Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1019
Esta semana
RSS
M Alto vulnerabilidad
27/09/2026
[CVE-2026-101064] Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server regist…
Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server registration that allows privileged users to specify arbitrary URLs without destination validation. Attackers with Power User or higher roles can coerce Obot to make requests to internal services and cloud metadata endpoints, reading responses in error messages to disclose sensitive credentials.
M Alto vulnerabilidad
27/09/2026
[CVE-2026-101059] utcp-http before 1.1.4 fails to validate the OAuth2 tokenUrl field from remote OpenAPI specification…
utcp-http before 1.1.4 fails to validate the OAuth2 tokenUrl field from remote OpenAPI specifications, allowing attackers to redirect credential submission to arbitrary endpoints. When a victim registers an attacker-controlled OpenAPI spec and invokes a generated OAuth2-protected tool, the library POSTs the victim's client_id and client_secret to the attacker-supplied token endpoint without URL va…
M Alto vulnerabilidad
27/09/2026
[CVE-2026-101060] python-utcp versions before 1.1.4 contain a server-side request forgery vulnerability in HttpCommuni…
python-utcp versions before 1.1.4 contain a server-side request forgery vulnerability in HttpCommunicationProtocol.call_tool that validates the initial tool URL but follows HTTP redirects without re-validating the target. Attackers controlling a tool endpoint can return a 302 redirect to internal services, allowing the UTCP client to reach cloud metadata endpoints or internal HTTP services and ret…
M Alto vulnerabilidad
27/09/2026
Vulnerabilidad alta en AzuraCast anterior a 0.23.8: SSRF y lectura de archivos locales
AzuraCast antes de la versión 0.23.8 contiene vulnerabilidades de Server-Side Request Forgery (SSRF) y lectura de archivos locales en el módulo AutoDJ de obtención de playlists remotas. Un usuario con permisos de Media en la estación puede crear playlists con URLs remotas que apunten a rutas file:// o direcciones internas (loopback/link-local), exponiendo información sensible del servidor. Afecta principalmente a emisoras de radio online y plataformas de streaming en LATAM que utilizan este software para automatizar contenido.
M Alto vulnerabilidad
27/09/2026
Vulnerabilidad alta en AzuraCast permite acceso a recursos de red restringidos
AzuraCast (versión anterior a 0.23.8) presenta una falla en la validación de URLs de retransmisión remota que permite a usuarios con permisos limitados apuntar a direcciones internas (loopback y redes privadas). Esta vulnerabilidad afecta principalmente a proveedores de streaming y radios en línea que operan la plataforma en entornos corporativos compartidos en México y Latinoamérica.
M Alto vulnerabilidad
27/09/2026
Vulnerabilidad de validación de URLs en AzuraCast anterior a 0.23.8 (CVE-2026-100849)
AzuraCast, plataforma de gestión de radio web autohospedada, contiene un fallo en la validación de URLs de webhooks que permite eludir restricciones de acceso a direcciones internas. La función AbstractConnector::getValidUrl() solo rechaza direcciones link-local, permitiendo ataques SSRF contra redes RFC1918 y loopback. Radiodifusoras y proveedores de streaming en LATAM que usen conectores Generic o Discord están expuestos.
