Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Rti" — 687 resultados ✕ Limpiar búsqueda
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1016
Esta semana
RSS
M Alto vulnerabilidad
01/10/2026
[CVE-2026-103921] GraphQL Tools provides utilities for building, stitching, and mocking GraphQL schemas. Prior to 1.1.…
GraphQL Tools provides utilities for building, stitching, and mocking GraphQL schemas. Prior to 1.1.35, the executor-legacy-ws buildWSLegacyExecutor() function hardcodes TLS certificate rejection off for Node.js connections to wss:// endpoints. Applications using the executor directly, or url-loader with SubscriptionProtocol.LEGACY_WS, can therefore accept an attacker-controlled certificate when a…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-79899] Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility…
Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates predictable temporary files without first setting a restrictive umask. A local user on the BoKS Master who can read files under BOKS_tmp may be able to obtain CA secret or host private-key material while the utility runs, or obtain CA secret material left behind after successful certificate…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102098] Kiteworks Core before version 9.5.0 is vulnerable to SQL Injection. A stored SQL injection vulnerabi…
Kiteworks Core before version 9.5.0 is vulnerable to SQL Injection. A stored SQL injection vulnerability in a Kiteworks administrative reporting feature could allow an authenticated administrator to read sensitive data from the underlying database and to affect the availability of the service. Exploitation requires an existing, authenticated administrative account with access to the affected repor…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-47601] NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the open-source kernel m…
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the open-source kernel module DMA-BUF import path where an unprivileged local user could cause improper preservation of memory access permissions when importing a read-only buffer from another device's DMA-BUF exporter. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denia…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-95616] An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An una…
An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 certificate whose SubjectKeyIdentifier extension declares a length of 0x7FFFFFFF; WSS4J decodes this while resolving the signature's key reference, before the message is authenticated, so an eleven-byte extension triggers a 2 GB allocat…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-97150] When converting baserCMS4-style addons to baserCMS5-style ones, BcAddonMigrator includes "config.ph…
When converting baserCMS4-style addons to baserCMS5-style ones, BcAddonMigrator includes "config.php" from the addon, which means the PHP code in the file is executed. Arbitrary files on the system may be read or deleted by an administrative user.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-84409] The device's update mechanism retrieves metadata for software updates over an unencrypted HTTP conne…
The device's update mechanism retrieves metadata for software updates over an unencrypted HTTP connection and stores portions of that metadata for later use. A management interface subsequently returns this stored value in a JSON response, and the web interface responsible for displaying update information inserts that value directly into the page as HTML. This behavior allows attacker‑controlled …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
29/09/2026
[CVE-2026-74225] U-Boot before 2026.10-rc5 contains out-of-bounds memory access in dhcp6_parse_options() that fails t…
U-Boot before 2026.10-rc5 contains out-of-bounds memory access in dhcp6_parse_options() that fails to validate SERVERID and CLIENTID option lengths from DHCPv6 packets. Attackers on the local network can send crafted DHCPv6 ADVERTISE or REPLY packets during netboot to corrupt memory and crash the bootloader.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-84422] IBM Guardium Data Protection 12.2 is vulnerable to command injection in the CLI certificate SMIME re…
IBM Guardium Data Protection 12.2 is vulnerable to command injection in the CLI certificate SMIME recipient deletion functionality, allowing an authenticated privileged CLI user to execute arbitrary commands with root privileges.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-84783] Issue summary: The first concurrent use of the same X.509 certificate by several threads may cause i…
Issue summary: The first concurrent use of the same X.509 certificate by several threads may cause its cached extension data to be freed while another thread is still using it. Impact summary: A remote, unauthenticated peer could crash a multi-threaded TLS client, or a multi-threaded TLS server that requests client certificates, if the first certificate chains built to the same trusted CA certifi…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102600] Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 0.1.1, @s…
Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 0.1.1, @socket.io/cluster-engine uses inherited object properties when looking up attacker-controlled session IDs in clustered deployments. Special property names such as __proto__ or constructor can resolve through the object prototype chain instead of identifying an actual connected client, causing the Nod…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-86450] Insertion of sensitive information into sent data vulnerability in Parla Auto Automotive Trading Lim…
Insertion of sensitive information into sent data vulnerability in Parla Auto Automotive Trading Limited Company DetaWix Mobile Web Portal allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects DetaWix Mobile Web Portal: before v1.0.19.
