Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ni" — 5706 resultados ✕ Limpiar búsqueda
22,394
Total alertas
4758
Críticas
17006
Altas
8
Ransomware
1261
Esta semana
RSS
M Alto vulnerabilidad
24/09/2026
[CVE-2026-93786] In the Linux kernel, the following vulnerability has been resolved: ksmbd: preserve VFS inherited P…
In the Linux kernel, the following vulnerability has been resolved: ksmbd: preserve VFS inherited POSIX ACL mask The VFS initializes a child's POSIX ACL from the parent's default ACL and the requested creation mode. Do not mutate the parent ACL or overwrite the child's VFS-computed access and default ACLs afterwards. This preserves restrictive ACL_MASK entries and prevents SMB object creation f…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-91160] OpenWA is a free, open source, self-hosted WhatsApp API gateway. Prior to 0.23.5, the /events WebSoc…
OpenWA is a free, open source, self-hosted WhatsApp API gateway. Prior to 0.23.5, the /events WebSocket gateway delivers the session.qr event to a VIEWER API key that subscribes by event name or through either wildcard subscription form, even though GET /api/sessions/{sessionId}/qr requires the OPERATOR role. When an allowed session is waiting to be paired, the exposed QR lets the key holder link …
M Alto vulnerabilidad
24/09/2026
[CVE-2026-88390] An out-of-bounds write vulnerability in jslGetTokenValueAsString() in Espruino 2v29 (commit bffc6d0)…
An out-of-bounds write vulnerability in jslGetTokenValueAsString() in Espruino 2v29 (commit bffc6d0) allows crafted JavaScript input containing an overlong token to trigger a one-byte write beyond the JsLex.token buffer in RELEASE/NO_ASSERT builds. The out-of-bounds write corrupts the adjacent tokenValue pointer, resulting in memory corruption and potentially causing application crashes or denial …
M Alto vulnerabilidad
24/09/2026
[CVE-2026-88376] Bento4 1.6.0.0 contains an integer underflow vulnerability in AP4_AvccAtom::Create() and AP4_HvccAto…
Bento4 1.6.0.0 contains an integer underflow vulnerability in AP4_AvccAtom::Create() and AP4_HvccAtom::Create(). A specially crafted MP4 file containing an avcC or hvcC atom with a declared size smaller than the atom header size can cause the payload-size calculation to wrap to a large unsigned value. The resulting invalid buffer allocation and copy operations can cause application termination, le…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-62368] Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a user with the customfields.crea…
Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a user with the customfields.create permission can store markup in CustomField.name, and app/Presenters/AssetPresenter.php assigns that value as an unescaped bootstrap-table header title. When another user opens an asset-list page associated with the fieldset, the stored markup executes on page load in that user's Snipe-IT session.…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-63498] Snipe-IT is an IT asset/license management system. Prior to 8.7.0, the uploaded-files API endpoint G…
Snipe-IT is an IT asset/license management system. Prior to 8.7.0, the uploaded-files API endpoint GET /api/v1/{object_type}/{id}/files/{file_id} allows an authenticated user with file-management access to upload XML and XSLT attachments and request them with the inline=true parameter. The app/Http/Controllers/Api/UploadedFilesController.php show() path does not apply the safe-inline allowlist use…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-96750] MongoDB Compass can interpolate a database name without escaping into the initial input of its embed…
MongoDB Compass can interpolate a database name without escaping into the initial input of its embedded MongoDB shell when a user opens the shell from that database's view. A user with privileges to create databases on a server that a Compass user connects to may, under specific conditions, have content evaluated as shell input within the Compass process, with that process's privileges. This requi…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
24/09/2026
[CVE-2026-93282] In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix maximum allowed acce…
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix maximum allowed access checks The DACL permission check looks for an ACE matching the current user and falls back to the Everyone ACE. It does not consider an Authenticated Users ACE, even though an authenticated session is a member of that well-known group. As a result, opening a file whose access is granted through…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-93260] In the Linux kernel, the following vulnerability has been resolved: powerpc/xive: propagate IPI ini…
In the Linux kernel, the following vulnerability has been resolved: powerpc/xive: propagate IPI init errors to prevent use-after-free When xive_init_ipis() fails (e.g. irq_domain_alloc_irqs() fails), the error path frees the global xive_ipis array. However, xive_smp_probe() previously ignored this failure and proceeded to call xive_setup_cpu_ipi(), which dereferences the already-freed xive_ipis…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-93262] In the Linux kernel, the following vulnerability has been resolved: md/raid5-ppl: fix use-after-fre…
In the Linux kernel, the following vulnerability has been resolved: md/raid5-ppl: fix use-after-free in ppl_do_flush() The loop in ppl_do_flush() continues iterating after calling ppl_io_unit_finished(), touching io->pending_flushes and leading to a use-after-free. Add a break statement to stop the loop once io is freed.
