Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 6 horas
13,736
Total alertas
3106
Críticas
10358
Altas
8
Ransomware
1053
Esta semana
RSS
M Crítico vulnerabilidad
03/07/2026
[CVE-2026-58422] Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
M Crítico vulnerabilidad
03/07/2026
[CVE-2026-58426] Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross…
Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write
M Crítico vulnerabilidad
03/07/2026
[CVE-2026-58289] Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) all…
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
03/07/2026
[CVE-2026-27780] Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive…
Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowing oversized input to bypass branch-protection checks.
M Crítico vulnerabilidad
03/07/2026
[CVE-2026-26232] Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single…
Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behavior during token exchange.
M Crítico vulnerabilidad
03/07/2026
[CVE-2026-26247] Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during a…
Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.
M Crítico vulnerabilidad
03/07/2026
[CVE-2026-26292] Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror op…
Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration transport protections for those LFS requests.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
03/07/2026
[CVE-2026-22874] Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration a…
Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.
M Crítico vulnerabilidad
03/07/2026
[CVE-2026-25718] Gitea versions before 1.25.5 mishandle path resolution during template repository generation, allowi…
Gitea versions before 1.25.5 mishandle path resolution during template repository generation, allowing template processing to read or write through symlinked or otherwise non-regular paths.
M Crítico vulnerabilidad
03/07/2026
[CVE-2026-20706] Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope c…
Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web archive download endpoint.
M Crítico vulnerabilidad
03/07/2026
[CVE-2026-20896] Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by defaul…
Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.
M Crítico vulnerabilidad
03/07/2026
[CVE-2026-22547] Gitea versions before 1.25.5 lack validation constraints for repository creation fields, including l…
Gitea versions before 1.25.5 lack validation constraints for repository creation fields, including length-limited template fields and trust model or object format values.
K Crítico vulnerabilidad
03/07/2026
[CVE-2026-12481] A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improp…
A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deserialization in the `Lambda` layer. Specifically, the `_raise_for_lambda_deserialization()` function fails to enforce the safe-mode guard when `safe_mode` is set to `None`, which is the default value when `from_config()` is called outside of a `SafeModeScope` context. This logic er…
M Crítico vulnerabilidad
03/07/2026
[CVE-2026-56015] Net::IP::LPM versions through 1.10 for Perl allow a heap out-of-bounds read via an unbounded prefix …
Net::IP::LPM versions through 1.10 for Perl allow a heap out-of-bounds read via an unbounded prefix length. add() passes the prefix string to the trie builder addPrefixToTrie() without checking it against the address width. addPrefixToTrie() then walks the prefix buffer by prefix_length bits, reading prefix[byte] for byte up to prefix_len/8, where prefix is the 4-byte (IPv4) or 16-byte (IPv6) pa…
M Crítico vulnerabilidad
03/07/2026
[CVE-2026-4321] Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i…
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Raera - Ankara Web Design and Digital Advertising Agency Destekz allows SQL Injection. This issue affects Destekz: through 02062026. NOTE: The vendor was contacted and it was learned that the product is not supported.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
03/07/2026
[CVE-2026-14544] A flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnerability, an incomplet…
A flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnerability, an incomplete fix for CVE-2026-8631, may allow a remote attacker to escalate privileges or achieve arbitrary code execution. This can occur through an integer overflow in the hpcups processing path when handling specially crafted print data.
A Crítico vulnerabilidad
03/07/2026
[CVE-2026-47898] Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net…
Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library). This issue affects Apache Lucene.Net.Analysis.Common: from 4.8.0-beta00005 before 4.8.0-beta00018. Users are recommended to upgrade to version 4.8.0-beta00018, which fixes the issue.
H Crítico vulnerabilidad
03/07/2026
[CVE-2026-8926] When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL wi…
When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user.
H Crítico vulnerabilidad
03/07/2026
[CVE-2026-8927] When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configur…
When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`.
H Crítico vulnerabilidad
03/07/2026
[CVE-2026-9079] libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not …
libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.