Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1018
Esta semana
RSS
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106378] Privilege elevation in Sandbox in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote at…
Privilege elevation in Sandbox in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Alto vulnerabilidad
01/10/2026
[CVE-2026-66246] iControl is affected by a Broken Access Control vulnerability, which could allow an attacker to expl…
iControl is affected by a Broken Access Control vulnerability, which could allow an attacker to exploit missing authentication checks or insecure direct object references (IDOR), enabling privilege escalation and the unauthorized modification or deletion of sensitive application data.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102118] A local privilege escalation vulnerability in Kiteworks could have allowed an attacker with an exist…
A local privilege escalation vulnerability in Kiteworks could have allowed an attacker with an existing shell under a low-privileged service account to escalate to root privileges on the appliance.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-53605] Reachy Mini ISO for Wireless contains the necessary files to build a custom Raspberry Pi OS image fo…
Reachy Mini ISO for Wireless contains the necessary files to build a custom Raspberry Pi OS image for the Reachy Mini Wireless robot, using pi-gen. Prior to version 0.2.4, the Reachy Mini Wireless OS image shipped with an overly broad sudoers entry granting the pollen daemon user (uid 1000) passwordless sudo access to /usr/bin/systemctl with no subcommand or argument restriction. This is a local p…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-88808] A vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to …
A vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to downstream clusters using its own cluster-admin credentials instead of the ServiceAccount pinned to the deployment. It affects multi-tenancy environments where different tenants share the same downstream clusters, for example different privileged or untrusted teams inside the same organization. This…
M Alto vulnerabilidad
23/09/2026
Escalada de privilegios alta en ManageEngine OpManager y Firewall Analyzer v12.8.710
ZohoCorp ManageEngine OpManager y Firewall Analyzer versiones 12.8.710 y anteriores contienen una vulnerabilidad de escalada de privilegios (CVSS 8.1) que permite a usuarios autenticados con permisos bajos obtener acceso administrativo mediante la importación maliciosa de perfiles de reportes. Esta vulnerabilidad afecta directamente a empresas en LATAM que utilizan estas herramientas para monitoreo de infraestructura y gestión de firewall.
M Alto vulnerabilidad
21/09/2026
Vulnerabilidad alta en CRI-O permite eludir contexto de seguridad en Kubernetes
Una falla en la restauración de puntos de control de CRI-O permite a usuarios con capacidad de crear pods eludir el contexto de seguridad de Kubernetes, reteniendo credenciales, capacidades Linux y configuraciones seccomp del contenedor comprometido. Esto expone infraestructuras containerizadas en México y LATAM a ejecución con privilegios elevados, afectando principalmente plataformas que utilizan Kubernetes en producción con múltiples usuarios o entornos multi-tenant.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
15/09/2026
[CVE-2026-75092] A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided b…
A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository). During RHEL 9 to RHEL 10 upgrades, the actor runs: mysqld --validate-config --log-error-verbosity=2 directly as root in the Leapp actor context, bypassing the packaged MySQL systemd unit that normally starts the daemon as User=mysql. A process compromised as the mysql OS identi…
G Alto vulnerabilidad
09/09/2026
[CVE-2026-87506] Privilege elevation in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who h…
Privilege elevation in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69464] Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker t…
Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
18/08/2026
[CVE-2026-24183] NVIDIA Cumulus Linux contains a vulnerability in the user management component, where an unprivilege…
NVIDIA Cumulus Linux contains a vulnerability in the user management component, where an unprivileged user could use improper privilege management on the system. A successful exploit of this vulnerability might lead to escalation of privileges.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-17445] IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrict…
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of an attacker-supplied user profile name.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-18669] IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to a privilege escalation as the result of a remote code …
IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to a privilege escalation as the result of a remote code execution vulnerability in the activation engine component. An authenticated attacker can execute a maliciously planted script with root authority.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-17110] IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary comman…
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands and obtain sensitive information due to improper privilege management.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-59133] Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an a…
Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a network.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
10/08/2026
[CVE-2026-18949] A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the da…
A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Account (SA) token, to exploit overly broad permissions granted to the SA. This enables the attacker to escalate their privileges to cluster-administrator level, gain access to sensitive data like credentials and keys across the entire cluster, and disrupt multi-tenant isolation.
M Alto vulnerabilidad
10/08/2026
[CVE-2026-18982] A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit…
A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin roles in any Kubernetes namespace to escalate their privileges. Through the creation of training jobs, an attacker can impersonate service accounts, access the host filesystem, and potentially execute arbitrary code remotely. This issue arises from the aggregation of training job permissio…
M Alto vulnerabilidad
10/08/2026
[CVE-2026-18608] A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which de…
A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permissions, includes extensive privileges beyond what is necessary for its operation. These excessive permissions, such as the ability to execute commands within pods and manage cluster-wide roles, could be exploited. If the DSPO pod were compromised, an attacker could leverage these priv…
M Alto vulnerabilidad
07/08/2026
[CVE-2026-48098] NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a use…
NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 execute privileged system commands using `sudo` and `shell=True` directly inside application logic. In environments where passwordless sudo (`NOPASSWD`) is enabled, privileged commands may execute silently without explicit user confirmation. Version 2.0.0 fixe…
M Alto vulnerabilidad
03/08/2026
[CVE-2026-67609] Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain a…
Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain a privilege escalation vulnerability that allows attackers with access to the apache account to execute arbitrary commands as root by exploiting an insecure sudoers configuration in /etc/sudoers.d/telenia. The configuration grants the apache user NOPASSWD execution of /bin/nice, which can be leverage…