Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Suse" — 21 resultados ✕ Limpiar búsqueda
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1013
Esta semana
RSS
M Alto vulnerabilidad
02/10/2026
[CVE-2026-103097] An API key is hardcoded and retrievable from the application package. Since Android applications can…
An API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and misuse the key.
M Alto vulnerabilidad
02/10/2026
[CVE-2026-103096] API key is hardcoded and retrievable from the application package. Since Android applications can be…
API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and misuse the key.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-100292] In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, a hidden debug interface can be enabled through …
In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, a hidden debug interface can be enabled through an authenticated request, allowing additional commands to be sent to a backend service. Once active, this pathway can unintentionally expose system‑level functionality that could be misused if crafted inputs reach the underlying command handler.
M Alto vulnerabilidad
28/09/2026
[CVE-2026-88805] Incorrect credential cleaning on logout could be used by remote attackers to keep access credentials…
Incorrect credential cleaning on logout could be used by remote attackers to keep access credentials even after the account was logged out. Affected is SUSE Rancher 2.15 before 2.15.2.
M Alto vulnerabilidad
28/09/2026
[CVE-2026-93538] A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated clus…
A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated cluster registration, cluster labels supplied by the registering agent, including labels in the reserved management.cattle.io/ namespace such as the cluster display name label, were applied to the resulting upstream Cluster object. Because Fleet resolves GitRepo and Bundle targets from those cluster lab…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-63506] Tina is a headless content management system. Prior to @tinacms/auth 1.1.4 and next-tinacms-azure 15…
Tina is a headless content management system. Prior to @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1, isAuthorized accepts a request-controlled clientID and asks isUserAuthorized to validate the bearer token against that selected TinaCloud app instead of the self-hosted site's configured app. An attacker with any TinaCloud account can submit the attacker's own app ID and valid token to a victi…
M Alto vulnerabilidad
01/09/2026
Inyección de comandos OS alta en yast2-users (CVE-2026-59680)
Se identificó una vulnerabilidad de inyección de comandos en yast2-users que afecta la gestión de usuarios en sistemas Linux basados en SUSE. La función get_password_term() no valida campos numéricos (shadowLastChange, shadowExpire), permitiendo ejecución arbitraria de comandos del sistema operativo con privilegios elevados. Afecta directamente servidores administrados en México y LATAM que utilicen esta herramienta.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
22/07/2026
[CVE-2026-65603] The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a privilege escalation flaw in …
The Grav Login plugin (grav-plugin-login) versions
F Alto vulnerabilidad
14/07/2026
[CVE-2026-49477] Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the …
Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve contains a regular expression vulnerable to catastrophic backtracking when processing an attribute selector with an unterminated quoted value in soupsieve/css_parser.py, allowing an attacker who can supply untrusted CSS selector strings to soupsieve.compile() or Beau…
F Alto vulnerabilidad
14/07/2026
[CVE-2026-49476] Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the …
Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unbounded memory when compiling large comma-separated selector lists, allowing an attacker who can supply a crafted selector string to soupsieve.compile() or Beautiful Soup .select() / .select_one() to allocate hundreds of megabytes of heap memory from a re…
S Alto vulnerabilidad
06/07/2026
[CVE-2026-44937] Potential forgery of webhook requests when using a unauthenticated webhook in SUSE Rancher Fleet 0.1…
Potential forgery of webhook requests when using a unauthenticated webhook in SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.5 could be used by remote attackers to cause a denial of service or a downgrade attack on other repositories on the system.
O Alto vulnerabilidad
02/07/2026
[CVE-2026-44941] A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 c…
A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a malicious repository to inject or overwrite files in the target system as root.
S Alto vulnerabilidad
30/06/2026
[CVE-2026-44946] A SAML authentication replay vulnerability in Rancher's Assertion Consumer Service (ACS) handler di…
A SAML authentication replay vulnerability in Rancher's Assertion Consumer Service (ACS) handler did not enforce one-time use of SAML assertion, potentially allowing person in the middle attacks against Rancher, affecting Rancher 2.14.0 before 2.14.3,
S Alto vulnerabilidad
30/06/2026
[CVE-2026-41053] Incorrect authentication caching in the team member ship expansion of the Rancher Github authenticat…
Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused it granting principal access to any logged in user, in 2.13 before 2.13.6 and 2.14 before 2.14.2.
S Alto vulnerabilidad
29/06/2026
[CVE-2026-41052] Improper privilege handling could be used by users with Project Owner role to escalate privileges, i…
Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher versions 2.14 before 2.14.2, 2.13 before 2.13.6, and 2.12 before 2.12.10.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
O Alto vulnerabilidad
29/06/2026
[CVE-2026-25707] A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10…
A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service or privilege escalation.
L Alto vulnerabilidad
25/06/2026
[CVE-2026-53159] In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: fix DMA address …
In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: fix DMA address corruption due to find_vma misuse fastrpc_get_args() uses find_vma() to look up the VMA for a user-provided pointer and compute a DMA address offset. When the address falls in a gap before the returned VMA, (ptr & PAGE_MASK) - vma->vm_start underflows, corrupting the DMA address sent to the DSP. R…
C Alto vulnerabilidad
23/06/2026
[CVE-2026-45135] Caddy is an extensible server platform that uses TLS by default. From 2.7.0 until 2.11.3, the FastCG…
Caddy is an extensible server platform that uses TLS by default. From 2.7.0 until 2.11.3, the FastCGI transport's splitPos() in modules/caddyhttp/reverseproxy/fastcgi/fastcgi.go misuses golang.org/x/text/search with search.IgnoreCase when the request path contains a non-ASCII byte. Two distinct flaws in that fallback let an attacker mislead Caddy's FastCGI splitting into treating a non-.php (or ot…
M Alto vulnerabilidad
16/06/2026
[CVE-2025-71261] An attacker with network-level access between the SUSE Virtualization and Rancher Manager in SUSE H…
An attacker with network-level access between the SUSE Virtualization and Rancher Manager in SUSE Harvester before 1.8.0 could interfere with the TLS handshake and abuse it to bypass TLS as a security control.
M Alto vulnerabilidad
10/06/2026
[CVE-2026-45062] FrankenPHP is a modern application server for PHP. From version 1.11.2 to before version 1.12.3, the…
FrankenPHP is a modern application server for PHP. From version 1.11.2 to before version 1.12.3, the splitPos() function in cgi.go misuses golang.org/x/text/search with search.IgnoreCase when the request path contains a non-ASCII byte. Two distinct flaws in that fallback let an attacker mislead FrankenPHP into treating a non-.php file as a .php script. In any deployment where the attacker can plac…