Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,331
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1201
Esta semana
RSS
M Alto vulnerabilidad
15/09/2026
[CVE-2026-88616] An issue in RuoYi-Vue-Plus 6.0.0 allows a remote attacker to execute arbitrary code via the FlwTaskC…
An issue in RuoYi-Vue-Plus 6.0.0 allows a remote attacker to execute arbitrary code via the FlwTaskController.java component, and the FlwTaskServiceImpl.completeTask, CompleteExecuteComponent.process, Warm-Flow TaskService.skip, POST /workflow/task/completeTask components
M Alto vulnerabilidad
15/09/2026
[CVE-2026-79425] An authenticated Server-Side Request Forgery (SSRF) in the /adminapi/file/online_upload component of…
An authenticated Server-Side Request Forgery (SSRF) in the /adminapi/file/online_upload component of CRMEB v6.0.0 allows attackers to scan internal resources via a crafted POST request.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-57586] CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents. Prior t…
CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents. Prior to 1.3.1, the default agent-coderag sync flow in code_rag/entry/cli.py calls sync_dependencies for an indexed path, and code_rag/core/manager.py treats build.gradle or build.gradle.kts as sufficient to invoke _sync_gradle. _sync_gradle prefers a repository-controlled gradlew or gradlew.bat file and p…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-55178] GeoLens is a self-hosted geospatial data catalog with semantic search, OGC and STAC APIs, and a map …
GeoLens is a self-hosted geospatial data catalog with semantic search, OGC and STAC APIs, and a map builder. Prior to 1.2.3, multiple read and link endpoints authorize only the resource named in the request URL and fail to re-authorize a second caller-influenced dataset reached through a relationship, map layer, VRT source, externalId lookup, or request body. When a public map references a private…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-53957] Contentful MCP Server is a Model Context Protocol server for the Contentful Management API. Prior to…
Contentful MCP Server is a Model Context Protocol server for the Contentful Management API. Prior to @contentful/mcp-server 1.7.19 and @contentful/mcp-tools 0.4.5, export_space and import_space in packages/mcp-tools/src/tools/jobs/space-to-space-migration/exportSpace.ts and packages/mcp-tools/src/tools/jobs/space-to-space-migration/importSpace.ts expose host, proxy, rawProxy, and insecure network …
M Alto vulnerabilidad
15/09/2026
[CVE-2026-54167] Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositor…
Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, the GitHub App provider accepts X-GitHub-Enterprise-Host as the API host while processing webhook events containing an installation.id, before webhook signature validation or confirmation that the host matches the repository URL in the signed payload…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-16140] OpenBMC's IPMI implementation, phosphor-net-ipmid, is vulnerable to a logic flaw where the authoriza…
OpenBMC's IPMI implementation, phosphor-net-ipmid, is vulnerable to a logic flaw where the authorization context of an existing session can be replaced with a target account while still maintaining the original integrity and encryption keys. Several downstream vendors implement phosphor-net-ipmid as their IPMI stack, such as NVIDIA and H3C. This issue effectively allows for privilege escalation wi…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
15/09/2026
[CVE-2026-16141] OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic flaw in which an unauthenticated…
OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic flaw in which an unauthenticated client can force the RAKP Message 1 handler to return before it overwrites the authentication object's constructor defaults. The IPMI service then accepts a RAKP Message 3 whose HMAC is computed with the constant 20-byte 'userKey' initialized from the string '0penBmc' and an often-predictable 'bmcR…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92073] Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 1…
Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92062] Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, …
Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92055] Privilege escalation in the DevTools component. This vulnerability was fixed in Firefox 156 and Fire…
Privilege escalation in the DevTools component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92054] Privilege escalation in the Memory component. This vulnerability was fixed in Firefox 156 and Firefo…
Privilege escalation in the Memory component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92053] Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox…
Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92047] Privilege escalation in the Crash Reporting component. This vulnerability was fixed in Firefox 156 a…
Privilege escalation in the Crash Reporting component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92052] Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. This vulner…
Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92043] Privilege escalation due to incorrect boundary conditions in the Audio/Video component. This vulnera…
Privilege escalation due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92033] Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 156.
Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 156.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92015] Privilege escalation in the WebExtensions component. This vulnerability was fixed in Firefox 156, Fi…
Privilege escalation in the WebExtensions component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, and Firefox ESR 153.3.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92017] Privilege escalation in the DOM: Service Workers component. This vulnerability was fixed in Firefox …
Privilege escalation in the DOM: Service Workers component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, and Firefox ESR 153.3.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92020] Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component. This…
Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, and Firefox ESR 153.3.