que se enrutan a endpoints protegidos, comprometiendo acceso a datos sensibles. Afecta especialmente a aplicaciones empresariales en LATAM que usan Quarkus en producción sin actualizar.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-89058] A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflec…
A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Credentials: true. This permissive cross-origin policy allows a malicious website to make credentialed cross-origin requests and read authenticated responses from a victim's session, re…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-89059] A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodie…
A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small crafted image declaring enormous dimensions to trigger a very large memory allocation, exhausting the JVM heap and resulting in a denial of service.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-87771] The Product Question and Answer WordPress plugin through 1.1.0 does not sanitize and escape paramete…
The Product Question and Answer WordPress plugin through 1.1.0 does not sanitize and escape parameters before using them in SQL queries on AJAX actions available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-18911] ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass…
ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93456] django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin…
django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing attackers to forge requests that modify page content. Signed-in editors visiting a malicious page can be tricked into storing unescaped content that renders to all visitors, enabling stored cross-site scripting attacks.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93450] go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON pars…
go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to unbounded recursion with no depth limit. Remote unauthenticated attackers can submit deeply nested JSON documents to services accepting OpenAPI specifications, causing fatal stack overflow that terminates the process and all in-flight requests.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93453] SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the a…
SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauthenticated attackers to redirect recovery tokens to attacker-controlled domains. Attackers can submit password recovery requests with a malicious Origin header to have valid password-reset tokens mailed to victim recovery addresses within links pointing to attacker infrastruc…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-93436] vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests …
vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests in prefill/decode disaggregated deployments. Remote attackers can submit requests with max_tokens=0 to exhaust decode-worker memory without bound until the worker restarts.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-85917] Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate pr…
Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.