Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1045
Esta semana
RSS
M Alto vulnerabilidad
05/09/2026
Vulnerabilidad SSRF alta en MindsDB hasta v26.1.0 permite acceso a servicios internos
MindsDB versiones hasta 26.1.0 contiene una vulnerabilidad de falsificación de solicitudes del lado del servidor (SSRF) en el manejador de rastreo web que permite a atacantes no autenticados recuperar URLs arbitrarias. Los agresores pueden eludir controles de lista blanca explotando configuraciones vacías por defecto y acceder a servicios internos y puntos de acceso de metadatos en la nube sin autenticación. Afecta especialmente a empresas de IA/ML en LATAM que exponen MindsDB en entornos multi-tenant o híbridos.
M Alto vulnerabilidad
05/09/2026
Vulnerabilidad alta de SSRF sin autenticación en Webstudio ≤0.296.0
Webstudio versión 0.296.0 y anteriores contiene una vulnerabilidad Server-Side Request Forgery (SSRF) sin autenticación en las rutas proxy /cgi/image, /cgi/video y /cgi/asset cuando la variable de entorno RESIZE_ORIGIN no está configurada. Atacantes pueden suministrar URLs arbitrarias para acceder a metadatos de instancias en la nube, servicios internos y realizar reconocimiento de infraestructura. Este vector afecta directamente a empresas en LATAM que ejecutan Webstudio en entornos cloud (AWS, Azure, Google Cloud).
M Alto vulnerabilidad
05/09/2026
SQL Chat: Cuatro endpoints API sin autenticación permiten ejecución de comandos SQL arbitrarios
SQL Chat contiene cuatro endpoints API sin protección de autenticación que aceptan parámetros de conexión a bases de datos suministrados por el atacante, permitiendo ejecutar consultas SQL arbitrarias contra hosts especificados. Los atacantes pueden acceder a bases de datos internas, enumerar esquemas, ejecutar comandos administrativos y pivotar hacia la red interna del servidor comprometido sin requerir credenciales previas. Este vector representa riesgo alta en infraestructuras LATAM donde SQL Chat se utiliza en entornos de desarrollo o acceso a datos corporativos.
M Alto vulnerabilidad
05/09/2026
[CVE-2026-52769] YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, the POST /api/f…
YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, the POST /api/forms/{formId}/actor/inbox route - exposed publicly with acl:"public" - accepts an HTTP Signature header whose keyId parameter is a URL. HttpSignatureService::verifySignature() parses the header and immediately makes a server-side HTTP GET to that URL, before any cryptographic verification or URL val…
M Alto vulnerabilidad
04/09/2026
[CVE-2026-63464] nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.6.0 to before v…
nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.6.0 to before version 0.7.2, non-admin operators (role user) can set allow_private: true on their own managed webhook subscription (POST/PATCH /api/v1/webhook-subscriptions). No admin check exists on this field. At delivery time, allow_private switches the dispatcher to an unguarded HTTP client, bypassing the priv…
M Alto vulnerabilidad
04/09/2026
[CVE-2026-77822] IBM ContextForge MCP Gateway could allow a remote authenticated attacker to obtain sensitive informa…
IBM ContextForge MCP Gateway could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery via DNS rebinding.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-19304] IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitiv…
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information from internal services due to a URL parser discrepancy.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
04/09/2026
[CVE-2026-19305] IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information …
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server-side request forgery.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-18905] IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) <= v1.0.6 MCP Context Forge could allow a …
IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`)
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85699] jina-ai reader contains a server-side request forgery vulnerability where URL validation is performe…
jina-ai reader contains a server-side request forgery vulnerability where URL validation is performed only on the initial request but not re-applied to subsequent redirect hops. Attackers can craft a public URL that redirects to internal network addresses or cloud metadata endpoints, allowing the server to fetch and return the target's response body to the attacker.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85691] MegaParse 0.0.55 contains an unauthenticated server-side request forgery vulnerability in the POST /…
MegaParse 0.0.55 contains an unauthenticated server-side request forgery vulnerability in the POST /v1/url endpoint that fetches caller-supplied URLs server-side. Attackers can supply internal service URLs or metadata endpoints without authentication to read their responses directly from the JSON response.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85686] ms-swift 4.5.2 contains a server-side request forgery vulnerability in the swift deploy OpenAI-compa…
