Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,696
Total alertas
3097
Críticas
10327
Altas
8
Ransomware
1751
Esta semana
RSS
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19679] An input validation vulnerability exists in Security Center's file upload handling, where insufficie…
An input validation vulnerability exists in Security Center's file upload handling, where insufficient sanitization of uploaded filenames could contribute to a downstream command injection issue.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19680] A SQL injection vulnerability exists in Security Center that could allow an attacker to access unaut…
A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's database.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19846] A vulnerability was identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function s…
A vulnerability was identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the argument url leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit is publicly available and might be used.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-12366] Zephyr's dynamic kernel-object disposal path unref_check() in kernel/userspace/userspace.c frees an …
Zephyr's dynamic kernel-object disposal path unref_check() in kernel/userspace/userspace.c frees an object's storage (k_free(dyn->data)) once its reference count reaches zero, after running a per-object-type cleanup. The cleanup switch handled only K_OBJ_MSGQ and K_OBJ_STACK; there was no K_OBJ_TIMER case. A dynamically-allocated, initialized, and armed k_timer keeps its embedded struct _timeout d…
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19629] A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Secu…
A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role and "manage user" permission on a single group to modify users belonging to other groups. This bypasses the intended access control restrictions and enables unauthorized cross-group user management.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19635] A local privilege escalation vulnerability exists in Security Center. An attacker with write access …
A local privilege escalation vulnerability exists in Security Center. An attacker with write access to a specific configuration file could achieve arbitrary code execution with elevated privileges, without requiring further user or victim interaction.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-12364] The user-space system-call verifier z_vrfy_z_log_msg_static_create() in subsys/logging/log_msg.c was…
The user-space system-call verifier z_vrfy_z_log_msg_static_create() in subsys/logging/log_msg.c was a pure pass-through: it forwarded the caller-supplied source, desc, package, and data arguments directly to the kernel-mode implementation z_impl_z_log_msg_static_create() without performing any of the mandatory K_SYSCALL_* checks. Because z_log_msg_static_create() is declared __syscall, under CONF…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
14/08/2026
[CVE-2026-46603] VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing …
VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-46439] compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 a…
compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and 4.0.3 have a Server-Side Template Injection (SSTI) vulnerability exists in the `trestle author jinja` command. The command recursively evaluates rendered templates, allowing an attacker to achieve arbitrary command execution with privileges of the running process by injecting malicious payloads i…
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19844] A vulnerability was found in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the func…
A vulnerability was found in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component ipv6.so. Performing a manipulation of the argument radvdinterfacename results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19845] A vulnerability was determined in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function s…
A vulnerability was determined in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function setStaticDhcpConfig of the file /cgi-bin/cstecgi.cgi of the component lan.so. Executing a manipulation of the argument Comment can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19628] A command injection vulnerability exists in Tenable Security Center. An authenticated administrator …
A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to achieve arbitrary command execution on the underlying operating system when specific backend operations are triggered.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-66271] Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File…
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-63700] Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Incorrect Default Permissio…
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Incorrect Default Permission vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-66270] Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File…
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
14/08/2026
[CVE-2026-53970] ZeroBrew version 0.3.1 and prior contains a missing integrity verification vulnerability in the Ruby…
ZeroBrew version 0.3.1 and prior contains a missing integrity verification vulnerability in the Ruby compatibility shim that allows network attackers to execute arbitrary code by substituting malicious content at formula resource or URL-based patch URLs without checksum validation. Attackers can intercept or replace downloads for secondary resource and patch paths in shim.rb, injecting attacker-co…
M Alto vulnerabilidad
14/08/2026
[CVE-2026-16772] In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to …
In Akaunting versions sync()` call without verifying whether the caller is authorized to manage roles. …
M Alto vulnerabilidad
14/08/2026
[CVE-2026-69101] Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vulnerability that allows authen…
Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vulnerability that allows authenticated attackers to perform server-side request forgery and out-of-band file exfiltration by supplying a crafted taskScript payload to the doEditWorkflow endpoint, which processes XML through an unhardened DocumentBuilderFactory with external entities and DTD loading enabled. Attackers can send a m…
M Alto vulnerabilidad
14/08/2026
[CVE-2026-73633] Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an applica…
Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to populate actions from a JSON request body, the plugin reads that body into memory without bounding how much it will accept, so a single request can exhaust the heap and deny service to other users. The plugin's configurable JSON input length limit does not bound this read. The …
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19768] Improper control of generation of code ('Code Injection') in the settings feature in Devolutions Pow…
Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings management permission to execute arbitrary PowerShell code via a crafted setting value that is not properly escaped when written to the settings configuration file.