Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 4 min
Buscando: "Nx" — 15 resultados ✕ Limpiar búsqueda
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1012
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Hace 2 horas
[CVE-2026-107813] Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, the api/cluster r…
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, the api/cluster router exposes node and namespace mutation operations and cluster-wide Nginx reload or restart operations with AuthRequired but without RequireSecureSession. An authenticated OTP-enabled user possessing a stolen or persisted JWT can therefore perform node CRUD, read or replace node credentials, chang…
M Alto vulnerabilidad Nuevo
Hace 2 horas
[CVE-2026-107807] Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, Nginx UI accepts …
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, Nginx UI accepts the Node.Secret master credential through the node_secret query parameter in HTTP and WebSocket authentication paths instead of requiring the X-Node-Secret header. The credential can consequently appear in access logs, proxy logs, browser history, Referer headers, configuration URLs, and deployment …
M Alto vulnerabilidad Nuevo
Hace 2 horas
[CVE-2026-107808] Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, POST /api/login c…
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, POST /api/login checks EnabledOTP but does not require a WebAuthn assertion when EnabledPasskey is true and no TOTP secret is configured. A passkey-only account is therefore issued a session after password verification, despite Enabled2FA reporting that the account has a second factor. An attacker who obtains the pa…
M Alto vulnerabilidad Nuevo
Hace 2 horas
[CVE-2026-107809] Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, AuthRequired acce…
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, AuthRequired accepts a browser-managed token cookie as an API credential after the front end stores the JWT in that cookie. Because management endpoints do not universally require a CSRF token or perform Origin or Referer validation, a remote attacker can induce a logged-in administrator's browser to submit authenti…
M Alto vulnerabilidad Nuevo
Hace 2 horas
[CVE-2026-107810] Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, internal/backup/r…
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, internal/backup/restore.go extracts inner archives before applying the restore_nginx and restore_nginx_ui flags and permits symlinks targeting the live Nginx configuration path. An authenticated user who can create and restore backups can craft a valid backup that places a symlink in the staging tree and then writes…
M Alto vulnerabilidad Nuevo
Hace 2 horas
[CVE-2026-107811] Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, ordinary authenti…
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, ordinary authenticated users can access /api/nodes and /api/nodes/:id, whose responses serialize the node token field. The same token is accepted as X-Node-Secret by AuthRequired and maps the request to initUser, allowing the user to impersonate a trusted node against a reachable cluster member. This cross-node auth…
M Alto vulnerabilidad Nuevo
Hace 2 horas
[CVE-2026-107812] Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, the self-upgrade …
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, the self-upgrade mechanism validates a downloaded binary only with a same-origin digest obtained from the same upgrade mirror. A compromised mirror or network attacker able to alter both responses can supply a malicious executable and matching digest. An operator-triggered upgrade is required, and the application in…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad Nuevo
Hace 3 horas
[CVE-2026-107805] Nginx UI is a web user interface for the Nginx web server. From 2.5.0 until 2.6.0, the node-signatur…
Nginx UI is a web user interface for the Nginx web server. From 2.5.0 until 2.6.0, the node-signature authentication path performs temporary file staging of an attacker-controlled request body and synchronizes it before validating the body digest and cryptographic signature. An unauthenticated remote client that can reach the API and provide syntactically valid signature metadata can consume tempo…
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107333] Malcolm's nginx based reverse proxy contains a URL path normalization inconsistency between its Lua …
Malcolm's nginx based reverse proxy contains a URL path normalization inconsistency between its Lua based role-based access control (RBAC) authorization layer and nginx's own request routing logic. An authenticated user can craft a specially formatted request path to bypass role-based restrictions and reach administrative or role gated endpoints they should not have access to. This affects all res…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-76457] As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS eng…
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76457 are related to out-of-bounds read issues that are grouped under t…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-76458] As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS eng…
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76458 are related to improper handling of exceptional conditions issues…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-76459] As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS eng…
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76459 are related to out-of-bounds write issues that are grouped under …
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-76453] As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS eng…
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76453 are related to improper neutralization issues that are grouped un…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-76456] As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS eng…
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76456 are related to improper input validation of special elements used…
M Alto vulnerabilidad
Hace 4 días
Vulnerabilidad alta en controlador NXP GAU ADC permite desbordamiento de búfer
El controlador ADC (conversor analógico-digital) GAU de NXP contiene un defecto de validación en la gestión de tamaño de búfer que puede permitir desbordamientos de memoria. La vulnerabilidad afecta sistemas embebidos y dispositivos IoT que utilicen este controlador, siendo especialmente relevante en infraestructura industrial y de automatización en LATAM. Con CVSS 8.4, representa un riesgo alto para integridad y disponibilidad de sistemas altas.