Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 min
Buscando: "Nsa" — 294 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
15/09/2026
[CVE-2026-76866] Netcore NR255-V firmware version 1.5.130703 builds root-run command lines from unquoted user-supplie…
Netcore NR255-V firmware version 1.5.130703 builds root-run command lines from unquoted user-supplied DDNS input in DDNSset_cgi.c and related ddns_Proc.c components, enabling os command argument injection. Attackers can exploit the unsanitized parameters to inject additional command arguments executed with root privileges.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-11729] IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3…
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code in client applications due to unsafe deserialization that enables JNDI injection attacks.
M Alto vulnerabilidad
15/09/2026
Vulnerabilidad alta en Polyaxon 2.16.4: ejecución de código arbitrario vía Jinja2 sin sandbox
Polyaxon versiones hasta 2.16.4 procesa campos de especificación de operaciones con un entorno Jinja2 sin aislamiento durante la preparación de ejecuciones en servidor. Usuarios autenticados pueden inyectar payloads Jinja2 en campos de cola, namespace, condiciones, presets o dependencias para ejecutar comandos del sistema operativo con privilegios del proceso scheduler, comprometiendo credenciales de bases de datos y datos sensibles. Afecta principalmente a plataformas MLOps y orquestación de contenedores en infraestructuras en la nube.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-19816] A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions car…
A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE (dry-run) flag. In the dnf5 backend, the RepoRemove handler ignores that contract and always executes the real transaction because its guard is written as (role == REPO_REMOVE || !SIMULATE), which is always true for RepoRemove. An unprivileged local user can therefore perform a ge…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-61701] Laravel MagicLink creates links for authentication without a password or for accessing private conte…
Laravel MagicLink creates links for authentication without a password or for accessing private content. From 2.0.0 until 2.25.1, MagicLink stores serialized action objects in the magic_links.action database column and deserializes them through src/MagicLink.php and src/Actions/ResponseAction.php without sufficient integrity protection, while an unsafe legacy unserialize() fallback remains reachabl…
M Alto vulnerabilidad
13/09/2026
Vulnerabilidad alta de desbordamiento de búfer en SIPp 3.7.7 y versiones anteriores
SIPp versiones hasta 3.7.7 contiene un desbordamiento de búfer en la función get_header() que permite a atacantes no autenticados enviar mensajes SIP con encabezados superiores a 20,490 bytes para causar crasheo del proceso. Esta vulnerabilidad afecta servidores VoIP y sistemas de prueba de telefonía en infraestructuras empresariales de LATAM. El impacto incluye negación de servicio en infraestructuras de comunicaciones altas.
M Alto vulnerabilidad
13/09/2026
Vulnerabilidad de denegación de servicio en Nodemailer 9.1.0 a 10.0.4 (CVE-2026-90776)
Nodemailer versiones 9.1.0 a 10.0.4 contienen una vulnerabilidad de complejidad cuadrática en el parser de direcciones que procesa comentarios RFC 5322. Atacantes pueden enviar encabezados de correo malformados para consumir CPU excesiva y bloquear el event loop de Node.js durante varios segundos, generando negación de servicio. Afecta especialmente a plataformas de notificaciones y sistemas de correo transaccional en LATAM que procesan volúmenes altos de mensajes.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
13/09/2026
Vulnerabilidad alta de desbordamiento de búfer en SIPp 3.7.7 y anteriores
SIPp versiones hasta 3.7.7 contiene un desbordamiento de búfer en la función get_peer_tag() al procesar encabezados SIP con parámetros de etiqueta superiores a 2048 bytes. Atacantes no autenticados pueden enviar mensajes SIP manipulados para causar el bloqueo de procesos en servidores de comunicaciones VoIP y telefonía empresarial. Este riesgo afecta infraestructuras de telefonía en la nube y sistemas PBX que implementen SIPp.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-15462] The Sticky Chat Widget plugin for WordPress is vulnerable to SQL Injection via the 'scw_form_fields'…
The Sticky Chat Widget plugin for WordPress is vulnerable to SQL Injection via the 'scw_form_fields' parameter array keys of the 'scw_save_form_data' AJAX action in versions up to, and including, 1.4.2. This is due to the save_form_data() function passing attacker-controlled POST array keys unsanitized to $wpdb->insert(), which wraps column identifiers in backticks without escaping them, allowing …
M Alto vulnerabilidad
10/09/2026
[CVE-2026-45768] Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M…
