Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1055
Esta semana
RSS
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-107207] LMCache through 0.5.5 contains a server-side request forgery vulnerability in its frontend monitorin…
LMCache through 0.5.5 contains a server-side request forgery vulnerability in its frontend monitoring service that allows unauthenticated attackers to bypass the proxy allowlist by registering arbitrary hosts. Attackers can add entries via POST /api/proxies and then use /proxy or /proxy2 to reach internal hosts, read responses, and tamper with nodes or stop the heartbeat.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-77214] libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_Par…
libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_ParseBuffer advances the parse buffer end with parser->m_bufferEnd += len using a caller-supplied length that is not validated against the allocated buffer size, so repeated XML_ParseBuffer calls move m_bufferEnd past the end of the heap allocation and subsequent parsing reads out of bounds. Reaching t…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-46570] In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_index_walk_down() in libntfs-3g/in…
In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_index_walk_down() in libntfs-3g/index.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by reading the special crafted file metadata.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-106560] Backstage is an open framework for building developer portals. Prior to 0.3.25, the @backstage/plugi…
Backstage is an open framework for building developer portals. Prior to 0.3.25, the @backstage/plugin-scaffolder-backend-module-confluence-to-markdown package is affected by improper repository path validation in a scaffolder backend module. An authenticated user who can execute an affected template and control its repository file location may cause generated content to be written outside the task…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-106558] Backstage is an open framework for building developer portals. Prior to 1.14.8, 1.15.6, and 2.0.1, t…
Backstage is an open framework for building developer portals. Prior to 1.14.8, 1.15.6, and 2.0.1, the @backstage/plugin-techdocs-node package improperly validated mapping-style markdown_extensions configuration. An authenticated attacker who can register or influence an SCM-backed documentation source may bypass TechDocs sanitization and cause Python objects to be imported and instantiated in the…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-106510] Backstage is an open framework for building developer portals. Prior to 1.14.6, the @backstage/plugi…
Backstage is an open framework for building developer portals. Prior to 1.14.6, the @backstage/plugin-techdocs-node package is affected by remote code execution via crafted markdown_extensions in techdocs mkdocs.yml. An authenticated user who can register catalog entities can provide a crafted mkdocs.yml causing arbitrary OS command execution on the TechDocs build host when the docs are built. Thi…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-106556] Backstage is an open framework for building developer portals. Prior to 1.14.6, the @backstage/plugi…
Backstage is an open framework for building developer portals. Prior to 1.14.6, the @backstage/plugin-techdocs-node package is affected by configuration bypass in techdocs mkdocs.yml sanitization. Insufficient validation of MkDocs configuration during TechDocs generation could allow an authenticated user who can register or modify documentation sources to execute arbitrary commands in the build en…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-46572] In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ib_cut_tail() in libntfs-3g/index.…
In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ib_cut_tail() in libntfs-3g/index.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by creating a file in a specially crafted directory.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-46434] wger is a free, open-source workout and fitness manager. Prior to version 2.6, a user with only the …
wger is a free, open-source workout and fitness manager. Prior to version 2.6, a user with only the `gym_trainer` permission can deactivate any account in the same gym, including `gym_manager` and `general_gym_manager` accounts. The `UserDeactivateView` grants access to anyone holding any one of `gym.manage_gym`, `gym.manage_gyms`, or `gym.gym_trainer` (OR logic via `WgerMultiplePermissionRequired…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-107183] llama.cpp before b11393 contains a use-after-free and double free vulnerability in common_chat_peg_m…
