Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 42 min
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1009
Esta semana
RSS
M Alto vulnerabilidad
21/09/2026
[CVE-2026-75939] A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy) rel…
A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy) release image signatures by checking for signature errors before the entire signed body is processed, leading to a bypass of the signature verification. A remote attacker, by intercepting or manipulating network traffic to the signature endpoint, could exploit this to craft a PGP message with a valid R…
M Alto vulnerabilidad
21/09/2026
Vulnerabilidad en verificación de firma de NooBaa-Core permite bypass de autenticación S3
Se identificó un defecto en la lógica de validación de firmas de noobaa-core que afecta la puerta de enlace multicloud de NooBaa. El servicio no rechaza correctamente solicitudes S3 con presigned URLs que contienen headers x-amz- sin firmar, permitiendo a atacantes eludir mecanismos de autenticación Signature Version 4 (SigV4). Empresas en LATAM que usan NooBaa para gestión de almacenamiento multicloud están en riesgo de acceso no autorizado a datos sensibles.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93657] hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Reso…
hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successful results. Attackers controlling the answering zone or positioned on the network path can have forged DNS records accepted as validated, bypassing DNSSEC authentication checks.
M Alto vulnerabilidad
18/09/2026
Vulnerabilidad alta en NetBackup Flex permite escalada a root sin autenticación adicional
Un usuario autenticado con privilegios bajos puede eludir la verificación criptográfica de comandos administrativos en NetBackup Flex OS proporcionando credenciales malformadas, obteniendo acceso root irrestricto. Esta vulnerabilidad afecta directamente a empresas en LATAM que dependen de NetBackup para respaldos y recuperación de datos altas, comprometiendo la integridad de toda la infraestructura de backup y los contenedores alojados.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-86038] libp2p is a JavaScript implementation of the libp2p networking stack. From 15.0.0 until 16.0.5, @lib…
libp2p is a JavaScript implementation of the libp2p networking stack. From 15.0.0 until 16.0.5, @libp2p/gossipsub uses the default StrictSign policy in packages/gossipsub/src/utils/buildRawMessage.ts, where validateToRawMessage verifies a signature with attacker-controlled msg.key but skips binding that key to msg.from when the claimed author is an RSA peer ID that does not inline a public key. An…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92718] Nuclei versions before 3.11.1 cache template signature verification based only on file modification …
Nuclei versions before 3.11.1 cache template signature verification based only on file modification time without content checksums. Attackers can replace verified templates with unsigned malicious content and restore the original modification time to bypass signature checks and execute arbitrary operating system commands.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-42784] A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates…
A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags subpacket is missing, leading to a discrepancy in how key capabilities are viewed. This key flag confusion allows an attacker to bypass the back-signature check. Consequently, an attacker can illegitimately bind an arbitrary subkey to their own certificate and forge signatures, com…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
15/09/2026
[CVE-2026-58200] Payload Plugins is a collection of plugins designed to enhance Payload CMS. From 0.3.0 until 0.4.0, …
Payload Plugins is a collection of plugins designed to enhance Payload CMS. From 0.3.0 until 0.4.0, @jhb.software/payload-cloudinary-plugin deployments with clientUploads enabled expose POST /api/cloudinary-generate-signature, whose handler in cloudinary/src/getGenerateSignature.ts passes attacker-controlled body.paramsToSign directly to cloudinary.utils.api_sign_request without a key allowlist, c…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-54155] node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the UserNameIde…
node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the UserNameIdentityToken authentication handler in packages/node-opcua-server/source/opcua_server.ts decrypts an RSA-OAEP password blob but does not verify that the trailing bytes match the current session serverNonce. An unauthenticated remote attacker can obtain the server public key through GetEndpoints and fo…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-57122] PraisonAI is a multi-agent teams system. Prior to 4.6.59, the WhatsApp and Linear bot webhook handle…
PraisonAI is a multi-agent teams system. Prior to 4.6.59, the WhatsApp and Linear bot webhook handlers verify HMAC signatures only when WHATSAPP_APP_SECRET or LINEAR_WEBHOOK_SECRET is configured and otherwise parse and dispatch unsigned request bodies. A remote unauthenticated client that reaches the webhook route can forge messages, comments, or agent-session events, impersonate platform users, i…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-80469] Ejecución arbitraria de código mediante carga de controladores maliciosos
Una vulnerabilidad alta permite a atacantes ejecutar código arbitrario en sistemas objetivo cargando paquetes de controladores maliciosos que eluden mecanismos de verificación. El impacto afecta principalmente a infraestructuras empresariales en LATAM que utilizan dispositivos de hardware con controladores sin validación adecuada. Requiere interacción del usuario para su explotación.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-73784] A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML respons…
A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML response, allowing an attacker to impersonate another user.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-89043] passport-saml-encrypted through 0.1.13 contains an XML signature wrapping vulnerability where signat…
passport-saml-encrypted through 0.1.13 contains an XML signature wrapping vulnerability where signature verification and assertion extraction use independent XPath lookups with no cross-validation. Attackers holding any validly signed SAML message can prepend a forged unsigned assertion that gets accepted as the verified identity while the genuine signature validates against the original assertion…
M Alto vulnerabilidad
09/09/2026
[CVE-2023-54355] PocketMine-MP versions before 5.3.1 and 4.23.1 fail to validate that the identityPublicKey in LoginP…
PocketMine-MP versions before 5.3.1 and 4.23.1 fail to validate that the identityPublicKey in LoginPacket uses the required secp384r1 elliptic curve. Attackers can provide LoginPackets with keys using different curves or non-EC key types to pass login verification but trigger an uncaught exception during ECDH key derivation, crashing the server.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69646] Improper verification of cryptographic signature in Skype for Business allows an unauthorized attack…
Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
08/09/2026
[CVE-2026-57098] Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized attack…
Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized attacker to disclose information over a network.
M Alto vulnerabilidad
07/09/2026
Vulnerabilidad en MCUboot y estrategia Direct XIP permite ejecución no autorizada en núcleos secundarios
MCUboot en configuración base no verifica adecuadamente la integridad de imágenes al usar la estrategia Direct XIP, permitiendo que la imagen principal inicie núcleos secundarios (radio, etc.) desde slots sin validar. Esto afecta sistemas embebidos y dispositivos IoT en operaciones altas de LATAM, especialmente en telecomunicaciones e industria.
M Alto vulnerabilidad
05/09/2026
[CVE-2026-52767] YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, HttpSignatureSe…
YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, HttpSignatureService::verifySignature() checks the result of PHP's openssl_verify() with a loose boolean negation - if (!openssl_verify(...)) { throw ... }. PHP's openssl_verify has four possible return values: 1, 0, -1, and "false". The -1 row is the bypass: PHP's truthiness rules make -1 a truthy value, so !(-1)…
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85525] Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a r…
Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a revoked TLS certificate to be accepted as valid, because OCSP responses were not reliably bound to the certificate being validated and definitive verification failures were treated as transient. A man-in-the-middle attacker holding a revoked certificate and its private key for a Snowflake or stage ho…
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85393] node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during …
node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage bytes inside the DigestAlgorithm sequence to forge valid signatures for arbitrary messages using low-exponent RSA keys. This is an incomplete fix for CVE-2026-33894.