Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1038
Esta semana
RSS
M Alto vulnerabilidad
03/09/2026
[CVE-2026-65818] Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privil…
Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-84761] Unauthenticated Server Side Request Forgery (SSRF) in LiteSpeed Cache <= 7.9 versions.
Unauthenticated Server Side Request Forgery (SSRF) in LiteSpeed Cache
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85179] Label Studio through 1.23.0 fails to validate webhook URLs, allowing authenticated users to dispatch…
Label Studio through 1.23.0 fails to validate webhook URLs, allowing authenticated users to dispatch requests to internal services including RFC 1918 addresses and cloud metadata endpoints. Attackers can create webhooks targeting private networks and exfiltrate annotation data by enabling payload transmission in outbound requests.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85180] Ollama fails to validate redirect destinations when pulling tensor-layer models, allowing unauthenti…
Ollama fails to validate redirect destinations when pulling tensor-layer models, allowing unauthenticated attackers to redirect blob downloads to arbitrary hosts. An attacker can control a registry, serve a malicious tensor-layer manifest, and cause the server to issue GET requests to internal hosts including cloud metadata endpoints.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85164] WWBN AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the set…
WWBN AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the set_api_userImages API endpoint that fails to validate profileImg and backgroundImg URLs before fetching them. Authenticated API clients can supply internal URLs to fetch cloud metadata or internal services, with responses written to publicly accessible web paths for retrieval.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-66842] BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrat…
BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrative user accounts through an undisclosed request to Traffic Management User Interface (TMUI). Impact: This vulnerability may allow an authenticated attacker with network access to the BIG-IP management interface to escalate privileges by creating administrative accounts on the BIG-IP system. Th…
M Alto vulnerabilidad
01/09/2026
[CVE-2026-8712] Wyoming before 1.10.2 contains a server-side request forgery vulnerability that allows unauthenticat…
Wyoming before 1.10.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers with network access to force outbound connections to arbitrary targets by supplying a malicious `uri` query parameter to the HTTP API. Attackers can pass arbitrary `tcp://` or `unix://` URIs to affected endpoints including /api/info, /api/speech-to-text, and /api/text-to-speech to overr…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
01/09/2026
Vulnerabilidad SSRF alta en Kyverno anterior a 1.18.0 permite inyección de solicitudes HTTP
Kyverno antes de la versión 1.18.0 contiene una vulnerabilidad de falsificación de solicitud del lado del servidor (SSRF) en apiCall.service.url que permite a usuarios autenticados enviar peticiones HTTP arbitrarias mediante inyección de entrada controlada por el usuario a través de sustitución de variables. Los atacantes pueden comprometer servicios internos, endpoints de metadatos en la nube y direcciones loopback, con datos de respuesta reflejados en mensajes de error de admisión. Esta vulnerabilidad afecta directamente a plataformas Kubernetes en producción en LATAM.
M Alto vulnerabilidad
01/09/2026
Vulnerabilidad SSRF alta en Kyverno anterior a 1.16.2 expone recursos internos
Kyverno antes de versión 1.16.2 contiene una vulnerabilidad de falsificación de solicitud del lado del servidor (SSRF) en la funcionalidad APICall. Un atacante con permisos de creación de políticas a nivel de namespace puede manipular el campo URL en la configuración ServiceCall para dirigir solicitudes HTTP hacia recursos internos arbitrarios, incluyendo endpoints de metadatos en la nube (169.254.169.254) o infraestructura de otros tenants. Esta vulnerabilidad afecta principalmente a empresas con Kubernetes en entornos cloud públicos (AWS, Azure, GCP) donde Kyverno gestiona políticas de seguridad.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82957] A vulnerability was found in hyperledger-firefly firefly up to 1.4.0. The impacted element is the fu…
A vulnerability was found in hyperledger-firefly firefly up to 1.4.0. The impacted element is the function ValidateOptions of the file internal/events/webhooks/webhooks.go of the component Webhook Subscription. Performing a manipulation of the argument url results in server-side request forgery. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The …
M Alto vulnerabilidad
31/08/2026
[CVE-2026-77348] Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, the f…
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, the fix for CVE-2026-33407 (GHSA-hhjq-82f8-m6rc, "SSRF via HTTP Proxy Environment Variable") hardened endpoints/logos/search.php by disabling cURL proxying (CURLOPT_PROXY = '' + CURLOPT_NOPROXY = '*'). However, Wallos ships a second, near-identical, unauthenticated logo-image search endpoint — endpoints/…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-81889] elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1…
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, elFinder URL uploads in php/elFinder.class.php can bypass server-side request forgery protections when PHP cURL is unavailable because validate_address() validates $info['ip'], but get_remote_contents() selects fsock_get_contents(), which connects to $arr['host'] and performs a second DNS resol…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-79747] MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/AP…
MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.32, an authenticated non-admin user can register a server pointing at an arbitrary URL and make the hub issue server-side requests to it, with no egress filtering (no block of loopback / RFC1918 / link-local 169.254.0.…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82801] A vulnerability was detected in NASA earthdata-search 1.0.0. Affected by this vulnerability is the f…
A vulnerability was detected in NASA earthdata-search 1.0.0. Affected by this vulnerability is the function scaleImage of the file serverless/src/scaleImage/handler.js of the component scale Endpoint. Performing a manipulation results in server-side request forgery. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82630] A vulnerability was identified in PowerJob up to 5.1.2. Impacted is the function MuConnectionManager…
A vulnerability was identified in PowerJob up to 5.1.2. Impacted is the function MuConnectionManager.getOrCreateConnection of the file powerjob-server/powerjob-server-starter/src/main/java/tech/powerjob/server/web/controller/TestController.java of the component Transport Endpoint. The manipulation leads to server-side request forgery. The attack is possible to be carried out remotely. The exploit …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
30/08/2026
[CVE-2026-82638] jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthe…
jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply publicly resolvable hostnames mapping to private addresses to retrieve cloud metadata and internal service content.
M Alto vulnerabilidad
29/08/2026
[CVE-2026-16600] The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its AJ…
The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its AJAX actions and does not validate a user-supplied URL before fetching it server-side, allowing users with subscriber-level access and above to make the site retrieve arbitrary internal or external URLs and read the response, resulting in a full-read Server-Side Request Forgery.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-82289] Gitingest through 0.3.1 fails to properly validate hostnames in _validate_host, accepting any host w…
Gitingest through 0.3.1 fails to properly validate hostnames in _validate_host, accepting any host with a git., gitlab., or github. prefix regardless of known-hosts list membership. Attackers can submit URLs with attacker-controlled hostnames to trigger outbound connections to arbitrary hosts and disclose GitHub personal access tokens via HTTP basic credentials.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-82285] bisheng through 2.6.0-fix2 contains a server-side request forgery vulnerability in the POST /api/v1/…
bisheng through 2.6.0-fix2 contains a server-side request forgery vulnerability in the POST /api/v1/workflow/report/callback endpoint that lacks authentication and applies no URL scheme restrictions or host filtering. Unauthenticated attackers can supply arbitrary URLs to enumerate internal network services and cloud metadata endpoints, then retrieve captured responses from object storage using ca…
M Alto vulnerabilidad
28/08/2026
[CVE-2026-82268] Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in the document parsi…
Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in the document parsing path that treats caller-supplied paths as URLs without scheme restriction or host validation. Attackers can reach the unauthenticated Gradio interface to make the server issue HTTP requests to arbitrary internal addresses including metadata services and read retrieved content through parsed docum…