Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1019
Esta semana
RSS
M Alto vulnerabilidad
04/09/2026
[CVE-2026-19298] IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitra…
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitrary code due to an authorization bypass in the flow build process.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85694] LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract…
LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived from web page content. Attackers can inject malicious Python code through web pages using indirect prompt injection to execute arbitrary code on the operator's host without review.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85674] aider (aider-chat) automatically loads a .aider.conf.yml configuration file from the root of the git…
aider (aider-chat) automatically loads a .aider.conf.yml configuration file from the root of the git repository it is launched in. A crafted repository can set test-cmd (executed at startup) or lint-cmd (executed on the first file edit), which aider runs through a shell (subprocess with shell=True) without any user confirmation, LLM interaction, or API key. Consequently, a user who clones and runs…
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85623] goose 1.37.0 executes arbitrary commands from recipe stdio extensions and retry.checks without secur…
goose 1.37.0 executes arbitrary commands from recipe stdio extensions and retry.checks without security inspection. Attackers can distribute malicious recipes that execute shell commands as the user running goose, bypassing the recipe security scan which does not inspect extensions or retry configurations.
M Alto vulnerabilidad
04/09/2026
Vulnerabilidad alta de ejecución remota de código en Grav <= 2.0.17
Grav antes de la versión 2.0.19 contiene una vulnerabilidad de ejecución remota de código (RCE) en el filtro Twig sort, que permite a usuarios autenticados ejecutar código PHP arbitrario mediante la función spl_autoload omitida en el denylist de seguridad. Afecta principalmente a sitios que utilizan Grav como CMS para portales web, intranets y aplicaciones empresariales en LATAM. El impacto es alta (CVSS 8.8) ya que compromete completamente la integridad del servidor.
M Alto vulnerabilidad
04/09/2026
Vulnerabilidad alta en OpenPanel anteriores a 2.3.0 permite ejecución de código remoto
OpenPanel versiones anteriores a 2.3.0 contiene una falla en la validación de expresiones de fórmulas en gráficos que permite a miembros autenticados del proyecto con acceso de lectura ejecutar código arbitrario. Los atacantes pueden recuperar el constructor nativo de JavaScript a través de objetos matriz de mathjs, cargar módulos de Node.js y ejecutar comandos del sistema operativo con privilegios del proceso API, comprometiendo completamente la infraestructura.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-19224] The Hummingbird Performance WordPress plugin before 3.21.2 does not restrict a network-wide setting…
The Hummingbird Performance WordPress plugin before 3.21.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85137] A security vulnerability has been detected in SeaCMS up to 13.6. This impacts the function parseIf o…
A security vulnerability has been detected in SeaCMS up to 13.6. This impacts the function parseIf of the file seacms_locoy_news.php of the component Locoy Collector. The manipulation of the argument pwd leads to code injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
M Alto vulnerabilidad
02/09/2026
Vulnerabilidad alta de RCE en DSpace 8.x, 9.x y 10.x afecta repositorios digitales
DSpace, software de código abierto ampliamente utilizado en universidades y instituciones públicas de LATAM para gestionar repositorios digitales, es vulnerable a ejecución remota de código (RCE) mediante plantillas Velocity en mensajes COAR Notify/LDN. Las versiones afectadas son 8.0-rc1 a 8.3, 9.0-rc1 a 9.2, y 10-rc1. Un atacante no autenticado podría ejecutar código arbitrario en el servidor con privilegios del proceso DSpace, comprometiendo la integridad de acervos académicos y datos sensibles.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-52833] Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5…
Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5, Nuclio's Java runtime generates a build.gradle file during function builds using Go's text/template package. The template renders runtimeAttributes.repositories[] values with the {{ . }} action, which performs no escaping. An attacker can embed a closing brace (}) to break out of the repositories …
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84645] In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their conf…
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration in independent top-level configuration files in Jenkins (such as the global configuration and jobs) can appear as nested field values in user-submitted `config.xml` documents and subsequently handle HTTP requests via Stapler, resulting in remote code execution.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-58572] Dell PowerStore contains a Code Injection vulnerability. An authenticated user with limited privileg…
Dell PowerStore contains a Code Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary code with root privileges.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82393] pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a t…
pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a tarball dependency's package.json manifest name because pnpm11/resolving/npm-resolver/src/pickPackage.ts rejects slash characters only for unscoped names. During pnpm install, the unvalidated name reaches raw path joins in pnpm11/installing/deps-resolver/src/resolvePeers.ts, pnpm11/installing/deps-re…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82598] A vulnerability was determined in SeaCMS up to 13.6. Affected is the function parseIf of the file se…
A vulnerability was determined in SeaCMS up to 13.6. Affected is the function parseIf of the file search.php of the component Template Engine. This manipulation of the argument searchtype causes code injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-18729] IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitra…
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
28/08/2026
[CVE-2026-82278] BISHENG before 2.6.0 contains a remote code execution vulnerability in the workflow run_once endpoin…
BISHENG before 2.6.0 contains a remote code execution vulnerability in the workflow run_once endpoint that allows authenticated users to execute arbitrary Python code. Attackers can submit crafted Code node definitions to the POST /api/v1/workflow/run_once endpoint, which executes them with exec() without sandboxing, gaining access to filesystem, credentials, and internal network resources.
M Alto vulnerabilidad
27/08/2026
[CVE-2026-54721] Silverstripe UserForms provides a visual form builder for the Silverstripe CMS. From 6.0.0 until 6.4…
Silverstripe UserForms provides a visual form builder for the Silverstripe CMS. From 6.0.0 until 6.4.9, 7.0.7, and 7.1.1, the userform email recipient subject field in the CMS accepts a specially crafted payload that can be interpreted as executable server-side code. An authenticated CMS user with permission to configure a UserForms email recipient can use the subject field to run arbitrary code o…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-81719] openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls: the …
openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls: the plugin signature policy defaulted to WARN, so an unsigned/unverifiable non-built-in plugin was compiled and executed in the host process at import time, before the runtime sandbox is installed. The only default gate was an incomplete, bypassable AST denylist. If a user is induced to load an attacker…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-19223] The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network adminis…
The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-58474] whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands that …
whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands that allows a remote attacker who controls a HuggingFace repository to achieve arbitrary code execution by crafting a malicious GGUF filename containing double quotes or other special characters. The script generation function in cli.py interpolates HuggingFace-derived values, including GGUF variant file…