Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1019
Esta semana
RSS
M Alto vulnerabilidad
01/09/2026
[CVE-2026-61759] NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u…
NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-61750] NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u…
NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-83497] Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch …
Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin allows a remote authenticated user with basic read/search permissions to execute arbitrary code on the server by sending a crafted cursor parameter to the plugins/sql endpoint.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-81757] Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions.
Author Remote Code Execution (RCE) in Rank Math SEO
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad de expansión de deserialización en SvelteKit 2.49.0 a 2.53.2 (CVE-2026-82259)
SvelteKit versiones 2.49.0 a 2.53.2 contienen un fallo de expansión de deserialización en la función experimental remoteFunctions. Atacantes pueden enviar entradas pequeñas que se expanden en arreglos de archivos masivos, causando agotamiento de memoria y denegación de servicio en aplicaciones web que procesan funciones remotas sin validar tamaños. El parche está disponible en versión 2.53.3.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-14558] The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions …
The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions and deserialises user-controlled post metadata when rendering submitted posts, allowing users with Editor-level access and above to inject arbitrary PHP objects, which can lead to remote code execution when a suitable POP chain is present on the site.
M Alto vulnerabilidad
27/08/2026
[CVE-2026-10036] SpeechBrain before 1.1.1 contains an arbitrary code execution vulnerability that allows attackers to…
SpeechBrain before 1.1.1 contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary code by supplying a crafted CKPT.yaml checkpoint metadata file parsed with PyYAML's unsafe loader during candidate enumeration in Checkpointer.recover_if_possible(). Attackers can embed malicious Python object construction tags such as !!python/object/apply in any CKPT.yaml file w…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
27/08/2026
[CVE-2026-78276] Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.
Editor PHP Object Injection in Fluent Boards Pro
M Alto vulnerabilidad
27/08/2026
[CVE-2026-78257] Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.
Contributor PHP Object Injection in Booking and Rental Manager
M Alto vulnerabilidad
25/08/2026
Inyección de Objetos PHP en plugin Kalles Addons para WordPress (CVE-2026-78572)
El plugin Kalles Addons para WordPress contiene una vulnerabilidad alta de inyección de objetos PHP (CVSS 8.1) en todas las versiones hasta la 1.0.6. Atacantes no autenticados pueden inyectar objetos maliciosos mediante deserialización de entrada no validada. El impacto depende de cadenas POP presentes en otros plugins o temas instalados, siendo de alto riesgo en tiendas WooCommerce y sitios corporativos de LATAM que usen extensiones adicionales.
M Alto vulnerabilidad
24/08/2026
[CVE-2026-40877] Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP ob…
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.
M Alto vulnerabilidad
24/08/2026
[CVE-2026-76843] The official Flair wheels for 0.15.0 and 0.15.1 still contain flair/models/clustering.py, whose Clus…
The official Flair wheels for 0.15.0 and 0.15.1 still contain flair/models/clustering.py, whose ClusteringModel.load static method returns pickle.loads(joblib.load(str(model_file))) and so executes arbitrary Python while loading a model file. Loading a model supplied by an attacker therefore runs that attacker's code with the privileges of the loading process. This is the same sink and the same fi…
M Alto vulnerabilidad
23/08/2026
[CVE-2026-78147] A vulnerability was found in ggml-org llama.cpp bec4772f6. The impacted element is the function dese…
A vulnerability was found in ggml-org llama.cpp bec4772f6. The impacted element is the function deserialize_tensor of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component ggml-RPC Server. Performing a manipulation of the argument op/op_params results in deserialization. The attack may be initiated remotely. This vulnerability is distinct from CVE-2026-34159 (GHSA-j8rj-fmpv-wcxw, PR #20908), wh…
M Alto vulnerabilidad
23/08/2026
Vulnerabilidad alta de inyección de objetos PHP en plugin PPWP para WordPress (CVE-2026-0551)
El plugin Password Protect Pages (PPWP) para WordPress en versiones hasta 1.9.18 es vulnerable a inyección de objetos PHP mediante deserialización insegura del parámetro 'post_protection_roles'. Atacantes autenticados con acceso de Colaborador o superior pueden ejecutar código arbitrario en servidores web. Esta vulnerabilidad afecta principalmente a sitios corporativos y de comercio electrónico en México y LATAM que protegen contenido sensible con este plugin.
M Alto vulnerabilidad
22/08/2026
[CVE-2026-71513] NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validat…
NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers to resolve dotted names by attribute traversal to callables outside the allowlisted namespace. Attackers can craft untrusted transition-parser models that execute arbitrary commands when TransitionParser.parse loads the mod…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
21/08/2026
[CVE-2026-54071] BabelDOC is a document translation tool. Prior to 0.6.3, BabelDOC's vendored PDF parser in babeldoc/…
BabelDOC is a document translation tool. Prior to 0.6.3, BabelDOC's vendored PDF parser in babeldoc/pdfminer/cmapdb.py deserializes untrusted pickle data when CMapDB._load_data() loads CMap files. PDF-controlled Encoding or CMapName values and embedded PostScript usecmap operators can reach this sink after path separators are decoded, while _normalize_cmap_name() removes only a leading slash. Abso…
M Alto vulnerabilidad
20/08/2026
[CVE-2026-18285] Aeon load_rehab_pile_dataset Deserialization of Untrusted Data Remote Code Execution Vulnerability. …
Aeon load_rehab_pile_dataset Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Aeon. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the load_rehab_pile_dataset met…
M Alto vulnerabilidad
20/08/2026
[CVE-2026-15679] Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution…
Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face PyTorch Image Models. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw …
M Alto vulnerabilidad
19/08/2026
[CVE-2026-76395] In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute ar…
In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splunk server by loading a model file containing crafted sparse matrix data. The deserialization of untrusted data is possible because a model codec in Splunk AI Toolkit deserializes sparse matrix data without guarding against embedded pickle content. For more information see Tro…
M Alto vulnerabilidad
19/08/2026
[CVE-2026-44901] Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4…
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, AffectedItemsWazuhResult.merge() in framework/wazuh/core/results.py trusts the sort_casting field in a cluster worker's JSON response. During a distributed API merge, attacker-controlled type names are resolved through Python builtins without an allowlist. A compro…