Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 5 horas
Buscando: "X" — 7734 resultados ✕ Limpiar búsqueda
13,735
Total alertas
3106
Críticas
10357
Altas
8
Ransomware
1055
Esta semana
RSS
M Alto vulnerabilidad
12/08/2026
[CVE-2026-18683] IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to privilege escalation via Navigator for i. An authentic…
IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to privilege escalation via Navigator for i. An authenticated user could elevate privileges to a root user to execute commands.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-18098] IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive informa…
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and compromise system integrity due to an XML injection flaw.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-73325] Fujitsu Research's OneCompression library 1.2.0 contains an unsafe deserialization vulnerability tha…
Fujitsu Research's OneCompression library 1.2.0 contains an unsafe deserialization vulnerability that allows attackers to execute arbitrary code by supplying a crafted model.pt checkpoint file, as QuantizedModelLoader.load_quantized_model_pt() unconditionally calls torch.load with weights_only=False, invoking Python's pickle machinery during deserialization. Attackers can embed malicious __reduce_…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-73292] Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/pas…
Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accepts a cross-site request using the authenticated user's semaphore session cookie without CSRF protection or current-password confirmation, allowing an unauthenticated attacker to change an administrator's or another user's password after user interaction. This issue is fixed in ve…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-65941] In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network a…
In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-67260] Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task…
Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's `next_kwargs` without an allow-list, so a Dag author — who controls that value through the task execution API — can cause an arbitrary module import and object instantiation inside the scheduler process, or terminate the sche…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-73291] Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to v…
Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr's ImageProxy in server/lib/imageproxy.ts uses the upstream ETag and Content-Type response headers to build a cache filename for the unauthenticated GET /avatarproxy/:jellyfinUserId route, allowing a malicious or compromised Jellyfin or Emby server, or a man-in-the-middle attacker…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
12/08/2026
[CVE-2026-73286] RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_cond…
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds attacker-controlled request headers from HeaderMap into server-derived userid, username, principaltype, groups, versionid, signatureversion, jwt:, and ldap: condition keys, allowing authenticated callers to satisfy identity-based policy conditions. This issue is fixed in version 1…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-73284] RustFS is a distributed object storage system built in Rust. RustFS AddServiceAccount in rustfs/src/…
RustFS is a distributed object storage system built in Rust. RustFS AddServiceAccount in rustfs/src/admin/handlers/service_account.rs accepts an attacker-controlled target_user after only checking CreateServiceAccountAdminAction, passes it to new_service_account, and prepare_service_account_auth sets is_owner for the resulting root-parent service account. This issue is fixed in version 1.0.0-beta.…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-73285] RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.64 until 1.0.0-rc.1, R…
RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.64 until 1.0.0-rc.1, RustFS external OPA authorization enabled by RUSTFS_POLICY_PLUGIN_URL in crates/iam/src/sys.rs sets PreparedIamAuth.needs_existing_object_tag incorrectly for PreparedIamMode::Opa, causing maybe_merge_object_tag_conditions to omit s3:ExistingObjectTag/* values and allowing authenticated users to bypas…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-14478] A maliciously created executable, when executed on the victim's machine, may allow a local low-privi…
A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC messages into named pipes, modify pipe permissions or ownership, and potentially impact confidentiality, integrity, and availability.
M Alto vulnerabilidad
12/08/2026
[CVE-2025-59319] CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the intende…
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the intended boot partition and selects the first partition index matching a hardcoded type value. A crafted Linux partition could be inserted ahead of this intended target, allowing for code execution in the context of high privilege.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-53996] NetBSD's hdaudio(4) driver in sys/dev/hdaudio/hdaudio.c contains a missing access control vulnerabil…
NetBSD's hdaudio(4) driver in sys/dev/hdaudio/hdaudio.c contains a missing access control vulnerability that allows unprivileged local attackers to invoke the HDAUDIO_FGRP_SETCONFIG ioctl without elevated permissions by exploiting the absence of an access check on /dev/hdaudioN device nodes. Attackers can repeatedly issue HDAUDIO_FGRP_SETCONFIG from one thread while keeping DMA and IRQs live from …
M Alto vulnerabilidad
12/08/2026
[CVE-2026-57858] Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in …
Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owners to inject arbitrary JavaScript by supplying a malicious analytics tracking ID without sanitization. Attackers can close the inline script string literal with a crafted payload that executes in the browser of every visitor to …
M Alto vulnerabilidad
12/08/2026
Desbordamiento de búfer alta en Fortinet FortiClient Windows permite ejecución remota de código
Una vulnerabilidad de desbordamiento de búfer en Fortinet FortiClient Windows (versiones 7.2.0-7.2.11 y 7.4.0-7.4.3) permite a atacantes no autenticados ejecutar código arbitrario manipulando respuestas DNS. El ataque requiere posición en la red para alterar tráfico DNS, afectando principalmente a empresas en LATAM con VPN corporativos que confían en FortiClient para acceso remoto seguro.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
12/08/2026
Vulnerabilidad alta de ejecución remota de código en repositorio archivado de Cloudflare
Se ha identificado una vulnerabilidad de ejecución remota de código (RCE) en un repositorio archivado de Cloudflare, explotable a través de configuraciones específicas de GitHub Actions. La vulnerabilidad permite comprometer secretos de flujo de trabajo altas como CLOUDFLARE_API_TOKEN y GITHUB_TOKEN, exponiendo credenciales de acceso a infraestructura en la nube. Empresas en LATAM que utilicen este repositorio o mantengan integraciones con GitHub Actions deben verificar inmediatamente su exposición.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-19566] Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via un…
Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via unbounded IPv6 prefix lengths. The _encode method accepts any prefix length matching `(0|[1-9][0-9]*)` and passes it to _width2bits(), which builds the mask as `'1' x ($width + 8)`, one character per bit. The _inc() method then unpacks the packed mask into a Perl array of one scalar per byte, so the …
M Alto vulnerabilidad
12/08/2026
Vulnerabilidad de negación de servicio en PLCnext Engineer (CVE-2025-41770)
Se ha identificado una vulnerabilidad de negación de servicio sin autenticación en la interfaz de comunicación PLCnext Engineer que permite a atacantes remotos interrumpir el acceso a través de la aplicación cliente. La explotación exitosa bloquea la comunicación hasta que el servicio PLCnext se reinicia manualmente, afectando operaciones altas en plantas industriales y sistemas de automatización en LATAM.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-18789] The Ezoic WordPress plugin before 2.23.1 does not properly restrict access to some of its content ex…
The Ezoic WordPress plugin before 2.23.1 does not properly restrict access to some of its content export functionality, allowing unauthenticated attackers to trigger a server-side export of the site's database, including user password hashes and password reset tokens, as well as to persistently change some of its settings.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-18474] The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before u…
The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when a non-default search field type is configured.