Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1019
Esta semana
RSS
M Alto vulnerabilidad
19/08/2026
[CVE-2026-76330] In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user coul…
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an authenticated user into opening a crafted link to Monitoring Console. When the authenticated user opens the link, Splunk Enterprise runs attacker-controlled Search Processing Language (SPL) using the permissions of that user. The injected SPL could access data and perform actions availabl…
M Alto vulnerabilidad
19/08/2026
[CVE-2026-76332] In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user coul…
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an authenticated user into opening a crafted link to Analytics Workspace. When the authenticated user opens the link, Splunk Enterprise runs attacker-controlled Search Processing Language (SPL) using the permissions of that user. The injected SPL could access data and perform actions availab…
M Alto vulnerabilidad
19/08/2026
[CVE-2026-17414] IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW95…
IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 Power Systems Firmware is affected by a vulnerability in partition firmware during network boot. An unauthenticated attacker with access to the same network as a partition performing a network boot can prevent that partition from completing its boot sequence. On partitions wher…
M Alto vulnerabilidad
19/08/2026
Vulnerabilidad alta de deserialización en SPLWare esProc hasta versión 20260507
Se ha identificado una vulnerabilidad de deserialización insegura en SPLWare esProc que afecta la función ObjectInputStream.readUnshared en SocketData.java. Un atacante remoto puede explotar esta falla para ejecutar código arbitrario en sistemas que ejecuten versiones vulnerables, comprometiendo servidores de procesamiento de datos en empresas de LATAM que utilizan esta plataforma de análisis paralelo.
M Alto vulnerabilidad
18/08/2026
[CVE-2026-52876] Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to v…
Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-path-at-time IPC handler in src/ipc/player.js accepts a renderer-controlled filePath without validating its type or location. If the mpv or VLC launch attempts are skipped or fail, the handler passes filePath to Electron's shell.openPath. A compromised renderer can provide the…
M Alto vulnerabilidad
18/08/2026
[CVE-2026-52877] Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to v…
Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-external IPC handler in src/ipc/downloads.js passes a renderer-supplied url directly to Electron's shell.openExternal without validating its protocol. A compromised renderer can submit file: URIs or operating-system-specific custom schemes, causing the host to open local files…
M Alto vulnerabilidad
18/08/2026
[CVE-2026-47629] NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause impr…
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause improper input validation. A successful exploit might lead to denial of service.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
18/08/2026
[CVE-2026-66783] A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for K…
A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a cluster administrator, or any user with permissions to modify the Submariner Custom Resource (CR), to specify an unvalidated image path. This lack of validation enables an attacker to execute arbitrary code with elevated privileges across the entire cluster, in…
M Alto vulnerabilidad
18/08/2026
[CVE-2026-66793] A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Man…
A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Management for Kubernetes. A user with permissions to annotate the namespaced ManagedClusterAddOn resource can override the governance-policy container image. This allows an attacker to run a controlled image with cluster-admin privileges on the managed cluster, leading to arbitrary code execution and …
M Alto vulnerabilidad
17/08/2026
[CVE-2026-16139] In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zon…
In Progress ShareFile Storage Zones Controller versions
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19826] A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function Hessian…
A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function Hessian2Input.readObject of the file /serialize/impl/HessianSerializer.java of the component xxl-rpc Listener. The manipulation results in deserialization. The attack may be performed from remote. The exploit is now public and may be used. The project closed the issue report as "not planned" without any fu…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-73658] Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4…
Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.5, Aws4FetchClient.buildUrl() and Aws4FetchClient.presign() in apps/webapp/app/v3/objectStoreClient.server.ts assign user-controlled packet keys to URL.pathname, while apps/webapp/app/routes/api.v1.packets.$.ts accepts params["*"] without rejecting dot segments and uses findResourc…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-59109] SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in re…
SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in received electronic invoices. When importing a received e-invoice (UBL/PEPPOL) or an e-commerce export, Zalktis concatenates partner-controlled values directly into SQL statement text using string concatenation, with neither parameterised queries nor escaping. The application's own escaping helper, Da…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-73418] NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 an…
NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the exported getToken() helper in the next-auth/jwt and @auth/core/jwt modules can throw an uncaught exception when it reads a malformed Authorization: Bearer header. When no session cookie is present, getToken() URL-decodes the bearer value before validating it, and malformed perce…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-69106] A low-privileged user may poison cached artifact metadata under specific conditions, potentially cau…
A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
11/08/2026
[CVE-2026-70313] Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose…
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-65811] Improper input validation in Power BI allows an authorized attacker to execute code over a network.
Improper input validation in Power BI allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-63520] Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute …
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-61363] Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code …
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-59134] Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code …
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.