Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 43 min
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1009
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Hace 5 horas
[CVE-2026-107811] Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, ordinary authenti…
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, ordinary authenticated users can access /api/nodes and /api/nodes/:id, whose responses serialize the node token field. The same token is accepted as X-Node-Secret by AuthRequired and maps the request to initUser, allowing the user to impersonate a trusted node against a reachable cluster member. This cross-node auth…
M Alto vulnerabilidad Nuevo
Hace 6 horas
[CVE-2026-78795] An issue in Netcore B11 Enterprise-level full Gigabit 9-port shop wireless router v1.3.241114.024540…
An issue in Netcore B11 Enterprise-level full Gigabit 9-port shop wireless router v1.3.241114.024540 and before allows a remote attacker to obtain sensitive information
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107383] MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL …
MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.5, 3.3.4, 3.4.7, and 3.5.4, the GeoJSON Polygon and MultiPolygon binary encoders size a Buffer.allocUnsafe() allocation from each ring's numeric length before confirming that the ring is an array. A malformed non-array ring can therefore reserve bytes that the writing loop sk…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-93677] IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitiv…
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to exposure of sensitive information to an unauthorized actor.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106459] Backstage is an open framework for building developer portals. From 0.3.0 until 0.3.8, the @backstag…
Backstage is an open framework for building developer portals. From 0.3.0 until 0.3.8, the @backstage/plugin-scaffolder-backend-module-sentry package is affected by improper input validation in sentry scaffolder actions. An authenticated internal user who can execute the affected actions may cause the backend to contact unintended destinations and disclose Sentry integration credentials. Subsequen…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106342] Information leak in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to ob…
Information leak in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106334] Information leak in Payments in Google Chrome prior to 155.0.8059.39 allowed a remote attacker lever…
Information leak in Payments in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106256] Information leak in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote…
Information leak in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106220] Information leak in Passwords in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to o…
Information leak in Passwords in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105635] Plane is an open-source project management tool. Prior to 1.4.0, ProjectJoinEndpoint at GET /api/wor…
Plane is an open-source project management tool. Prior to 1.4.0, ProjectJoinEndpoint at GET /api/workspaces/{slug}/projects/{project_id}/join/{pk}/ uses permission_classes = [AllowAny] and returns the full ProjectMemberInvite record, including its email, token, and role, to unauthenticated callers. The corresponding POST endpoint checks only whether the submitted email matches project_invite.email…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105211] ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauth…
ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with OTP-Email and OTP-SMS enrolled can read both codes from server-action responses to gain MFA-authenticated sessions, including administrator takeover.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-47360] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod…
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module.   When SessionCookieRemove changes across internal redirects, the session cookie may still be passed to a backend server. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-96255] The Payments for Hubtel WordPress plugin before 1.0.2 does not prevent public access to a debug log …
The Payments for Hubtel WordPress plugin before 1.0.2 does not prevent public access to a debug log in which it records payment requests, including the store's payment gateway API credentials in plain text, allowing unauthenticated attackers to obtain those credentials.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102121] A form-rendering interface in the Advanced Forms component is reachable without authentication so th…
A form-rendering interface in the Advanced Forms component is reachable without authentication so that published forms can be displayed to anonymous visitors, but it returned more data than the form itself required. Anyone who knew the web address of a published form could potentially retrieve the form owner's Kiteworks account profile, including personal details, along with parts of the deploymen…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-47514] NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, w…
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause exposure of kernel stack contents including return addresses and pointers. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
28/09/2026
[CVE-2026-102267] PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT PyJWKClient is …
PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT PyJWKClient is affected because redirect destinations are not revalidated against the JWKS trust boundary. This occurs when a configured trusted JWKS endpoint returns an attacker-influenced redirect. As a result, PyJWKClient follows the redirect and consumes the redirected response as key material. Consequently, f…
M Alto vulnerabilidad
27/09/2026
Vulnerabilidad de control de acceso en AzuraCast anterior a 0.23.8 expone credenciales de administración
AzuraCast versiones anteriores a 0.23.8 contiene un fallo de control de acceso en el endpoint GET /api/station/{id}/vue/profile que permite a usuarios autenticados con permisos limitados de visualización extraer contraseñas en texto plano de Icecast/Shoutcast (admin, origen y retransmisión). Usuarios con acceso de solo lectura pueden invocar este endpoint y recibir credenciales frontend en respuestas JSON, comprometiendo la seguridad de infraestructuras de streaming de radio y podcasting frecuentes en medios latinoamericanos.
M Alto vulnerabilidad
27/09/2026
[CVE-2026-100723] vm2 before 3.12.2 does not apply its Buffer backing-store ownership invariant (byteOffset === 0 and …
vm2 before 3.12.2 does not apply its Buffer backing-store ownership invariant (byteOffset === 0 and buffer.byteLength === length) to Buffers returned from host builtin modules. When an application explicitly exposes Node's zlib module through NodeVM's builtin allowlist (require: { builtin: ['zlib'] }), zlib.deflateSync can return a Buffer backed by Node's shared small-buffer pool whose .buffer is …
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100708] Froxlor before 2.3.13 returns the ssl_key_file column — which stores the raw PEM TLS private-key con…
Froxlor before 2.3.13 returns the ssl_key_file column — which stores the raw PEM TLS private-key content — verbatim in the JSON responses of the Certificates.get and Certificates.listing API commands, because the results of the underlying domain_ssl_settings queries are passed through ApiCommand::response() without any field stripping or allowlist. A low-privileged authenticated customer API calle…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100703] Kyverno 1.16.0 through 1.19.0 registers the globalcontext.Lib CEL library in its policy environment …
Kyverno 1.16.0 through 1.19.0 registers the globalcontext.Lib CEL library in its policy environment without confining it to the policy's namespace, unlike the sibling libraries (resource.Lib, http.Lib, configMap loader) which are handed the policy namespace. A tenant who can create a namespaced policy (e.g. NamespacedValidatingPolicy, and likewise the namespaced mutating, deleting, generating, and…