M Alto vulnerabilidad
24/09/2026
[CVE-2026-93237] In the Linux kernel, the following vulnerability has been resolved: LoongArch: Add DIRECT_MAP_PHYSM…
In the Linux kernel, the following vulnerability has been resolved: LoongArch: Add DIRECT_MAP_PHYSMEM_END definition get_free_mem_region() and mhp_get_pluggable_range() bound their search to DIRECT_MAP_PHYSMEM_END. LoongArch does not define it, so the fallback in include/linux/mm.h applies: under CONFIG_SPARSEMEM_VMEMMAP it is (1ULL
M Alto vulnerabilidad
24/09/2026
[CVE-2026-88368] NanoSVG commit 239e102ec contains an incorrect numeric conversion vulnerability in the rasterizer's …
NanoSVG commit 239e102ec contains an incorrect numeric conversion vulnerability in the rasterizer's nsvg__addActive() function. A specially crafted SVG document containing sufficiently large geometry coordinates can cause fixed-point-scaled edge coordinates to exceed the range representable by int. The rasterizer subsequently converts these values to int without range validation, resulting in unde…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-63203] Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.31.0 until 1.42.0,…
Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.31.0 until 1.42.0, the Account API handlers in packages/core/src/routes/account/third-party-tokens.ts allow a caller holding a same-user access token with only the openid scope to retrieve stored social or enterprise SSO provider access tokens through GET /api/my-account/identities/{target}/access-token or GET /api/m…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-97362] HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows unauthenticate…
HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows unauthenticated attackers to cause a complete and persistent loss of availability by sending a single crafted request. Attackers can trigger a hung serving thread that enters a busy loop, rendering the entire file server unresponsive to all clients without self-recovery until an operator manually restarts the ser…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-90959] A path traversal vulnerability was found in pulpcore. The content upload API accepts a 'file_url' pa…
A path traversal vulnerability was found in pulpcore. The content upload API accepts a 'file_url' parameter that allows users with file repository privileges to specify a local file URL for Pulp to download and store. A URL scheme validation check uses a string prefix comparison that only rejects URLs beginning with 'file://', but Python's URL parser recognizes the 'file:' scheme without double sl…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
24/09/2026
[CVE-2026-56736] phpMyFAQ is an open source FAQ web application. A stored cross-site scripting (XSS) vulnerability in…
phpMyFAQ is an open source FAQ web application. A stored cross-site scripting (XSS) vulnerability in versions prior to 4.2.0-alpha allows any unauthenticated user (or low-privileged registered user) to inject arbitrary JavaScript that executes in an administrator's browser when they review or edit a user-submitted FAQ entry. This leads to admin account takeover via session theft. The vulnerability…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-95519] A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a us…
A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `rpm -q -p` or similar manifest-processing flows, leads to arbitrary code execution. This occurs because manifest entries are unexpectedly macro-expanded before being opened, allowing embedded shell commands to run with the privileges of the `rpm` process. Successful exploitat…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-97182] A security vulnerability has been detected in halo-dev Halo up to 2.25.4/2.26.1. Affected is an unkn…
A security vulnerability has been detected in halo-dev Halo up to 2.25.4/2.26.1. Affected is an unknown function of the file application/src/main/java/run/halo/app/content/comment/ReplyNotificationSubscriptionHelper.java of the component SpEL Handler. Such manipulation leads to improper neutralization. The attack may be performed from remote. The exploit has been disclosed publicly and may be used…
M Alto vulnerabilidad
24/09/2026
Vulnerabilidad alta de inyección SQL en DIAEnergie anterior a versión 1.11.00.022
Se ha identificado una vulnerabilidad de inyección SQL (CVE-2026-78309, CVSS 8.8) en DIAEnergie que afecta versiones anteriores a la 1.11.00.022. Esta falla permite a atacantes ejecutar comandos SQL no autorizados, comprometiendo la confidencialidad e integridad de bases de datos en sistemas energéticos altas de la región. Empresas en México y Latinoamérica que utilicen esta plataforma enfrentan riesgo elevado de exfiltración de datos y manipulación de registros operacionales.
M Alto vulnerabilidad
24/09/2026
Vulnerabilidad alta en plugin YOP Poll de WordPress permite robo de credenciales de administrador
El plugin YOP Poll para WordPress (versiones hasta 7.0.10) contiene una falla de validación de origen que permite a atacantes no autenticados robar tokens REST (nonces) de administradores mediante postMessage() con targetOrigin comodín. Los atacantes pueden utilizar estos tokens para cambiar la dirección de correo de cuentas administrativas y comprometer completamente los sitios WordPress. Esta vulnerabilidad afecta directamente a pequeñas y medianas empresas en México y LATAM que utilizan WordPress con plugins no actualizados.