Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
Buscando: "Perl" — 354 resultados ✕ Limpiar búsqueda
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1003
Esta semana
RSS
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102697] Ollama versions 0.14.0 before 0.31.2 contain an incorrect authorization vulnerability in the experim…
Ollama versions 0.14.0 before 0.31.2 contain an incorrect authorization vulnerability in the experimental agent mode Bash tool approval mechanism that fails to properly parse shell syntax. Attackers who can influence model output through prompt injection can execute additional shell commands by appending control operators like semicolons or logical operators to approved commands, bypassing the ses…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-86450] Insertion of sensitive information into sent data vulnerability in Parla Auto Automotive Trading Lim…
Insertion of sensitive information into sent data vulnerability in Parla Auto Automotive Trading Limited Company DetaWix Mobile Web Portal allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects DetaWix Mobile Web Portal: before v1.0.19.
M Alto vulnerabilidad
28/09/2026
[CVE-2026-101091] SiYuan versions before v3.8.4 fail to properly validate SQL statements in block query embed blocks e…
SiYuan versions before v3.8.4 fail to properly validate SQL statements in block query embed blocks executed against siyuan.db. Attackers can craft malicious .sy documents with non-read-only SQL statements that execute automatically during background indexing, rendering, or export operations without authentication.
M Alto vulnerabilidad
28/09/2026
Vulnerabilidad alta en productos Wi-Fi BUFFALO permite ejecución remota de comandos
BUFFALO Wi-Fi products procesa incorrectamente entradas en formularios web para construir cadenas de comandos del sistema operativo, permitiendo a usuarios administrativos ejecutar comandos OS arbitrarios mediante solicitudes HTTP maliciosamente elaboradas. Afecta principalmente a infraestructuras de conectividad en pequeñas y medianas empresas (PYMES) de México y Latinoamérica que utilizan equipos BUFFALO para redes corporativas.
M Alto vulnerabilidad
27/09/2026
[CVE-2026-101032] navi through 2.24.0 fails to properly escape cheatsheet variable values when substituting them into …
navi through 2.24.0 fails to properly escape cheatsheet variable values when substituting them into shell commands. Attackers can inject shell metacharacters through crafted file names in suggestion command directories to execute arbitrary commands with victim privileges.
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100685] Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint by workspace, allowi…
Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint by workspace, allowing builders to enumerate chat identity link records across all workspaces in a tenant. Attackers with builder access to a single workspace can retrieve sensitive chat identity linking data including user IDs and external chat service identifiers from other workspaces they have no permission to acces…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100676] January, the media proxy/embed service of stoatchat (stoatchat/stoatchat), before version 0.15.5 imp…
January, the media proxy/embed service of stoatchat (stoatchat/stoatchat), before version 0.15.5 improperly resolves SVG values as local filesystem paths when a fetched resource is served as image/svg+xml. An unauthenticated remote attacker who causes the service to proxy an attacker-hosted SVG (e.g. via the /proxy endpoint) can determine whether local files exist through observable r…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100643] SiYuan versions before v3.8.4 fail to properly escape four stored Attribute View values in textarea …
SiYuan versions before v3.8.4 fail to properly escape four stored Attribute View values in textarea elements, allowing authenticated attackers to inject JavaScript by modifying field descriptions, template sources, select option descriptions, or footer calculation templates. Attackers can execute stored JavaScript when other users open affected database menus, and in the Electron desktop app with …
M Alto vulnerabilidad
26/09/2026
Vulnerabilidad alta de autorización en OpenClaw anterior a 2026.7.1
OpenClaw versiones anteriores a 2026.7.1 presentan un fallo de autorización que permite a usuarios no-propietarios ejecutar cambios de configuración MCP mediante los comandos /mcp set y /mcp unset. Los atacantes pueden persistir comandos MCP arbitrarios en stdio que se ejecutan con los privilegios del proceso OpenClaw, comprometiendo la confidencialidad, integridad y disponibilidad del host. Este riesgo afecta principalmente a empresas en LATAM que utilizan OpenClaw en entornos de producción sin restricciones de acceso adecuadas.
