Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ui" — 2786 resultados ✕ Limpiar búsqueda
22,298
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1168
Esta semana
RSS
M Alto vulnerabilidad
16/09/2026
[CVE-2026-89818] In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn: fix integer ove…
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check If the supplied msg[2] (num_buffers) is 0x3FFFFFFF, the expression 6 + num_buffers * 4 wraps to 2 and the bounds check passes, letting the parser loop far past the end of the message BO. Triggering it additionally requires a ~4GiB mapping so that msg[1] survives …
M Alto vulnerabilidad
16/09/2026
Vulnerabilidad alta en Arista EOS OSPFv3: reinicio no autorizado de agente
Una vulnerabilidad en Arista EOS con OSPFv3 configurado (CVSS 7.5) permite que paquetes especialmente crafteados causen el reinicio inesperado del agente OSPFv3, interrumpiendo la disponibilidad de enrutadores en infraestructuras altas. El impacto afecta principalmente a operadores de redes en centros de datos y proveedores de conectividad en LATAM que dependen de equipos Arista para su backbone de red.
M Alto vulnerabilidad
16/09/2026
Vulnerabilidad alta en Arista EOS con gNSI permite escalada de privilegios (CVE-2026-73454)
Plataformas Arista EOS con interfaz gRPC Network Security Interface (gNSI) Credentialz configurada son vulnerables a solicitudes especialmente diseñadas que modifican propiedades de cuentas de usuario. Un atacante podría asignar privilegios elevados a cuentas existentes, comprometiendo el control de acceso en infraestructura de red alta. El impacto afecta directamente a proveedores de servicios y centros de datos en LATAM que dependen de equipos Arista para segmentación y control de tráfico.
M Alto vulnerabilidad
16/09/2026
Vulnerabilidad alta en Arista EOS permite ejecución remota de código con privilegios root
Arista EOS presenta una vulnerabilidad (CVSS 8.8) en la interfaz gRPC Network Management Interface (gNMI) que permite a clientes autenticados ejecutar código arbitrario con privilegios root en switches de red. Afecta infraestructuras altas de centros de datos y proveedores de servicios en LATAM que utilizan equipos Arista con gNMI habilitado. El riesgo es elevado en entornos de nube privada y redes corporativas donde estos switches gestionan tráfico sensible.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-2380] Vulnerabilidad de registro no autorizado en Arista EOS con servicios OpenConfig
Plataformas Arista EOS ejecutando servicios OpenConfig (gNMI, gNSI, RESTCONF, NETCONF) registran inadecuadamente solicitudes y respuestas sensibles en el dispositivo local o servidores de contabilidad remota, exponiendo credenciales y configuraciones altas. La vulnerabilidad afecta infraestructuras de redes datacenter y carriers en LATAM que utilizan automatización basada en OpenConfig para gestión de equipos Arista.
M Alto vulnerabilidad
16/09/2026
XikeStor Layer3: Falla de autenticación en descarga de configuración (CVE-2026-88263)
Los switches Layer3 de XikeStor carecen de validación de autenticación en el servicio de descarga de datos de configuración, permitiendo a atacantes no autenticados recuperar credenciales y configuraciones de red. Esta exposición es alta en entornos corporativos de LATAM que utilizan estos equipos como infraestructura core, riesgando acceso lateral a sistemas internos y uso como puente de salto hacia redes segmentadas.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92299] @jitsi/electron-sdk before 10.0.5 exposes getDesktopSources() via contextBridge without requiring an…
@jitsi/electron-sdk before 10.0.5 exposes getDesktopSources() via contextBridge without requiring an active getDisplayMedia() picker, allowing any script in the meeting page to enumerate screens and windows. Attackers can call the jitsi-screen-sharing-get-sources IPC route to retrieve desktop thumbnails at arbitrary resolution without user consent or operating system permission prompts.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92215] A vulnerability has been found in a2ui-project a2ui up to 0.10.7. Affected by this vulnerability is …
A vulnerability has been found in a2ui-project a2ui up to 0.10.7. Affected by this vulnerability is the function httpx.get of the file agent_sdks/python/a2ui_agent/src/a2ui/extensions/file_resolve/file_resolver.py of the component FileResolver. The manipulation leads to server-side request forgery. It is possible to initiate the attack remotely. The identifier of the patch is 2bb8423060308bbdea8ba…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-76870] Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in the mtd_write pre…
Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in the mtd_write pre-flash validation routine triggered by short firmware uploads. Attackers can upload a truncated firmware image via put_file_cgi.c to trigger out-of-bounds reads across main.c, check_image_uuid.c, and oemMD5Update.c.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-76866] Netcore NR255-V firmware version 1.5.130703 builds root-run command lines from unquoted user-supplie…
Netcore NR255-V firmware version 1.5.130703 builds root-run command lines from unquoted user-supplied DDNS input in DDNSset_cgi.c and related ddns_Proc.c components, enabling os command argument injection. Attackers can exploit the unsanitized parameters to inject additional command arguments executed with root privileges.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-76852] Netcore NR268 firmware version 1.7.121109 has an improper integrity verification flaw in mtd_write a…
Netcore NR268 firmware version 1.7.121109 has an improper integrity verification flaw in mtd_write allowing forged firmware authenticity checks. Attackers can exploit put_file.cgi and check_image_uuid.c to bypass firmware signature validation and load unauthorized firmware images.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-10144] Rsbuild before 2.0.9 contains a command injection vulnerability that allows attackers to execute arb…
Rsbuild before 2.0.9 contains a command injection vulnerability that allows attackers to execute arbitrary OS commands by supplying a crafted URL containing shell metacharacters to the server.open configuration on macOS. The openBrowser() function in packages/core/src/server/open.ts passes the URL through encodeURI() before interpolating it into a shell command executed via child_process.exec(), b…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91748] Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote atta…
Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High)
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91735] Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.47 allowed a remote attacker w…
Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
15/09/2026
[CVE-2026-54544] Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.16, two API endpoints…
Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.16, two API endpoints that trigger outbound HTTP requests are missing the @login_required decorator. An unauthenticated attacker can call POST /api/test-discord-webhook or POST /api/test-webhook and cause the Fireshare server to issue an arbitrary HTTP POST to any URL the attacker supplies, including internal network ad…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
15/09/2026
[CVE-2026-87273] Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The …
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker …
M Alto vulnerabilidad
15/09/2026
[CVE-2026-87276] Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The …
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-87265] Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Other issue). …
Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Other issue). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to c…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-87258] Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Folders, Files & At…
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Folders, Files & Attachments). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks require human interaction from a person other than the attacker and while the vulnerability …
M Alto vulnerabilidad
15/09/2026
[CVE-2026-87249] Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Sec…
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks require human interaction from a person other than the attacker. Su…