Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
Buscando: "Rti" — 687 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
16/09/2026
[CVE-2026-89922] In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Take srcu when impor…
In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Take srcu when importing watchpoint data __import_wp_info() backs up the original guest memory contents of a watchpoint with read_guest_abs(), which is kvm_read_guest() and therefore resolves the memslot via __kvm_memslots(). That requires kvm->srcu (or kvm->slots_lock) to be held, otherwise a concurrent memslot updat…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-89856] In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Clamp MSI-X deri…
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Clamp MSI-X derived queue counts to avoid truncation ha->msix_count is u16, but ha->max_req_queues, ha->max_rsp_queues and ha->max_qpairs are u8. Deriving the queue count as "ha->max_req_queues = ha->msix_count - 1" therefore truncates: a board (or a misconfigured/malicious hot-plugged device) advertising 257 MSI-…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-89823] In the Linux kernel, the following vulnerability has been resolved: drm: fix race between partial d…
In the Linux kernel, the following vulnerability has been resolved: drm: fix race between partial drm_dev_register() failure and ioctl If drm_dev_register() fails after registering a minor (e.g. render minor registered, primary minor fails), userspace could have opened the first minor and entered a drm_dev_enter() critical section. Since the unplugged flag was never set, the ioctl proceeds while…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-89814] In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: clamp the isolation…
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: clamp the isolation index for rings outside a partition adev->isolation[] has one slot per partition, but a ring that is not assigned to one keeps AMDGPU_XCP_NO_PARTITION, which is ~0, so indexing the array with it is out of bounds. SDMA submissions hit this on both the isolation enforcement and the VM flush path and…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-89781] In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix out-of-bounds rea…
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix out-of-bounds read in read_log_rec_buf() read_log_rec_buf() copies a log record into a caller buffer starting at u32 off = lsn_to_page_off(log, lsn) + log->record_header_len; log->record_header_len (and log->data_off, used for the following pages) comes verbatim from the on-disk restart area and is only checked …
M Alto vulnerabilidad
16/09/2026
Vulnerabilidad alta en Arista EOS con gNSI permite escalada de privilegios (CVE-2026-73454)
Plataformas Arista EOS con interfaz gRPC Network Security Interface (gNSI) Credentialz configurada son vulnerables a solicitudes especialmente diseñadas que modifican propiedades de cuentas de usuario. Un atacante podría asignar privilegios elevados a cuentas existentes, comprometiendo el control de acceso en infraestructura de red alta. El impacto afecta directamente a proveedores de servicios y centros de datos en LATAM que dependen de equipos Arista para segmentación y control de tráfico.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-73446] On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthen…
On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker can send a crafted IS-IS Hello Protocol Data Unit (PDU) that causes the device to tear down an established IS-IS adjacency. This may result in traffic disruption and loss of IP reachability for prefixes advertised through that adjacency.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
15/09/2026
[CVE-2026-88975] Http4s is a Scala interface for HTTP services. Prior to 0.23.37 and 1.0.0-M48, Ember’s HTTP/2 read l…
Http4s is a Scala interface for HTTP services. Prior to 0.23.37 and 1.0.0-M48, Ember’s HTTP/2 read loop parses a frame’s 24-bit declared length but waits to buffer the entire payload before comparing it with SETTINGS_MAX_FRAME_SIZE. An unauthenticated peer can declare a payload near 16 MiB on a connection where Ember advertised 16 KiB and either complete or slowly stream it, causing up to 1024-fol…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-73955] Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Char…
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Charting). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker. Successful at…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-88765] GitLab has remediated an issue in GitLab EE affecting all versions from 12.3 to 19.1.8, 19.2 before …
GitLab has remediated an issue in GitLab EE affecting all versions from 12.3 to 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 under certain conditions could allow an authenticated user to achieve remote code execution by importing a specially crafted Git project export to overflow the Unicode conversion buffer used in Advanced Search indexing.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-61668] DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0…
DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, WorkloadManagementSystem/Utilities/PilotWrapper.py pilotWrapperScript uses ssl._create_unverified_context to download the second-stage pilot.tar archive without TLS certificate verification and downloads the reference checksum through the same unvalidated channel. An attacke…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-12150] IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3…
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote attacker with a trusted TLS client certificate to cause a denial of service and potentially affect memory contents due to improper validation of deeply nested certificate data during …
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91955] FreeRDP before 3.31.0 fails to validate client-supplied DesktopWidth and DesktopHeight values during…
FreeRDP before 3.31.0 fails to validate client-supplied DesktopWidth and DesktopHeight values during GCC negotiation, allowing remote attackers to crash the server. Attackers can send crafted RDP packets with zero or oversized dimensions to trigger division-by-zero or assertion failures in multifragment update capability calculations, terminating the server process.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91848] A vulnerability was identified in WuzhiCMS up to 4.1.0. Affected by this issue is the function artic…
A vulnerability was identified in WuzhiCMS up to 4.1.0. Affected by this issue is the function article::getDataOfJson of the file /index.php?m=content&f=article&v=getDataOfJson. The manipulation of the argument title/master_table leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early …
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92047] Privilege escalation in the Crash Reporting component. This vulnerability was fixed in Firefox 156 a…
Privilege escalation in the Crash Reporting component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
15/09/2026
Vulnerabilidad de acceso anónimo en lamp-cloud permite lectura de propiedades del sistema JVM
lamp-cloud en versiones hasta 5.10.0 expone un patrón de ruta /*/anno/** accesible sin autenticación, permitiendo a atacantes remotos recuperar propiedades altas del JVM como rutas del sistema de archivos, classpath, detalles del SO y secretos de inicio mediante solicitudes POST a /defGenProject/anno/getProperties. Esta exposición de metadatos del servidor facilita reconocimiento para ataques posteriores contra infraestructura en México y LATAM.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-13107] IBM Business Automation Workflow containers and traditional may use programming model artifacts that…
IBM Business Automation Workflow containers and traditional may use programming model artifacts that are vulnerable to XML Entity Injection attacks by default.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-19624] A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection proper…
A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection properties (vpn.data and vpn.secrets values) unescaped into a generated ipsec.conf file that pluto loads as root. A local unprivileged user can create and activate their own L2TP VPN profile containing a newline-injected leftupdown directive; pluto executes that command as root when the IKE security assoc…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-57132] PraisonAI is a multi-agent teams system. Prior to 4.6.62, setting PRAISONAI_CALL_AUTH to disabled ma…
PraisonAI is a multi-agent teams system. Prior to 4.6.62, setting PRAISONAI_CALL_AUTH to disabled makes verify_token accept requests to /api/v1/agents/{id}/invoke without CALL_SERVER_TOKEN authentication. Deployments that use the application's advertised opt-out can expose registered agents and their connected tools or private context to unauthenticated invocation. The vulnerability is fixed in 4.…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-82428] Description Dependency artifacts uploaded with `storm jar --artifacts` were stored under a blob key…
Description Dependency artifacts uploaded with `storm jar --artifacts` were stored under a blob key derived only from the Maven coordinate, for example `dep---.jar`. The key was therefore identical for every user of the cluster and predictable in advance. When the blob already existed, the uploader caught `KeyAlreadyExistsException` and silently reused it, with no check that the existing blob's c…