M Alto vulnerabilidad
26/09/2026
Vulnerabilidad alta en OpenClaw Codex permite ejecución remota de código sin autorización
OpenClaw Codex anterior a versión 2026.7.1 presenta falla en validación de autorización que permite a usuarios no propietarios con acceso a comandos crear enlaces nativos y ejecutar operaciones con acceso a archivos, herramientas y procesos del sistema. Afecta principalmente a empresas que utilizan esta plataforma para orquestación de infraestructura en entornos cloud de LATAM.
M Alto vulnerabilidad
26/09/2026
Vulnerabilidad alta en OpenClaw anterior a 2026.7.1 permite ejecución de código arbitrario
OpenClaw versiones anteriores a 2026.7.1 presentan un defecto de validación de autorización en el comando de instalación Codex que permite a usuarios sin permisos instalar plugins arbitrarios y ejecutar procesos MCP con privilegios de OpenClaw. Esta vulnerabilidad compromete confidencialidad, integridad y disponibilidad de sistemas host, afectando servidores en entornos empresariales de México y Latinoamérica que utilicen esta plataforma.
M Alto vulnerabilidad
26/09/2026
Vulnerabilidad alta en OpenClaw Slack 2026.8.0 y anteriores permite bypass de políticas de remitentes
OpenClaw Slack versiones anteriores a 2026.8.1 no validan correctamente las listas de remitentes autorizados en mensajes directos grupales, permitiendo a participantes no autorizados activar agentes de Slack y acceder a herramientas y datos. Esta falla de control de acceso afecta principalmente a organizaciones en LATAM que utilizan automatización de Slack para gestionar datos sensibles, cumplimiento normativo y comunicaciones altas.
M Alto vulnerabilidad
26/09/2026
Vulnerabilidad alta en paquete npm OpenClaw permite ejecución de comandos arbitrarios
OpenClaw (paquete npm 'openclaw') versiones anteriores a 2026.7.1 presenta una falla en la validación de mayúsculas y minúsculas que permite a actores maliciosos eludir controles de seguridad y crear trabajos cron persistentes. Un agente con capacidad de herramientas puede ser manipulado para ejecutar comandos arbitrarios con los privilegios del proceso OpenClaw, comprometiendo servidores de aplicaciones altas en entornos empresariales de LATAM.
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100568] OpenClaw versions before 2026.8.1 fail to properly restrict access to operator command cron jobs, al…
OpenClaw versions before 2026.8.1 fail to properly restrict access to operator command cron jobs, allowing model-visible agent callers to read and execute ownerless command jobs. Attackers can inspect stored environment variables and force-run disabled or unscheduled command jobs to access secrets and execute operator-authored commands.
M Alto vulnerabilidad
25/09/2026
[CVE-2026-100390] Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field wh…
Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers connecting over IPv6 can supply arbitrary X-Forwarded-For values to spoof their source IP and bypass authorization provider IP-based access controls.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
25/09/2026
[CVE-2026-5267] Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an eve…
Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an event-streaming API that does not properly enforce authentication. An unauthenticated attacker with network access to the affected service could access the event stream and potentially obtain sensitive information.
M Alto vulnerabilidad
25/09/2026
[CVE-2026-91839] A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager. The nm-fo…
A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager. The nm-fortisslvpn-service improperly handles carriage-return/line-feed (CR/LF) characters in VPN connection profile credentials. A local unprivileged user can exploit this by crafting a malicious VPN profile to inject additional configuration directives. This can lead to arbitrary code execution with root p…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-58007] Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of…
Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through socfpga_v2.14.0.
M Alto vulnerabilidad
24/09/2026
[CVE-2026-58008] Stack-based buffer overflow vulnerability in Altera Trusted Firmware on HPS allows Exploitation of I…
Stack-based buffer overflow vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through socfpga_v2.14.0.
M Alto vulnerabilidad
24/09/2026
[CVE-2026-58006] Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of…
Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through socfpga_v2.14.0.