Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ni" — 1486 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1055
Esta semana
RSS
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-65113] NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause us…
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of hard-coded credentials. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, denial of service, and information disclosure.
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-12718] Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i…
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Karel Electronic Industry and Trade Inc. KarelIPS allows Blind SQL Injection. This issue affects KarelIPS: through 22092026. NOTE: The vendor was contacted and it was learned that the product is not supported.
M Crítico vulnerabilidad
22/09/2026
Vulnerabilidad crítica en VeloCloud Orchestrator (VCO) on-prem permite acceso remoto no autorizado
VeloCloud Orchestrator (VCO) on-prem contiene una vulnerabilidad crítica (CVSS 10.0) que permite a atacantes remotos acceder a funcionalidades internas privilegiadas y comprometer la integridad del orquestador. La explotación exitosa impacta confidencialidad, integridad y disponibilidad de datos gestionados. Versiones hosted y dedicadas fueron afectadas, con implicaciones directas para proveedores de conectividad SD-WAN en México y LATAM que dependen de VCO para operaciones críticas.
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-87080] Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name containing …
Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name containing a character it never encoded in decode_punycode. The pure-Perl decoder reads one digit at a time with four-argument substr and tests the result with defined to detect the end of the input. substr on an exhausted string returns the empty string rather than undef, so decoding continues past the end. …
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-19658] The Give Tributes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, …
The Give Tributes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.3.1 via deserialization of untrusted input . This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is i…
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-13355] The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to Administrator in vers…
The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 3.11.0. This is due to a chained flaw: the populate_via_query_string() function in the mb-frontend-submission component unconditionally overrides the form's target object_id from the GET parameter 'rwmb_frontend_field_object_id' without any authorization check, and Form::p…
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-94493] A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unkno…
A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unknown processing of the file /index.html of the component WebSocket Service. The manipulation results in missing authentication. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
21/09/2026
[CVE-2026-79916] MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.5-lts, authenticated workspace me…
MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.5-lts, authenticated workspace members can inject control characters into AWS Bedrock access_key_id and secret_access_key fields that _update_aws_credentials writes to /root/.aws/credentials without safe parsing. An attacker can append a new AWS profile containing credential_process, then select that profile during a later model-va…
M Crítico vulnerabilidad
21/09/2026
[CVE-2026-79920] Ajenti is a Linux & BSD modular server admin panel. Prior to version 2.2.16, any authenticated user …
Ajenti is a Linux & BSD modular server admin panel. Prior to version 2.2.16, any authenticated user can call /api/core/tasks/start to enqueue InstallPlugin, UnInstallPlugin, or UpgradeAll from plugins/plugins/tasks.py without plugin-management authorization. InstallPlugin and UnInstallPlugin construct a pip package specification from unvalidated name and version fields, and the task worker invokes…
M Crítico vulnerabilidad
21/09/2026
Vulnerabilidad crítica de desbordamiento de búfer en Netcore NBR200V2 1.3.241127.071246
Se ha identificado una vulnerabilidad crítica (CVSS 9.9) en el enrutador Netcore NBR200V2 versión 1.3.241127.071246. La falla existe en la función vlan_load_form_uci del archivo /usr/bin/routerd, permitiendo un desbordamiento de búfer mediante manipulación del parámetro wan_num. El ataque es remoto, el exploit está públicamente disponible y el fabricante fue notificado previamente. Esta vulnerabilidad afecta directamente a infraestructuras de conectividad en empresas mexicanas y latinoamericanas que utilizan este dispositivo como gateway de red.
M Crítico vulnerabilidad
21/09/2026
Vulnerabilidad crítica de desbordamiento de búfer en Netcore NBR200V2 (CVE-2026-94100)
Se identificó una debilidad crítica (CVSS 9.9) en el enrutador Netcore NBR200V2 versión 1.3.241127.071246 que afecta la función wan_config_set_vlan del componente de reconfiguración VLAN WAN. Un atacante remoto puede manipular el parámetro vlan_wanX.ports para provocar un desbordamiento de búfer y potencialmente ejecutar código arbitrario. El exploit está disponible públicamente, aumentando significativamente el riesgo para dispositivos expuestos en redes corporativas e ISPs de la región.
M Crítico vulnerabilidad
21/09/2026
[CVE-2026-94098] A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This vulnerability affects unk…
A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This vulnerability affects unknown code of the file /www/cgi-bin/upgrade of the component Firmware Upgrade CGI Endpoint. Such manipulation of the argument QUERY_STRING leads to command injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this di…
M Crítico vulnerabilidad
21/09/2026
[CVE-2026-94099] A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. This issue affects some u…
A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. This issue affects some unknown processing of the file restore.cgi of the component Backup Restore. Performing a manipulation of the argument QUERY_STRING results in command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was c…
M Crítico vulnerabilidad
21/09/2026
[CVE-2026-94095] A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vulnerability…
A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vulnerability is an unknown functionality of the file /usr/bin/network_tools of the component Traceroute Diagnostic Feature. The manipulation of the argument url leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacte…
M Crítico vulnerabilidad
21/09/2026
[CVE-2026-94096] A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by this issue is some unkn…
A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by this issue is some unknown functionality of the file /usr/bin/network_tools of the component LAN IP Configuration Handler. The manipulation of the argument ipv4 results in command injection. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this d…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
21/09/2026
[CVE-2026-94097] A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part o…
A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file /www/cgi-bin/network_tools of the component CGI Diagnostic Endpoint. This manipulation of the argument param/key/val causes command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about t…
M Crítico vulnerabilidad
20/09/2026
[CVE-2026-94089] A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of…
A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authentication Handler. Executing a manipulation of the argument id/password can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
M Crítico vulnerabilidad
20/09/2026
[CVE-2026-90817] An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing a…
An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could potentially exploit it by manipulating HTTP requests to access an unintended controller route from a public survey context and by supplying a crafted file-path/stream parameter during import handling. If successfully exploited, this co…
M Crítico vulnerabilidad
20/09/2026
Vulnerabilidad crítica de desbordamiento de búfer en Comfast CF-N1-S 2.6.0.1
Se ha identificado una vulnerabilidad crítica (CVSS 10.0) en los routers Comfast CF-N1-S versión 2.6.0.1 que afecta la interfaz web de gestión. Un desbordamiento de búfer en la función get_css_path_from_uri del archivo /cgi-bin/mbox-config permite a atacantes remotos ejecutar código arbitrario sin autenticación. La vulnerabilidad ha sido divulgada públicamente y explotada activamente.
M Crítico vulnerabilidad
20/09/2026
[CVE-2026-93958] A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function syst…
A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used.