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100705] Kyverno before 1.19.1 is vulnerable to server-side request forgery. The default egress blocklist (16…
Kyverno before 1.19.1 is vulnerable to server-side request forgery. The default egress blocklist (169.254.169.254, 169.254.169.253, metadata.google.internal, 127.0.0.0/8, ::1/128) and the scoped-token control were wired only into the new CEL http.Get/Post library and were never applied to the legacy apiCall service executor (pkg/engine/apicall/executor.go) or to the GlobalContextEntry external-API…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100697] Adminer 6.0.0 through 6.0.1, when the official ClickHouse driver plugin (plugins/drivers/clickhouse.…
Adminer 6.0.0 through 6.0.1, when the official ClickHouse driver plugin (plugins/drivers/clickhouse.php, rewritten in 6.0.0) is loaded, is vulnerable to pre-authentication server-side request forgery. An unauthenticated attacker can submit auth[driver]=clickhouse with auth[server] set to an arbitrary URL (for example http://127.0.0.1:18089), causing the Adminer server to issue an HTTP POST contain…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100567] OpenClaw is an agent gateway distributed as the npm package 'openclaw'. In versions >= 2026.4.5 and …
OpenClaw is an agent gateway distributed as the npm package 'openclaw'. In versions >= 2026.4.5 and < 2026.8.1, the Gateway validated a single DNS resolution result for a configured remote Chrome DevTools Protocol (CDP) hostname, but the raw WebSocket and Playwright transports performed a later, independent DNS resolution, discarding the DNS pinning enforced at validation time. An attacker who con…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100555] OpenClaw is an npm-distributed gateway application. In versions >= 2026.7.1 and < 2026.8.1, Synology…
OpenClaw is an npm-distributed gateway application. In versions >= 2026.7.1 and < 2026.8.1, Synology Chat attachment delivery could lose DNS pinning: the Gateway validated a single DNS result for a supplied file URL but then passed the original hostname to the Synology NAS, where it could resolve to a different destination. When attachment delivery accepted a remotely influenced hostname, an attac…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-100391] MediaFlow Proxy through 2.4.9 contains a server-side request forgery vulnerability in the /proxy rou…
MediaFlow Proxy through 2.4.9 contains a server-side request forgery vulnerability in the /proxy routes due to missing and incomplete destination validation in the d query parameter. Remote attackers can supply arbitrary internal URLs including loopback and cloud metadata endpoints to read full responses from the proxy server.
M Alto vulnerabilidad
25/09/2026
[CVE-2026-51773] An issue in the VMware datastore driver of OpenStack glance_store. When an authenticated attacker pr…
An issue in the VMware datastore driver of OpenStack glance_store. When an authenticated attacker provides a maliciously crafted image location URI pointing to an external server, the _retry_request function fails to validate the destination host before attaching sensitive authentication headers.
M Alto vulnerabilidad
24/09/2026
[CVE-2026-97326] A weakness has been identified in songxinjianqwe Chat up to ac63d25297079eed5e4ba7e88d3b7a032637150d…
A weakness has been identified in songxinjianqwe Chat up to ac63d25297079eed5e4ba7e88d3b7a032637150d. Affected by this issue is some unknown functionality of the file chat-server/src/main/java/cn/sinjinsong/chat/server/ChatServer.java of the component chat-server. This manipulation causes server-side request forgery. The attack may be initiated remotely. The exploit has been made available to the …
M Alto vulnerabilidad
24/09/2026
[CVE-2026-77294] TREK is a collaborative travel planner. Prior to 3.3.0, TREK allows an authenticated user to store a…
TREK is a collaborative travel planner. Prior to 3.3.0, TREK allows an authenticated user to store an attacker-controlled llm_base_url through the settings API when the LLM_PARSING feature is enabled. Write permission to the target trip instance is required to trigger the vulnerable AI-assisted import path. The value is consumed by the clients in server/src/nest/llm-parse/clients/openai-compatible…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-79764] Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capa…
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.5.0 until 2.5.1, the /homepage/proxy endpoint accepts an authenticated user's url query parameter and passes it to http.get or https.get without destination restrictions. In src/backend/database/routes/homepage-proxy-routes.ts, new URL performs only syntactic validation, allowing re…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
24/09/2026
[CVE-2026-77581] BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6 and earlier, the certificate a…
BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6 and earlier, the certificate and timestamp CORS proxy in cloudflare/cors-proxy-worker.js uses isPrivateOrReservedHost() to validate a supplied hostname separately from the DNS resolution used by fetch(targetUrl), allowing an attacker-controlled hostname to resolve to an internal or reserved destination after validation. A certif…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-76086] Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/integra…
Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/integrations/form-settings control panel action in IntegrationsController::actionFormSettings is reachable without the required form integration permissions and passes request-supplied settings to a configured integration. An authenticated attacker can replace outbound host properties such as apiUrl while …
M Alto vulnerabilidad
22/09/2026
[CVE-2026-18066] IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to obtain …
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to obtain sensitive information and trigger unauthorized actions due to server-side request forgery.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-84395] Premiere Pro is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in …
Premiere Pro is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation potentially resulting in unauthorized write access. Exploitation of this issue does not require user interaction. Scope is changed.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-81999] Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability…
Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. An attacker with high privileges could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope is changed.