Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 41 min
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1009
Esta semana
RSS
M Alto vulnerabilidad
25/09/2026
[CVE-2026-94445] A malicious txtar could escape the intended execution context and force arbitrary writes to the play…
A malicious txtar could escape the intended execution context and force arbitrary writes to the playground host's trusted filesystem. Disjointly, one of the three possible paths to invoke go vet on the playground host did not correctly restrict the execution environment. This permitted a Go process to make a read for an environment configuration file rooted in the playground host's $HOME. To…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-97865] A security flaw has been discovered in Open-Web-Analytics up to 1.8.1. Affected is the function Even…
A security flaw has been discovered in Open-Web-Analytics up to 1.8.1. Affected is the function Event::loadFromArray of the file queue.php of the component Remote Event Queue Endpoint. Performing a manipulation results in deserialization. The attack can be initiated remotely. Upgrading to version 1.8.2 is able to address this issue. The patch is named 78c1222ec0e2119d84684032da1541120a2cdd23. The …
M Alto vulnerabilidad
25/09/2026
[CVE-2026-85750] Piwigo before v16.4.0 is vulnerable to arbitrary file read and remote code execution in image upload…
Piwigo before v16.4.0 is vulnerable to arbitrary file read and remote code execution in image upload handling when using the Imagick library due to insufficient validation and unsafe processing of user-supplied image files. By abusing format confusion (e.g., disguising SVG content as PNG), an attacker can trigger unintended interpretation of embedded SVG elements that reference local files. In mor…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-97182] A security vulnerability has been detected in halo-dev Halo up to 2.25.4/2.26.1. Affected is an unkn…
A security vulnerability has been detected in halo-dev Halo up to 2.25.4/2.26.1. Affected is an unknown function of the file application/src/main/java/run/halo/app/content/comment/ReplyNotificationSubscriptionHelper.java of the component SpEL Handler. Such manipulation leads to improper neutralization. The attack may be performed from remote. The exploit has been disclosed publicly and may be used…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-86679] ZohoCorp ManageEngine Applications Manager versions 182000 and below were vulnerable to a permission…
ZohoCorp ManageEngine Applications Manager versions 182000 and below were vulnerable to a permissions validation issue that allowed a low-privileged user to delete service monitors outside their assigned scope.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-86683] ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user t…
ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to change the proxy settings.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-76980] ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to…
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Data Exposure vulnerability in the Firewall Analyzer syslog collector.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
22/09/2026
[CVE-2026-19480] CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result …
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-82003] Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability that could re…
Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-77605] Notepad++ is a free and open-source source code editor. Prior to 8.9.8, the Folder as Workspace Run …
Notepad++ is a free and open-source source code editor. Prior to 8.9.8, the Folder as Workspace Run by system action in Notepad++ can resolve a different sibling file than the file selected by the user. When an attacker places a command script whose name is the selected text-file path with .cmd appended, and the user invokes Run by system on the text file on Windows 10 or Windows 11, Notepad++ can…
M Alto vulnerabilidad
21/09/2026
[CVE-2026-49453] Joplin is an open source note-taking and to-do application that organises notes and lists into noteb…
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.6.15 and 3.7.2, Joplin accepts synchronized resource metadata whose id or file_extension contains parent-directory or path-separator characters. BaseItem.unserialize() stores the unvalidated fields, resourceFilename() concatenates them into a destination path, and ResourceFetcher wr…
M Alto vulnerabilidad
21/09/2026
[CVE-2026-73547] Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36…
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's ext_authz filter assumes that a request contains a :path pseudoheader when applying query_parameters_to_set or query_parameters_to_remove from an authorization response. A path-less CONNECT request makes request_headers_->Path() return null, and Filter::onCom…
M Alto vulnerabilidad
21/09/2026
[CVE-2026-73552] Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36…
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy HTTP RBAC accepts RFC-valid opaque header bytes but evaluates safe_regex values with RE2's UTF-8 subject semantics. A downstream client can preserve a prohibited marker and add an unrelated obs-text octet, causing RE2::FullMatch to return false and a negative R…
M Alto vulnerabilidad
21/09/2026
[CVE-2026-73513] Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36…
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's optional oghttp2 upstream HTTP/2 codec accepts a response trailer HEADERS frame without END_STREAM. Envoy completes and deferred-deletes the ActiveRequest while oghttp2 keeps the stream open, leaving ClientStreamImpl with a dangling response_decoder_ referenc…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-81180] SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users …
SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor Professional can upload image files whose formats cause image processing to invoke Ghostscript, allowing embedded PostScript to operate in the shared temporary directory. An attacker can combine that behavior with a race involving GnuPG configuration files in temporary subdirectories to…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93567] HTTP/1 authority-form CONNECT is translated to malformed HTTP/2 CONNECT with Host-controlled :author…
HTTP/1 authority-form CONNECT is translated to malformed HTTP/2 CONNECT with Host-controlled :authority
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93568] HTTP/2 and HTTP/3 Extended CONNECT requests are downgraded as regular CONNECT requests
HTTP/2 and HTTP/3 Extended CONNECT requests are downgraded as regular CONNECT requests
M Alto vulnerabilidad
18/09/2026
[CVE-2026-12954] The Mapster WP Maps plugin for WordPress is vulnerable to Arbitrary User Meta Write in all versions …
The Mapster WP Maps plugin for WordPress is vulnerable to Arbitrary User Meta Write in all versions up to, and including, 1.23.0 via the `my_profile_update()` function. This is due to the function performing no nonce verification, no capability check, and no allowlist validation on the meta key supplied via the `acf-photo-gallery-groups` POST parameter before passing both the meta key and its corr…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-18911] ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass…
ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-81875] HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in J…
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.12, SHCParser in org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/elementmodel/SHCParser.java can consume attacker-controlled Smart Health Card JWT content whose header contains zip: "DEF" and whose small raw-DEFLATE payload expands to a very large value. SHCParser.decodeJWT()…