Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1003
Esta semana
RSS
M Alto vulnerabilidad
03/09/2026
[CVE-2026-80465] A vulnerability has been identified in Mendix SAML (Mendix 10 compatible) (All versions < V4.2.3), M…
A vulnerability has been identified in Mendix SAML (Mendix 10 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 11 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 9.24 compatible) (All versions < V3.6.27). Affected versions of the module do not properly validate the SAML response signature. This could allow unauthenticated remote attackers to hijack an account (session) in specific…
M Alto vulnerabilidad
31/08/2026
Vulnerabilidad alta en controlador Phison PS3111-S11 permite falsificación de firmware
El controlador de almacenamiento Phison PS3111-S11 valida firmas RSA utilizando claves públicas embebidas en la imagen del firmware en lugar de almacenamiento inmutable, permitiendo a atacantes generar pares de claves RSA arbitrarios y firmar firmware modificado que el controlador acepta como legítimo. Esta vulnerabilidad afecta directamente a servidores, sistemas de backup y centros de datos en LATAM que utilizan almacenamiento basado en estos controladores, comprometiendo la integridad del firmware de dispositivos de almacenamiento altas.
M Alto vulnerabilidad
30/08/2026
[CVE-2026-82645] AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/vie…
AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint. Supplying a 'token' request parameter waives both the Live::canRestream() access gate and the restream ownership check, causing the endpoint to return any restream's stream_key and stream_url (credentials for external platforms such as YouTube, Facebook…
M Alto vulnerabilidad
29/08/2026
Vulnerabilidad alta en pac4j-oidc: falla en validación de tokens de acceso
pac4j-oidc anterior a versión 6.5.6 no valida correctamente firmas de tokens de acceso, emisores, audiencias ni expiración al extraer roles de Keycloak. Atacantes pueden falsificar tokens con roles administrativos combinados con tokens ID válidos para eludir controles de autorización en aplicaciones que dependen de validación de roles en pac4j. Afecta directamente sistemas de identidad y control de acceso en infraestructuras empresariales de México y LATAM que implementen esta librería.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-54330] Ceph is an open-source distributed storage platform providing object, block, and file storage. In ve…
Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Ceph Object Gateway (RGW) SigV4 handler does not reject requests that carry x-amz-* headers absent from the signed header set, allowing anyone holding a presigned URL to attach arbitrary unsigned x-amz-* headers that RGW will honor. AWS S3 requires every x-amz-…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-81714] openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fingerprint matching in…
openssl_encrypt (pip: openssl-encrypt) versions
M Alto vulnerabilidad
19/08/2026
[CVE-2026-76234] libcrux-ecdh and libcrux-ed25519 before 0.0.6, and libcrux-psq before 0.0.7, contain cryptographic i…
libcrux-ecdh and libcrux-ed25519 before 0.0.6, and libcrux-psq before 0.0.7, contain cryptographic implementation bugs. libcrux-ecdh did not properly check length and clamping during X25519 secret validation (and had a broken clamping check for imported X25519 secret keys); libcrux-ed25519 performed a duplicated clamping step during key generation; and libcrux-psq panicked instead of propagating a…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
18/08/2026
[CVE-2025-9210] Missing signature validation in JSON Web Tokens in Otalio Ship Property Management System versions b…
Missing signature validation in JSON Web Tokens in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to escalate privileges via tampering with JWTs
M Alto vulnerabilidad
15/08/2026
[CVE-2026-18500] @fastify/jwt is a JSON Web Token plugin for Fastify. In versions before 10.2.2, a per-request verifi…
@fastify/jwt is a JSON Web Token plugin for Fastify. In versions before 10.2.2, a per-request verification key passed to request.jwtVerify({ key }) is silently overridden by the plugin's globally configured secret, because the option merge applies the global key last. Applications that use different keys for different authorization domains, for example separate user and admin keys, therefore accep…
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19910] PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution Vulnera…
PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability. The specific flaw exists within the application installer. The issue results from the lack of proper …
M Alto vulnerabilidad
13/08/2026
Vulnerabilidad alta en ManageEngine Password Manager Pro y PAM360 permite eludir autenticación
ManageEngine Password Manager Pro (versiones anteriores a 13232) y PAM360 (versiones anteriores a 8551) presentan una vulnerabilidad de elusión de autenticación (CVSS 8.8) por validación incorrecta de SAML. Esto permite a atacantes acceder a gestores de credenciales sin autenticación válida, comprometiendo todas las contraseñas almacenadas en la solución. Afecta principalmente a empresas medianas y grandes en México y LATAM que utilizan estas herramientas para administración centralizada de accesos.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-68759] A holder of a valid integration credential may impersonate other users under specific conditions.
A holder of a valid integration credential may impersonate other users under specific conditions.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-68757] A user with access to a valid SAML response may impersonate another user under specific conditions.
A user with access to a valid SAML response may impersonate another user under specific conditions.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-15556] A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion …
A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML response and auth as any principal with any roles on the protected application.
M Alto vulnerabilidad
07/08/2026
[CVE-2026-62918] Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker …
Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
05/08/2026
[CVE-2026-16443] A flaw was found in the SAML metadata import functionality of the keycloak-services component, which…
A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system incorrectly disables signature validation for SAML responses even if a signing certificate is provided. This issue allows an un…
M Alto vulnerabilidad
03/08/2026
[CVE-2026-18568] XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify …
XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify returns true when every signature was skipped before any cryptographic check. verify in lib/XML/Sig.pm counts the `//dsig:Signature` elements into `$numsigs` and iterates over them, but two paths reach `next` before any digest or key check runs: a `SignedInfo/Reference/@URI` that resolves to no ele…
M Alto vulnerabilidad
03/08/2026
[CVE-2026-18092] Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping…
Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml reads assertion identity with document-wide XPath instead of the signed subtree. new_from_xml reads the NameID, attribute values, SessionIndex, audience and other identity fields with document-wide XPath, such as //saml:Assertion/saml:AttributeStatement/saml:Attribute and //sa…
M Alto vulnerabilidad
03/08/2026
[CVE-2026-18089] Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses aga…
Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedded certificate in verify_xml when no trust anchor is configured. verify_xml in Net::SAML2::Role::VerifyXML runs "return if !$anchors && !$cacert;" as soon as the XML::Sig check succeeds, and that check uses the X.509 certificate taken from the response's own dsig:KeyInfo/dsi…
M Alto vulnerabilidad
31/07/2026
[CVE-2026-53501] Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC valid…
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s .replace() when removing the signature from the URL before validation. Since .replace() removes all occurrences of the substring, an attacker can insert the same signature multiple times in the URL and manipulate the final URL used for validation. Thi…