M Alto vulnerabilidad
29/09/2026
Falta de autenticación en Progress Fiddler Everywhere 8.0.2 permite acceso no autorizado a tokens OAuth
Progress Software Fiddler Everywhere 8.0.2 presenta una vulnerabilidad alta (CVSS 7.7) que permite a un atacante local sin credenciales acceder al backend .NET (Fiddler.WebUi) a través de canales HTTP y SignalR no autenticados. Esto posibilita la generación de tokens OAuth fraudulentos y la lectura del certificado raíz man-in-the-middle. Afecta principalmente a desarrolladores y equipos de testing que utilizan esta herramienta en México y Latinoamérica para análisis de tráfico HTTPS.
M Alto vulnerabilidad
28/09/2026
[CVE-2026-16513] The userspace verifier z_vrfy_rtio_sqe_copy_in_get_handles() in subsys/rtio/rtio_syscalls.c (subsys/…
The userspace verifier z_vrfy_rtio_sqe_copy_in_get_handles() in subsys/rtio/rtio_syscalls.c (subsys/rtio/rtio_handlers.c before v4.3.0) validated the RTIO object handle and the sqes input array, but not the handle out-parameter. On the first loop iteration it executed *handle = sqe, storing the kernel address of the newly acquired submission-queue entry through a pointer taken verbatim from user m…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-101916] @grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. P…
@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.6 and 1.14.5, getAuthContext does not distinguish authorized from unauthorized peer certificates when server credentials set requireClientCertificate to false. When applications use the returned authentication context, they can treat an unauthorized certificate as authorized, causing im…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
28/09/2026
Vulnerabilidad alta en NeuVector permite inyección de comandos OS en contenedores privilegiados
NeuVector versiones 5.4 (anteriores a 5.4.11) y 5.5 presenta manejo inadecuado de parámetros que permite a usuarios autenticados con permisos de escritura en Políticas Runtime o acceso a claves gRPC internas inyectar comandos del sistema operativo en contenedores enforcer privilegiados. Esto resulta en compromiso total del nodo worker. Afecta principalmente a infraestructuras containerizadas en Azure, AWS y datacenters locales de la región.
M Alto vulnerabilidad
28/09/2026
[CVE-2026-82386] Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a weblog adminis…
Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a weblog administrator to read files readable by the Roller process and reach internal network addresses by importing a crafted OPML document, because the bookmark import parser does not disable external entity resolution. No non-default configuration is required; the import is reached through the administrator boo…
M Alto vulnerabilidad
27/09/2026
Vulnerabilidad alta de deserialización insegura en MONAI anterior a v1.6.0
MONAI antes de la versión 1.6.0 contiene una vulnerabilidad de deserialización insegura en la clase NumpyReader que utiliza numpy.load con allow_pickle=True sin validación, permitiendo a atacantes ejecutar código arbitrario mediante archivos .npy y .npz maliciosos en pipelines de datos estándar. Esta vulnerabilidad afecta especialmente a organizaciones en LATAM que utilizan MONAI en aplicaciones de análisis médico, investigación biomédica e inteligencia artificial sin restricciones en el origen de los datos de entrenamiento.
M Alto vulnerabilidad
27/09/2026
Vulnerabilidad alta en AzuraCast permite acceso a recursos de red restringidos
AzuraCast (versión anterior a 0.23.8) presenta una falla en la validación de URLs de retransmisión remota que permite a usuarios con permisos limitados apuntar a direcciones internas (loopback y redes privadas). Esta vulnerabilidad afecta principalmente a proveedores de streaming y radios en línea que operan la plataforma en entornos corporativos compartidos en México y Latinoamérica.
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100720] Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When a customer (the lowe…
Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When a customer (the lowest-privileged authenticated role) uploads an SSL certificate for one of their own domains, the Certificates API add()/update() methods parse it with openssl_x509_parse() and store the issuer organization (issuer['O']) value verbatim without sanitization. Froxlor's table-listing renderer then emits s…