llama.cpp before b11393 contains a use-after-free and double free vulnerability in common_chat_peg_mapper::map that allows unauthenticated remote attackers to corrupt heap memory via a dangling current_tool pointer. Attackers can submit a chat_parser in a POST /completion request emitting a tool-id after a tool-close tag to crash llama-server and shape a heap write primitive.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-42618] In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_decompress() in compress.c that al…
In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_decompress() in compress.c that allows an attacker to corrupt one byte of heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by reading the special crafted file.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-43976] wger is a free, open-source workout and fitness manager. Prior to version 2.6, five gym management v…
wger is a free, open-source workout and fitness manager. Prior to version 2.6, five gym management views in wger apply a flawed gym-scope guard (`gym_a != gym_b`) that silently passes when both operands are `None`. A trainer with `gym.gym_trainer` and `gym.add_adminusernote` permissions and no gym assignment (`gym=None`) can read private admin notes, uploaded documents, gym contracts, user configu…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-42617] In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ir_to_ib() in index.c that allows …
In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ir_to_ib() in index.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by extending a directory, e.g., by creating a file.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-107181] Telegram Desktop before 7.2.9 contains an IPC record-separator injection vulnerability in Core::Sand…
Telegram Desktop before 7.2.9 contains an IPC record-separator injection vulnerability in Core::Sandbox that allows remote attackers to inject OPEN: records via crafted tg:// links containing unescaped semicolons. Attackers can reach the interpret: scheme handler to upload local files, including tdata session keys, to an attacker channel, enabling account takeover.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-102257] A Zip Slip vulnerability in the in the SMA1000 Appliance Management Console (AMC) interface allows a…
A Zip Slip vulnerability in the in the SMA1000 Appliance Management Console (AMC) interface allows an attacker to extract files outside the intended destination directory using a specially crafted archive, resulting in remote code execution.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-102256] Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command I…
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 appliance which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.
M Alto vulnerabilidad
Hace 3 días
Vulnerabilidad de inyección de comandos en GitAhead 2.7.1 para macOS (CVE-2026-106059)
GitAhead versión 2.7.1 y anteriores en macOS contiene una vulnerabilidad de inyección de comandos que permite a atacantes ejecutar comandos de shell mediante nombres de repositorios manipulados. La falla reside en la interpolación sin escapado de rutas de archivos en AppleScript, ejecutándose con privilegios del usuario víctima cuando se selecciona la opción 'Show in Finder'. Desarrolladores y equipos de DevOps en LATAM que usen GitAhead en macOS están expuestos si trabajan con repositorios de terceros o compartidos.
M Alto vulnerabilidad
Hace 3 días
Inyección SQL ciega en plugin WP Post Author afecta sitios WordPress hasta versión 4.0.0
Se identificó una vulnerabilidad de inyección SQL ciega (CVE-2026-42708, CVSS 7.6) en el plugin AF themes WP Post Author para WordPress que afecta versiones hasta 4.0.0. Un atacante podría ejecutar comandos SQL no autorizados para extraer datos sensibles de bases de datos. Este riesgo impacta directamente a empresas, gobiernos y organizaciones en México y LATAM que usan este plugin en sitios públicos o administrativos.
M Alto vulnerabilidad
Hace 3 días
Inyección SQL en Slider by 10Web permite acceso no autorizado a bases de datos
Se identificó una vulnerabilidad de inyección SQL ciega en el plugin Slider by 10Web (versiones hasta 1.2.63) que permite a atacantes ejecutar comandos SQL maliciosos contra bases de datos. Esta vulnerabilidad afecta directamente a sitios WordPress en México y Latinoamérica que utilizan este plugin popular para galerías de imágenes, exponiendo información sensible de clientes y operaciones.
M Alto vulnerabilidad
Hace 3 días
Vulnerabilidad de inyección de comandos OS en Rundeck anterior a 6.2.0
Rundeck versiones anteriores a 6.2.0 contiene una vulnerabilidad de inyección de comandos en sistemas Windows que permite a usuarios autenticados con permisos de ejecución de trabajos ejecutar comandos arbitrarios en nodos Windows mediante opciones manipuladas. Los atacantes pueden inyectar metacaracteres de cmd.exe como && o | en opciones de texto libre, eludiendo la protección de comillas simples en CLIUtils.quoteWindowsCMDArg. Afecta especialmente a infraestructuras de orquestación en centros de datos y entornos híbridos de LATAM.