Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "X" — 7854 resultados ✕ Limpiar búsqueda
13,971
Total alertas
3188
Críticas
10511
Altas
8
Ransomware
981
Esta semana
RSS
R Alto vulnerabilidad
02/07/2026
[CVE-2026-38972] Notepad3 through 6.25.822.1 contains a DLL search-order hijacking vulnerability in the About-dialog …
Notepad3 through 6.25.822.1 contains a DLL search-order hijacking vulnerability in the About-dialog code path in src/Notepad3.c. The application calls LoadLibrary(L"MSFTEDIT.DLL") with a bare DLL name, which allows a local attacker to place a malicious MSFTEDIT.DLL in the application directory or another preferred DLL search location and achieve arbitrary code execution in the context of the user …
M Alto vulnerabilidad
02/07/2026
[CVE-2026-59092] JuiceFS through 1.3.1, fixed in commit a46979c, contains an authentication bypass vulnerability that…
JuiceFS through 1.3.1, fixed in commit a46979c, contains an authentication bypass vulnerability that allows unauthenticated remote attackers to access sensitive debug and metrics endpoints by exploiting improper handler registration on the shared http.DefaultServeMux. Attackers can request the /debug/pprof/cmdline endpoint to obtain the process command line containing metadata engine connection st…
M Alto vulnerabilidad
02/07/2026
[CVE-2026-59094] Pathway through 0.31.1, fixed in commit d09722e, document store applies a caller-supplied glob patte…
Pathway through 0.31.1, fixed in commit d09722e, document store applies a caller-supplied glob pattern to indexed document paths using a hand-written recursive matcher that branches two ways on each ** token without memoization, giving exponential worst-case complexity. The filepath_globpattern value is taken from the body of the unauthenticated HTTP endpoints /v1/retrieve, /v1/inputs and /v2/answ…
M Alto vulnerabilidad
02/07/2026
[CVE-2026-59096] Dapr Sentry's OIDC discovery endpoint derives the issuer and jwks_uri of the /.well-known/openid-con…
Dapr Sentry's OIDC discovery endpoint derives the issuer and jwks_uri of the /.well-known/openid-configuration document from the request Host, honoring an attacker-controlled X-Forwarded-Host header without validation when no allowed-hosts list is configured (the default), and serves the document with a one-hour public cache lifetime. A remote unauthenticated attacker can poison the discovery docu…
M Alto vulnerabilidad
02/07/2026
[CVE-2026-58467] Cockpit CMS through 2.14.0 contains a path traversal and local file inclusion vulnerability that all…
Cockpit CMS through 2.14.0 contains a path traversal and local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files or execute PHP files by including unvalidated PATH_INFO derived from REQUEST_URI in filesystem path construction without containment checks. Attackers can inject dot-dot sequences into the URL to traverse outside the designated spaces directory, …
M Alto vulnerabilidad
02/07/2026
[CVE-2026-58465] Eclipse Wakaama before snapshot/2026-05-26 contains an unbounded memory allocation vulnerability in …
Eclipse Wakaama before snapshot/2026-05-26 contains an unbounded memory allocation vulnerability in the CoAP Block1 handler within coap/block.c that allows unauthenticated remote attackers to exhaust server memory by sending a sequence of Block1 PUT requests with incrementing block numbers. Attackers can target the registration endpoint over UDP without authentication, causing the server to repeat…
E Alto vulnerabilidad
02/07/2026
[CVE-2026-55952] The Erlang/OTP ssl application does not validate that the PSK identity list and binder list carried …
The Erlang/OTP ssl application does not validate that the PSK identity list and binder list carried in a TLS 1.3 ClientHello pre-shared key extension have equal length before passing them to the session ticket handler. In tls_handshake_1_3:handle_pre_shared_key/3, an OfferedPreSharedKeys record with a mismatched number of identities and binders is forwarded directly to tls_server_session_ticket:us…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
02/07/2026
[CVE-2024-58352] Landray OA contains an unauthenticated HQL injection vulnerability that allows unauthenticated attac…
Landray OA contains an unauthenticated HQL injection vulnerability that allows unauthenticated attackers to query arbitrary Hibernate entity classes by injecting malicious HQL syntax into the uid POST parameter of the wechatLoginHelper.do endpoint. Attackers can exploit the lack of input sanitization in the string-concatenated filter expression passed to the Hibernate findList() call to extract se…
O Alto vulnerabilidad
02/07/2026
[CVE-2026-44941] A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 c…
A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a malicious repository to inject or overwrite files in the target system as root.
P Alto vulnerabilidad
02/07/2026
[CVE-2026-8079] In Progress Flowmon versions prior to 12.5.9 and 13.0.11, a vulnerability exists whereby an authenti…
In Progress Flowmon versions prior to 12.5.9 and 13.0.11, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the PDF generation process that results in operations being performed with the privileges of another user, potentially leading to unauthorized access to sensitive data and unintended modifications to system configuration.
P Alto vulnerabilidad
02/07/2026
[CVE-2026-9272] In Progress Flowmon ADS versions prior to 12.5.6 and 13.0.5, a vulnerability exists whereby an adver…
In Progress Flowmon ADS versions prior to 12.5.6 and 13.0.5, a vulnerability exists whereby an adversary who is authenticated as a low-privileged user in the Anomaly Detection System (ADS) may send specially crafted requests that could result in unauthorized access to application data and its modification.
U Alto vulnerabilidad
02/07/2026
[CVE-2026-56841] A malicious actor with access to the network and low privileges could exploit an authenticated SQL I…
A malicious actor with access to the network and low privileges could exploit an authenticated SQL Injection vulnerability found in UniFi Protect Application to escalate privileges on the host device.
U Alto vulnerabilidad
02/07/2026
[CVE-2026-56842] A malicious actor with access to the network and under certain conditions could exploit an Incorrect…
A malicious actor with access to the network and under certain conditions could exploit an Incorrect Authorization vulnerability found in UniFi Network Application to persist privileges within UniFi Network Application after such access had been removed.
U Alto vulnerabilidad
02/07/2026
[CVE-2026-55112] A malicious actor with access to the network and low privileges and under certain conditions could e…
A malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi OS with UniFi Protect Application to escalate privileges on the host device.
U Alto vulnerabilidad
02/07/2026
[CVE-2026-55113] A malicious actor with access to the network could exploit a Server-Side Request Forgery (SSRF) vuln…
A malicious actor with access to the network could exploit a Server-Side Request Forgery (SSRF) vulnerability found in UniFi Talk Application to execute a Denial of Service (DoS) attack and bypass authentication in certain UniFi Talk API endpoints.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
U Alto vulnerabilidad
02/07/2026
[CVE-2026-55114] A malicious actor with access to the network and low privileges could exploit an Improper Access Con…
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.
U Alto vulnerabilidad
02/07/2026
[CVE-2026-55117] A malicious actor with access to the network could exploit a Path Traversal vulnerability found in U…
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Access Application to access files on the host device.
U Alto vulnerabilidad
02/07/2026
[CVE-2026-55118] A malicious actor with access to the network,low privileges and under certain conditions could explo…
A malicious actor with access to the network,low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.
U Alto vulnerabilidad
02/07/2026
[CVE-2026-55119] A malicious actor with access to the network and low privileges could exploit an Improper Access Con…
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Talk Application to escalate privileges within the UniFi Talk Application.
U Alto vulnerabilidad
02/07/2026
[CVE-2026-54404] A malicious actor with access to the network and low privileges could exploit a series of authentica…
A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi OS to escalate privileges within such UniFi OS devices or instances.