ms-swift 4.5.2 contains a server-side request forgery vulnerability in the swift deploy OpenAI-compatible API that fetches multimodal media URLs without validation or redirect filtering. Unauthenticated attackers can supply arbitrary image_url, audio_url, or video_url parameters to make the server issue requests to internal services and cloud metadata endpoints.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85673] LLaMA-Factory contains a server-side request forgery vulnerability in the OpenAI-compatible API mult…
LLaMA-Factory contains a server-side request forgery vulnerability in the OpenAI-compatible API multimodal media URL handler that allows unauthenticated attackers to bypass SSRF validation. The check_ssrf_url guard validates URLs once but requests.get follows redirects and re-resolves DNS without re-validation, enabling attackers to use HTTP redirects or DNS rebinding to access internal addresses …
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85675] OWL's DocumentProcessingToolkit contains a server-side request forgery vulnerability in the extract_…
OWL's DocumentProcessingToolkit contains a server-side request forgery vulnerability in the extract_document_content tool that fetches caller-supplied URLs with no scheme, host, or IP filtering. Attackers can inject malicious URLs through prompt injection to make the server fetch internal resources, with responses returned to the agent context.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85666] OGX (formerly Llama Stack, affected at commit fbe8e0f) contains an unauthenticated server-side reque…
OGX (formerly Llama Stack, affected at commit fbe8e0f) contains an unauthenticated server-side request forgery vulnerability in the OpenAI-compatible POST /v1/responses endpoint. MCP tool definitions accept a server_url parameter (along with headers and authorization values) that is fetched server-side without destination validation; the existing validate_url_not_private() guard used for other URL…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85608] Douyin_TikTok_Download_API through 4.1.2 contains a server-side request forgery vulnerability in the…
Douyin_TikTok_Download_API through 4.1.2 contains a server-side request forgery vulnerability in the /api/download and /api/hybrid/video_data endpoints that allows unauthenticated attackers to fetch arbitrary URLs by supplying a url query parameter. Attackers can request internal services including cloud metadata endpoints and retrieve response bodies containing sensitive credentials through error…
M Alto vulnerabilidad
04/09/2026
Vulnerabilidad SSRF alta en Openpanel anterior a versión 2.3.0 permite acceso no autenticado
Openpanel versiones anteriores a 2.3.0 contiene una vulnerabilidad de falsificación de solicitud del lado del servidor (SSRF) sin autenticación en el endpoint GET /tools/site-checker. Un atacante remoto puede enviar URLs arbitrarias a través del parámetro de consulta url, forzando al servidor a realizar peticiones HTTP a sistemas internos y externos sin validación. Este vector afecta especialmente a proveedores de hosting y servicios web en LATAM que utilizan Openpanel como panel de control.
M Alto vulnerabilidad
04/09/2026
Vulnerabilidad alta de SSRF en OpenPanel anterior a 2.3.0 permite acceso no autenticado a metadatos internos
OpenPanel versiones anteriores a 2.3.0 contiene una vulnerabilidad de Server-Side Request Forgery (SSRF) en los endpoints /misc/favicon y /misc/og que permite a atacantes no autenticados forzar al servidor a consultar hosts internos y endpoints de metadatos en la nube. Los atacantes pueden enumerar servicios internos, robar credenciales y acceder a información sensible de infraestructura. Esta vulnerabilidad afecta directamente a empresas en LATAM que utilizan OpenPanel como panel de control, especialmente en entornos de hosting compartido y nubes públicas.
M Alto vulnerabilidad
04/09/2026
Vulnerabilidad alta de SSRF en OpenPanel antes de 2.3.0 permite acceso a servicios internos
OpenPanel anterior a versión 2.3.0 contiene una vulnerabilidad de Server-Side Request Forgery (SSRF) sin autenticación en el endpoint GET /tools/site-checker que permite a atacantes remotos hacer que el servidor emita solicitudes hacia servicios internos, localhost y endpoints de metadatos en la nube. Un atacante puede explotar esto para leer títulos de respuestas HTTP internas, información sensible de la infraestructura y credenciales almacenadas en metadatos. Esta vulnerabilidad afecta directamente a proveedores de hosting, resellers y empresas que utilizan OpenPanel como panel de control en sus servidores en México y Latinoamérica.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85380] A weakness has been identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601…
A weakness has been identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This vulnerability affects the function catchimage of the file Public/ueditor/php/controller.php of the component UEditor. This manipulation of the argument source[] causes server-side request forgery. The attack may be initiated remotely. The exploit has been made ava…