Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
Buscando: "Multiple Vendors" — 13201 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Alto vulnerabilidad
12/06/2026
[CVE-2026-50108] The Naxclow platform API that returns device relay registration details exposes a persistent credent…
The Naxclow platform API that returns device relay registration details exposes a persistent credential without verifying that the requester is the legitimate device or owner. An actor able to present a platform-valid request signature can retrieve credentials for arbitrary devices and register on the relay as that device, enabling interception and disruption of its communications.
M Alto vulnerabilidad
12/06/2026
[CVE-2026-42947] A flaw in Naxclow's platform’s onboarding workflow allows an attacker to replay a confirm-then-bind …
A flaw in Naxclow's platform’s onboarding workflow allows an attacker to replay a confirm-then-bind sequence to silently reassign a device to an arbitrary account. Because the affected endpoints validate request signatures but do not confirm legitimate ownership, an attacker with any account can take over a device without user interaction while the device remains online and unaware.
M Alto vulnerabilidad
12/06/2026
[CVE-2026-12043] Improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library m…
Improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library might allow a remote threat actor operating a server to cause memory corruption on a connecting client application, potentially leading to arbitrary code execution, via a crafted sequence of HTTP/2 HEADERS frames. To remediate this issue, users should upgrade to aws-c-http version 0.11.0.
M Alto vulnerabilidad
12/06/2026
[CVE-2026-12143] form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5,…
form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header without escaping carriage return (CR), line feed (LF), or double-quote (") characters. An application that passes attacker-controlled data as a field name or filename …
M Alto vulnerabilidad
12/06/2026
[CVE-2026-53981] Cap-go prior to 12.128.2 contains an account takeover vulnerability in its email change mechanism th…
Cap-go prior to 12.128.2 contains an account takeover vulnerability in its email change mechanism that allows an attacker with temporary authenticated session access to change the registered email address without re-authentication such as password or MFA verification. Attackers can redirect verification to an attacker-controlled email address and subsequently perform a password reset to permanentl…
M Alto vulnerabilidad
12/06/2026
[CVE-2026-9638] Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure random values for salts. These ve…
Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitable for cryptography.
M Alto vulnerabilidad
12/06/2026
[CVE-2026-6211] Unrestricted upload of file with dangerous type vulnerability in Global IT Informatics Services Inc.…
Unrestricted upload of file with dangerous type vulnerability in Global IT Informatics Services Inc. WEOLL allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WEOLL: from 2.0.9 before 3.2.45.33.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
12/06/2026
[CVE-2026-7368] The Yarbo cloud does not enforce per-device or per-user authorization. Any client possessing valid c…
The Yarbo cloud does not enforce per-device or per-user authorization. Any client possessing valid credentials, whether the shared hard-coded credentials or legitimate per-user credentials, can subscribe to wildcard topics covering all robots globally, and can publish to any robot's command topic using only the robot's serial number (disclosed in the telemetry stream). Even after removal of hard-c…
M Alto vulnerabilidad
12/06/2026
[CVE-2026-47135] vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, Symbol.for override in setup-…
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, Symbol.for override in setup-sandbox.js only intercepts 2 of 9 dangerous Node.js cross-realm symbols. Combined with the bridge's set/defineProperty/deleteProperty traps having no isDangerousCrossRealmSymbol key check, sandbox code can obtain real cross-realm symbols, write them to host objects, and control host-side behavior — …
M Alto vulnerabilidad
12/06/2026
[CVE-2026-47139] vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM supports excluding pub…
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM supports excluding public network builtins from the wildcard builtin option. With this configuration direct access to http, https, http2, net, dgram, tls, dns, and dns/promises is blocked. However, Node.js also exposes underscored internal HTTP builtins such as _http_client and _http_server. These are not blocked when th…
M Alto vulnerabilidad
12/06/2026
[CVE-2026-47209] vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the BaseHandler.set trap in b…
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the BaseHandler.set trap in bridge.js (line 1231) ignores the receiver parameter and unconditionally writes to the host target object. Per the Proxy set trap specification, when receiver !== proxy (e.g., when a child object inherits from the proxy via Object.create), the property assignment should create an own property on the …
M Alto vulnerabilidad
12/06/2026
[CVE-2026-12066] A security flaw has been discovered in PbootCMS up to 3.2.12. This vulnerability affects the functio…
A security flaw has been discovered in PbootCMS up to 3.2.12. This vulnerability affects the function retrieve of the file apps/home/controller/MemberController.php of the component Password Handler. The manipulation of the argument username/password/email/checkcode results in weak password recovery. It is possible to launch the attack remotely. The exploit has been released to the public and may …
M Alto vulnerabilidad
12/06/2026
[CVE-2026-11845] The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a OS Command Injecti…
The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a OS Command Injection vulnerability, allowing privileged remote attackers to inject arbitrary OS commands and execute them on the device.
M Alto vulnerabilidad
12/06/2026
[CVE-2026-11846] The  iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has an Arbitrary File D…
The  iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has an Arbitrary File Deletion vulnerability, allowing authenticated remote attackers to exploit this vulnerability to delete arbitrary system files or directories,  resulting in data destruction or service disruption.
M Alto vulnerabilidad
12/06/2026
[CVE-2026-12059] The SSH service of CelloOS developed by Cellopoint has an Improper Access Control vulnerability, all…
The SSH service of CelloOS developed by Cellopoint has an Improper Access Control vulnerability, allowing authenticated remote attackers to bypass the enforced command restrictions and execute operating system commands outside the originally authorized scope.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
12/06/2026
[CVE-2026-48612] Improper state verification in the OAuth implementation could allow an attacker to manipulate the au…
Improper state verification in the OAuth implementation could allow an attacker to manipulate the authentication flow and cause a victim’s account to be linked to an attacker-controlled account. This can result in unauthorized account linking and potential account takeover.
M Alto vulnerabilidad
12/06/2026
[CVE-2026-47368] A malicious actor with access to the network could exploit a Path Traversal vulnerability found in c…
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to obtain data from such UniFi OS devices or instances.
M Alto vulnerabilidad
12/06/2026
[CVE-2026-48610] Under certain network configurations, a malicious actor with access to network could exploit an Impr…
Under certain network configurations, a malicious actor with access to network could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi OS devices.
M Alto vulnerabilidad
12/06/2026
[CVE-2026-47366] Improper verification of access permissions when modifying permissions through the Administration Co…
Improper verification of access permissions when modifying permissions through the Administration Control Panel (ACP) allowed an authenticated administrator to grant permissions beyond the level authorized for their account, resulting in privilege escalation within the administrative interface.
M Alto vulnerabilidad
11/06/2026
[CVE-2026-45418] ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #132, any authentic…
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #132, any authenticated user who can upload videos can add multiple subtitles from different files and change their title (English, Spanish...). The POST /actions/subtitle_edit.php request used to change their title includes a number parameter which is vulnerable to SQL Injection. A boolean-based blind SQL injection c…