Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Apache" — 217 resultados ✕ Limpiar búsqueda
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1020
Esta semana
RSS
M Alto vulnerabilidad
01/10/2026
Vulnerabilidad XXE alta en Apache Camel Quarkus permite lectura de archivos locales
Apache Camel Quarkus versiones 3.2.0-3.33.2 y 3.34.0-3.39.x contienen una vulnerabilidad de inyección XXE (XML External Entity) en su extensión de soporte XSLT que permite a atacantes leer archivos locales o realizar solicitudes a sistemas internos. Empresas en México y LATAM que usan Camel Quarkus en pipelines de integración de datos quedan expuestas a filtración de credenciales y configuraciones sensibles.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-85532] Apache WSS4J accepted attacker-controlled derived-key lengths and offsets without adequate bounds. T…
Apache WSS4J accepted attacker-controlled derived-key lengths and offsets without adequate bounds. This could permit cryptographically weak keys or excessive CPU and memory consumption when processing crafted WS-Security messages. The fixes enforce a minimum key length of 16 bytes, a maximum length of 512 bytes, and a maximum offset of 4096 bytes. Users are recommended to upgrade to versions 4.0.2…
M Alto vulnerabilidad
30/09/2026
Vulnerabilidad en Apache MINA SSHD permite eludir autenticación multifactor SSH
Apache MINA SSHD, librería Java para SSH cliente-servidor, presenta una vulnerabilidad alta (CVSS 8.1) que permite eludir esquemas de autenticación multifactor configurados en servidores SSH. Afecta principalmente a infraestructuras Java en LATAM que implementan autenticación de múltiples claves públicas. La falla compromete sistemas de acceso remoto en empresas, data centers y plataformas en la nube que dependen de esta librería.
M Alto vulnerabilidad
30/09/2026
Agotamiento de memoria en clientes SFTP de Apache MINA SSHD (CVE-2026-94002)
Apache MINA SSHD versiones 0.9.0 a 2.19.0 y 3.0.0-M1 a 3.0.0-M5 contienen una vulnerabilidad de agotamiento de memoria en el componente sshd-sftp. El cliente SFTP (DefaultSftpClient) no valida que las respuestas recibidas correspondan a solicitudes legítimas, permitiendo consumo excesivo de recursos. Afecta a aplicaciones Java que utilizan esta biblioteca para transferencia de archivos segura.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102495] Apache XmlSchema doesn't limit how deeply schema imports and includes can be nested, so a malicious …
Apache XmlSchema doesn't limit how deeply schema imports and includes can be nested, so a malicious schema can make parsing recurse until the stack overflows. This causes a denial of service. Users are recommended to upgrade to version 2.3.3, which fixes this issue.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102496] Apache XmlSchema doesn't limit how deeply schema structures can be nested when it builds its schema …
Apache XmlSchema doesn't limit how deeply schema structures can be nested when it builds its schema model, so a malicious schema can make parsing recurse until the stack overflows. This causes a denial of service. Users are recommended to upgrade to version 2.3.3, which fixes this issue.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102497] The Apache XmlSchema walker (xmlschema-walker) doesn't detect cycles in type derivation, substitutio…
The Apache XmlSchema walker (xmlschema-walker) doesn't detect cycles in type derivation, substitution groups, model groups or attribute groups. A malicious schema with such a cycle can make the walker recurse until the stack overflows, causing a denial of service. Users are recommended to upgrade to version 2.3.3, which fixes this issue.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
28/09/2026
[CVE-2026-101292] Apache ActiveMQ Artemis before 2.34.0 contains an unsafe reflection vulnerability in FederationStrea…
Apache ActiveMQ Artemis before 2.34.0 contains an unsafe reflection vulnerability in FederationStreamConnectMessage.getFederationPolicy(). The method calls Class.forName(clazz).getConstructor().newInstance() where clazz is read directly from the CORE protocol wire buffer without type validation. An authenticated federation peer can send a FEDERATION_DOWNSTREAM_CONNECT packet with a crafted class n…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-82383] Missing Authentication for Critical Function in Apache Roller 6.1.5 allows an unauthenticated remote…
Missing Authentication for Critical Function in Apache Roller 6.1.5 allows an unauthenticated remote attacker to persistently change a site-global configuration value (the frontpage weblog selection) on any installed instance, because the setup action remains anonymously reachable after installation and persists configuration without an authorization check. No optional feature or non-default confi…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-82386] Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a weblog adminis…
Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a weblog administrator to read files readable by the Roller process and reach internal network addresses by importing a crafted OPML document, because the bookmark import parser does not disable external entity resolution. No non-default configuration is required; the import is reached through the administrator boo…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-82375] Server-Side Request Forgery (SSRF) in Apache Roller 6.1.5 allows an authenticated user with entry-ed…
Server-Side Request Forgery (SSRF) in Apache Roller 6.1.5 allows an authenticated user with entry-editing rights on a weblog to cause outbound HTTP requests to attacker-chosen destinations through legacy outbound Trackback and entry enclosure handling. The Trackback control is hidden in the standard UI, but its action remains directly reachable; the enclosure path is relevant only when an author s…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-82376] Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a user with entr…
Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a user with entry-editing rights on a weblog to cause the server to parse an attacker-influenced trackback response with an XML parser that does not disable external entity resolution, leading to disclosure of files readable by the Roller process. The Trackback control is hidden in the standard UI, but its action r…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-82379] Authentication Bypass by Capture-replay in Apache Roller 6.1.5 allows an attacker who captures a val…
Authentication Bypass by Capture-replay in Apache Roller 6.1.5 allows an attacker who captures a valid WSSE digest authentication header to replay it and gain the victim's AtomPub authority, because the authentication does not enforce nonce uniqueness or timestamp freshness. Only installations that enable the non-default AtomPub API with WSSE authentication and plaintext-compatible password storag…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-82380] Cross-Site Request Forgery (CSRF) in Apache Roller 6.1.5 allows a remote attacker to cause a logged-…
Cross-Site Request Forgery (CSRF) in Apache Roller 6.1.5 allows a remote attacker to cause a logged-in user to perform state-changing actions under the victim's authority, because the CSRF validation filters accept a request that does not submit the required salt token, validating instead against a value the server itself generated for the request. No optional feature or non-default configuration …
M Alto vulnerabilidad
28/09/2026
[CVE-2026-82348] Authorization Bypass Through User-Controlled Key in Apache Roller 6.1.5 allows an authenticated user…
Authorization Bypass Through User-Controlled Key in Apache Roller 6.1.5 allows an authenticated user with authoring rights on one weblog to read, modify, or delete resources belonging to another weblog through unscoped identifier-based lookups. This affects multi-user installations where users are intended to be isolated between weblogs; no optional feature or non-default configuration is required…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
25/09/2026
[CVE-2026-92550] A pre-authentication attacker could leverage type size/count handling to cause excessive allocation …
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue.
M Alto vulnerabilidad
25/09/2026
[CVE-2026-92560] A pre-authentication attacker could leverage type size/count handling to cause excessive allocation …
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue.
M Alto vulnerabilidad
25/09/2026
[CVE-2026-92608] Improper handling of property-encoding exceptions in AMQP 1.0-to-AMQP 0-10 message conversion allows…
Improper handling of property-encoding exceptions in AMQP 1.0-to-AMQP 0-10 message conversion allows authenticated message producers to disrupt delivery to AMQP 0-10 consumers via message properties that the target encoder does not handle correctly. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue.
M Alto vulnerabilidad
24/09/2026
[CVE-2026-57590] A missing authorization vulnerability exists in the Task Group APIs of Apache DolphinScheduler. The …
A missing authorization vulnerability exists in the Task Group APIs of Apache DolphinScheduler. The affected APIs do not properly verify whether the authenticated user has permission to access the project associated with the target Task Group. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-86247] Race condition within a thread vulnerability in Apache Tomcat Native allowed client certificate veri…
Race condition within a thread vulnerability in Apache Tomcat Native allowed client certificate verification requirements to be down-graded for some configurations. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Unsupported versions may also be affected. Users are recommended to upgrade to version 2.0.16 or 1.3.9, which fixes the issue.