Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Quest" — 282 resultados ✕ Limpiar búsqueda
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1810
Esta semana
RSS
M Crítico vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-76835] OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may sk…
OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the default reverse-proxy configuration. GetRequestURI in pkg/requests/util/util.go prefers that header over the real request URI whenever CanTrustForwardedHeaders returns true, and isAllowedPath in oauthproxy.go matches the s…
M Crítico vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-71933] Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslo…
Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vulnerability is caused by missing authorization checks. A remote attacker can trigger these vulnerabilities via crafted requests to modify configuration, restart services, save startup configuration, or clear logs.
M Crítico vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-76840] RustDesk's Windows clipboard redirection copies a peer-supplied length into a fixed-size caller buff…
RustDesk's Windows clipboard redirection copies a peer-supplied length into a fixed-size caller buffer without an upper bound check. When an OLE paste consumer such as explorer.exe calls IStream::Read with a buffer of cb bytes, CliprdrStream_Read in libs/clipboard/src/windows/wf_cliprdr.c requests that many bytes of a remote file through cliprdr_send_request_filecontents and then executes CopyMemo…
M Crítico vulnerabilidad Nuevo
Hace 11 horas
[CVE-2026-78169] A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the functio…
A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file /goform/aspRemoteApConfTempSend of the component HTTP Request Handler. Performing a manipulation of the argument Profile results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.
M Crítico vulnerabilidad
Hace 2 días
Vulnerabilidad crítica SSRF en plugin Mailgun para WordPress permite acceso no autorizado
El plugin Mailgun for WordPress versiones hasta 2.2.0 contiene una vulnerabilidad de Server-Side Request Forgery (SSRF) por validación insuficiente en la función add_list(). Atacantes no autenticados pueden explotar el path traversal mediante claves controladas en $_POST['addresses'] para acceder a recursos internos del servidor. Afecta directamente a sitios WordPress en México y LATAM que utilizan este plugin para gestión de correos transaccionales.
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-61539] Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and …
Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference passes attacker-influenced Llama3 tool-call output to eval() in xinference/model/llm/tool_parsers/llama3_tool_parser.py and xinference/model/llm/utils.py. Requests to /v1/chat/completions with a tools field flow through xinference/api/restful_api.py, xinference/model/llm/transfor…
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-77087] Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attack…
Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary commands via DNS rebinding. An attacker can craft a malicious webpage that, when visited by a developer running Paperclip locally, uses DNS rebinding to make authenticated API requests and execute commands through the process adapter.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-62941] Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an ins…
Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across projects, the project restriction check (`AllowInstanceCreation`) runs BEFORE the source instance's configuration is merged into the request. Dangerous configuration keys (including `security.privileged`, `raw.lxc`, `raw.apparmor`) from the source instance are merged AFTER the check pas…
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-77806] SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited i…
SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection via an X-Spip-Filtre HTTP request header that is mishandled by analyse_resultat_skel.
M Crítico vulnerabilidad
Hace 3 días
Vulnerabilidad crítica en proxy LLM de Headroom permite suplantación de usuarios
Headroom's LLM proxy contiene una vulnerabilidad de autenticación insuficiente (CVSS 9.1) en el encabezado x-headroom-user-id que permite a atacantes acceder y modificar datos de memoria de otros usuarios sin autorización. El fallo afecta rutas de chat completion y websocket en headroom/proxy/handlers/openai.py. Empresas que usan este proxy para gestionar modelos de lenguaje corren riesgo de exposición de datos sensibles y suplantación de identidad.
M Crítico vulnerabilidad
Hace 3 días
Vulnerabilidad crítica de autenticación en plugins de WordPress para WooCommerce (CVE-2026-77264)
El plugin 'Automation Web Platform – Notifications and OTP for WooCommerce' y el complemento 'Advanced Country Code' para WordPress presentan un bypass de autenticación en versiones hasta 4.8.6. La función handle_email_otp_return() expone el token de login secreto en respuestas públicas de solicitudes OTP, permitiendo acceso no autorizado sin validación de correo. Afecta directamente a tiendas en línea, plataformas de e-commerce y sitios con autenticación de dos factores basada en OTP en México y Latinoamérica.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-69851] Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevat…
Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-65801] Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to e…
Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-71485] Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies …
Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies the client-controlled protocol.ConnectRequest.headers map through OnClientConnecting in internal/client/handler.go, ConnectEvent.Headers, and SetEmulatedHeadersToContext. The requestHeaders path in internal/proxy/http.go, the requestMetadata path in internal/proxy/grpc.go, and the Consume path in in…
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-73256] Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated atta…
Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated attacker can exploit an HTTP/1.0 reverse-proxy deployment by sending a request with Transfer-Encoding: chunked and conflicting framing. The http_cb() function in src/http.c tests hm.proto.len with an impossible greater-than-eight condition even though mg_http_parse() requires an eight-byte protocol stri…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-73257] Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthentica…
Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthenticated attacker can send an HTTP request containing both Content-Length and Transfer-Encoding: chunked. The cl_count and te_count checks in the mg_http_parse() and http_cb() paths in src/http.c accept both headers and prioritize chunked encoding, while a Content-Length-preferring reverse proxy can use …
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-55642] dbx is a cross-platform database client for databases. Prior to 0.5.51, dbx-web auth_middleware in c…
dbx is a cross-platform database client for databases. Prior to 0.5.51, dbx-web auth_middleware in crates/dbx-web/src/auth.rs passes every protected request to the handler chain when password_hash is None. A fresh deployment reaches that state when DBX_PASSWORD is unset and no stored password exists, while crates/dbx-web/src/main.rs binds the service to 0.0.0.0 on port 4224 by default. An unauthen…
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-28164] Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Sit…
Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery. This issue affects Easy Elementor Addons: from n/a through 2.3.7.
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-75860] The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verifica…
The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on one of its actions, which runs on every request and is available to unauthenticated users, allowing them to update arbitrary WordPress options. This can be leveraged to enable user registration and set the default role to administrator, leading to privilege escalation and full site takeover.
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-76850] LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine…
LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdeploy/pytorch/disagg/conn/engine_conn.py reads peer-to-peer cache-free requests with recv_pyobj(), which deserializes the received bytes with pickle.loads(), and the isinstance check against DistServeCacheFreeRequest runs only after deserialization has already completed. The peer that supplie…