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, LDAP transaction state could store an unbounded number of responses. Because LDAP can be processed over UDP, crafted traffic may cause Suricata to consume excessive memory, potentially resulting in denial of service. Version 8.0…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-73694] FileRun before 2026.3.0 contains an OS command injection vulnerability caused by a no-op redefinitio…
FileRun before 2026.3.0 contains an OS command injection vulnerability caused by a no-op redefinition of escapeshellcmd() in CLI.php that strips shell-metacharacter escaping, allowing attacker-controlled input to reach an exec() sink unsanitized. Attackers can exploit this through an interactive path via image_preview.php with a crafted args parameter requiring superuser authentication, or through…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-78623] The Okta Access Gateway does not sanitize SAML assertion values before interpolating them into datab…
The Okta Access Gateway does not sanitize SAML assertion values before interpolating them into database queries in the advanced mode datastore configuration. The unsanitized values are substituted directly into the query string prior to preparation, resulting in unintended SQL execution against the configured backend database.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-73316] XenForo before 2.3.13 contains a payment replay vulnerability in the PayPal REST payment provider th…
XenForo before 2.3.13 contains a payment replay vulnerability in the PayPal REST payment provider that allows attackers to process the same webhook payload multiple times by exploiting a missing duplicate transaction ID check. Attackers can replay a valid webhook payload to trigger duplicate payment events, resulting in repeated subscription activations and unauthorized account upgrades.
M Alto vulnerabilidad
08/09/2026
Vulnerabilidad alta en PX4 Autopilot 1.17.0 y anteriores: use-after-free en módulo load_mon
PX4 Autopilot versiones hasta 1.17.0 contiene una vulnerabilidad use-after-free en el módulo load_mon que permite a atacantes ejecutar comandos maliciosos a través de shells PXH o MAVLink, causando corrupción de memoria. Esta falla afecta directamente sistemas de vehículos autónomos, drones industriales y equipos de defensa en operaciones altas en LATAM, siendo explotable sin autenticación en entornos accesibles.
M Alto vulnerabilidad
05/09/2026
[CVE-2026-19887] The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up…
The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.1 via deserialization of untrusted input in the Telecom EDY payment callback (usces_action_acting_transaction). Unauthenticated attackers can store arbitrary 'reserve' key/value pairs as order metadata during a public checkout, then invoke the callback with an attacker-chose…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
04/09/2026
[CVE-2026-18175] IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due t…
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due to improper authorization in the DDM target dispatcher.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85160] AVideo through commit c91b5975d contains a cross-site request forgery and path traversal vulnerabili…
AVideo through commit c91b5975d contains a cross-site request forgery and path traversal vulnerability in stopLive.php that allows attackers to delete directories by exploiting missing token validation and unsanitized key parameter concatenation. Attackers can craft an image tag with a traversal payload like key=../../videos to trigger recursive deletion of the videos directory when an admin visit…
M Alto vulnerabilidad
02/09/2026
Vulnerabilidad alta de RCE en DSpace 8.x, 9.x y 10.x afecta repositorios digitales
DSpace, software de código abierto ampliamente utilizado en universidades y instituciones públicas de LATAM para gestionar repositorios digitales, es vulnerable a ejecución remota de código (RCE) mediante plantillas Velocity en mensajes COAR Notify/LDN. Las versiones afectadas son 8.0-rc1 a 8.3, 9.0-rc1 a 9.2, y 10-rc1. Un atacante no autenticado podría ejecutar código arbitrario en el servidor con privilegios del proceso DSpace, comprometiendo la integridad de acervos académicos y datos sensibles.
M Alto vulnerabilidad
02/09/2026
Exposición de datos sensibles sin autenticación en WooCommerce Product Attachment ≤ 2.3.3
WooCommerce Product Attachment versión 2.3.3 y anteriores contiene una vulnerabilidad que permite a atacantes acceder a datos sensibles sin requerir autenticación, con puntuación CVSS 7.5. Esta exposición afecta principalmente a tiendas en línea operadas en México y Latinoamérica que utilizan este plugin en WordPress. El riesgo se amplifica en entornos de comercio electrónico que manejan información de clientes, productos o transacciones.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84202] ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, allowing arbitrary c…
ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, allowing arbitrary code execution through Python object construction tags. Attackers can craft malicious model repositories with poisoned configuration files that execute code when loaded by users.