Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Quest" — 1677 resultados ✕ Limpiar búsqueda
22,298
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1168
Esta semana
RSS
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86498] In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed…
In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission
M Alto vulnerabilidad
07/09/2026
[CVE-2026-18453] A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling…
A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op_shared_search allows an unauthenticated remote attacker to crash the LDAP server by sending a crafted sequence of search requests using the USE_ONE_BACKEND control, resulting in denial of service.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86428] commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the Attrib…
commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the AttributesExtension when processing distinctly-named attributes. Attackers can submit Markdown with numerous distinct attribute names to cause quadratic-time attribute merging and filtering, consuming disproportionate CPU resources and preventing legitimate requests from completing.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86273] A weakness has been identified in projeto-siga siga up to 11.1.1. Affected by this issue is the func…
A weakness has been identified in projeto-siga siga up to 11.1.1. Affected by this issue is the function DownloadExterno.getUrl of the file sigaex/src/main/java/br/gov/jfrj/siga/vraptor/ExUtilController.java of the component HTML-to-PDF Endpoint. This manipulation of the argument html causes server-side request forgery. The attack may be initiated remotely. The exploit has been made available to t…
M Alto vulnerabilidad
06/09/2026
[CVE-2026-86259] OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowin…
OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services. Attackers can supply arbitrary provider URLs via the x-base-url header or baseUrl parameter to access sensitive cloud credentials and metadata.
M Alto vulnerabilidad
06/09/2026
Vulnerabilidad alta en Bifrost HTTP transport permite ejecución de código remoto sin autenticación
Bifrost HTTP transport anterior a versión 2.0.0 permite a atacantes no autenticados cargar y ejecutar plugins maliciosos a través de POST /api/plugins cuando la autenticación de gestión está deshabilitada (configuración por defecto). El cargador de objetos compartidos descarga archivos desde URLs HTTP y los ejecuta como librerías dinámicas en Go, comprometiendo completamente servidores en infraestructuras altas de LATAM. Afecta especialmente a plataformas de integración y orquestación de datos sin hardening de seguridad.
M Alto vulnerabilidad
05/09/2026
Vulnerabilidad SSRF alta en MindsDB hasta v26.1.0 permite acceso a servicios internos
MindsDB versiones hasta 26.1.0 contiene una vulnerabilidad de falsificación de solicitudes del lado del servidor (SSRF) en el manejador de rastreo web que permite a atacantes no autenticados recuperar URLs arbitrarias. Los agresores pueden eludir controles de lista blanca explotando configuraciones vacías por defecto y acceder a servicios internos y puntos de acceso de metadatos en la nube sin autenticación. Afecta especialmente a empresas de IA/ML en LATAM que exponen MindsDB en entornos multi-tenant o híbridos.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
05/09/2026
Vulnerabilidad alta de SSRF sin autenticación en Webstudio ≤0.296.0
Webstudio versión 0.296.0 y anteriores contiene una vulnerabilidad Server-Side Request Forgery (SSRF) sin autenticación en las rutas proxy /cgi/image, /cgi/video y /cgi/asset cuando la variable de entorno RESIZE_ORIGIN no está configurada. Atacantes pueden suministrar URLs arbitrarias para acceder a metadatos de instancias en la nube, servicios internos y realizar reconocimiento de infraestructura. Este vector afecta directamente a empresas en LATAM que ejecutan Webstudio en entornos cloud (AWS, Azure, Google Cloud).
M Alto vulnerabilidad
04/09/2026
[CVE-2026-86090] ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipient…
ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authenticated non-administrator users can issue POST requests to irreversibly delete all configured notification endpoints and recipients, silencing all alerts.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-86091] ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing …
ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-administrators to delete all host pools and member bindings. Attackers can issue POST requests to the delete pools endpoint to irreversibly destroy every host pool, removing traffic policy bindings and visibility restrictions that may bypass security policies.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-82712] Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request for…
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request forgery vulnerability. This could allow an attacker to perform state changing operations on the device.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-9317] Nango before 0.71.6 contains a missing authentication vulnerability in the runner tRPC server that a…
Nango before 0.71.6 contains a missing authentication vulnerability in the runner tRPC server that allows unauthenticated attackers to execute arbitrary JavaScript code by invoking the exposed start procedure without credentials. Attackers with network access to the runner port can send requests to the unauthenticated start procedure, bypassing the unenforced RUNNER_SECRET_KEY environment variable…
M Alto vulnerabilidad
04/09/2026
[CVE-2026-82538] ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerability in the repository…
ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerability in the repository trash table where the table navigation sort field from HTTP requests is passed directly into the ORDER BY clause of a SQL query without validation against declared sortable columns. Authenticated users with write permission on any container can inject arbitrary SQL through the sort parameter, and b…
M Alto vulnerabilidad
04/09/2026
[CVE-2026-19534] undici's WebSocket client crashes the whole Node.js process during the opening handshake when a serv…
undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A default WebSocket connection sends no subprotocol, but if the server's 101 response includes a Sec-WebSocket-Protocol header, undici dereferences a null value while checking it against the requested list and throws an uncaught TypeErr…
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85152] undici 8.10.0 omits the destination origin from the cache and request-deduplication keys when the ca…
undici 8.10.0 omits the destination origin from the cache and request-deduplication keys when the cache or deduplicate interceptor is composed directly onto a Client or Pool. Because the internal cache key falls back to an empty origin string, a cacheable or in-flight response from one upstream origin is returned for a request to a different, trusted origin whenever the method, path, and relevant …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
04/09/2026
[CVE-2026-77822] IBM ContextForge MCP Gateway could allow a remote authenticated attacker to obtain sensitive informa…
IBM ContextForge MCP Gateway could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery via DNS rebinding.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-19305] IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information …
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server-side request forgery.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-19306] IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from …
IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from the server filesystem — including server secret material (secret_key, JWT signing keys, the application database, /proc/self/environ, and other tenants' upload directories) — by supplying absolute paths or traversal sequences in the files parameter of an authenticated build request. The file content…
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85699] jina-ai reader contains a server-side request forgery vulnerability where URL validation is performe…
jina-ai reader contains a server-side request forgery vulnerability where URL validation is performed only on the initial request but not re-applied to subsequent redirect hops. Attackers can craft a public URL that redirects to internal network addresses or cloud metadata endpoints, allowing the server to fetch and return the target's response body to the attacker.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85691] MegaParse 0.0.55 contains an unauthenticated server-side request forgery vulnerability in the POST /…
MegaParse 0.0.55 contains an unauthenticated server-side request forgery vulnerability in the POST /v1/url endpoint that fetches caller-supplied URLs server-side. Attackers can supply internal service URLs or metadata endpoints without authentication to read their responses directly from the JSON response.