Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1018
Esta semana
RSS
M Alto vulnerabilidad
Hace 1 día
Vulnerabilidad alta en hMailServer 6.0.0-6.3.5: fallo en validación DANE/DNSSEC en SMTP saliente
hMailServer versiones 6.0.0 a 6.3.5 contienen una vulnerabilidad que permite eludir la validación DANE (RFC 7672) en entregas SMTP salientes. El servidor no valida correctamente respuestas DNSSEC incompletas, malformadas o sin pruebas NSEC/NSEC3, permitiendo entregas de correo a destinos no autenticados. Afecta principalmente a proveedores de correo y servidores de mensajería en LATAM que dependen de DNSSEC para seguridad de entrega.
M Alto vulnerabilidad
24/09/2026
[CVE-2026-61788] DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Prior to ve…
DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Prior to version 0.22.6, setting `readonly = true` on the `execute_sql` tool does not make the connection read-only. The connectors are written to set PostgreSQL `default_transaction_read_only=on` (and open SQLite in `readOnly` mode), but that code is gated on a config value that is never populated, so it neve…
M Alto vulnerabilidad
21/09/2026
[CVE-2026-77560] Tinyauth is an authentication and authorization server. Prior to 5.1.2, Tinyauth compares forwarded …
Tinyauth is an authentication and authorization server. Prior to 5.1.2, Tinyauth compares forwarded hostnames case-sensitively while reverse proxies route equivalent hostnames case-insensitively, allowing an authenticated low-privilege user to bypass per-app access controls with a differently cased hostname. The lookup in internal/service/access_controls_service.go through lookupStaticACLs and Get…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-61595] djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered pe…
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, `djust.tenants` isolation was enforced only on the HTTP path. The current tenant was stored in `threading.local()` and set exclusively by the HTTP-only `TenantMiddleware`, so on the live (WebSocket/SSE) path `get_current_tenant()` was always `None` during mount and…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-81379] Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypas…
Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85649] (Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fail-open password validation vu…
(Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fail-open password validation vulnerability in the Alpha user and root user password loops of Shell/debian-minbase-install.sh. The installer invokes mkpasswd to generate yescrypt password hashes but does not check the command's return value and unconditionally accepts the result. If mkpasswd fails to generate a yescrypt hash, for …
M Alto vulnerabilidad
02/09/2026
[CVE-2026-18329] Description NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a js_access …
Description NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a js_access handler performs asynchronous request body processing and an exception is thrown during asynchronous access-control evaluation before an explicit access denial is returned. An unauthenticated attacker can exploit this vulnerability by sending a crafted HTTP request that triggers an error condition i…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
13/08/2026
[CVE-2026-70452] rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attacker…
rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent hosts deny rules by inducing DNS resolution failures during hostname-based access control evaluation. When a DNS lookup for a hostname-based deny rule fails, the daemon skips the rule rather than defaulting to a deny decision, enabling attackers who can trigger DNS failures to bypass…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-69306] Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypas…
Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-44094] An unauthenticated remote attacker can enforce the system to fall back to a firmware partition with …
An unauthenticated remote attacker can enforce the system to fall back to a firmware partition with an insecure configuration including default credentials. This could allow the attacker to gain SSH access to the system as an unprivileged user "user-app". Charging could be interrupted.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-50528] Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a …
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
T Alto vulnerabilidad
23/06/2026
[CVE-2026-54762] Traefik is an HTTP reverse proxy and load balancer. From 3.7.0-ea.1 until 3.7.5, there is a medium s…
Traefik is an HTTP reverse proxy and load balancer. From 3.7.0-ea.1 until 3.7.5, there is a medium severity vulnerability in Traefik's Kubernetes Ingress NGINX provider that causes affected routes to fail open. When an Ingress explicitly enables BasicAuth or DigestAuth through the supported nginx.ingress.kubernetes.io/auth-type and auth-secret annotations, but the referenced auth Secret cannot be …