Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ni" — 1486 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1054
Esta semana
RSS
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-93606] vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedde…
vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host API that returns a host-realm Promise, the bridge's rejection sanitizer (hostPromiseSanitizeReject / makeSanitizedPromiseCallback / normalizeHostPromiseCallbacks in lib/bridge.js) only wraps `then`/`catch` rejection slots that hold a function, and the sandbox-side `Symbol.species`/`…
M Crítico vulnerabilidad
18/09/2026
Vulnerabilidad crítica en Synology DiskStation Manager permite lectura/escritura de archivos arbitrarios
Una falla en la codificación de salida del componente SCGI en Synology DSM afecta versiones anteriores a 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 y 7.4-90075, permitiendo a atacantes remotos leer, modificar archivos arbitrarios y ejecutar ataques de negación de servicio. Empresas en LATAM que usan NAS Synology para almacenamiento centralizado están en riesgo inmediato de exposición de datos sensibles e interrupciones operativas.
M Crítico vulnerabilidad
18/09/2026
Vulnerabilidad crítica en Synology DiskStation Manager permite lectura/escritura de archivos arbitrarios
Se identificó una vulnerabilidad de entropía insuficiente en la lógica de autenticación de Synology DSM (versiones anteriores a 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 y 7.4-90075) que permite a atacantes remotos acceder, modificar archivos arbitrarios y ejecutar ataques de denegación de servicio sin credenciales válidas. Afecta directamente a servidores NAS en entornos corporativos, PyMES y centros de datos en LATAM que dependen de estos dispositivos para almacenamiento centralizado.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-67100] HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure fla…
HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject database commands to extract sensitive system details, as well as manipulate request values to gain unauthorized access to full personal profile data and PII across different organizations.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-84738] The AF Companion WordPress plugin before 2.2.0 does not validate the type of files uploaded through…
The AF Companion WordPress plugin before 2.2.0 does not validate the type of files uploaded through one of its import features, allowing users with a low-privileged store-management role to upload arbitrary files, including PHP ones, leading to Remote Code Execution.
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-54734] Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters in…
Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-supplied parameters into outbound request URLs without using HttpUtil to validate the resulting domain or path segment. A malicious actor who can supply bid-request parameters can cause the server to send HTTP requests to unintended destinations, potentially reaching internal network …
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-54670] WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatc…
WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/contribuicao/controller/control.php accepts attacker-controlled nomeClasse and metodo values without a complete controller and method allowlist, exempts sensitive ContribuicaoLogController operations from authentication, and constructs a controller include path without canonical dire…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-45140] Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unau…
Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary code on the server. The authoritative advisory does not identify the affected endpoint, component, input, or exploitation mechanism. This issue is fixed in version 2.0.1.
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-45143] Chamilo LMS is an open-source learning management system. From 2.0.0 through at least 2.1.0, Chamilo…
Chamilo LMS is an open-source learning management system. From 2.0.0 through at least 2.1.0, Chamilo LMS stores private Message.content without server-side sanitization and renders it as HTML in assets/vue/views/message/MessageShow.vue and public/main/template/default/message/view_message.html.twig. An authenticated low-privilege user, including a student, can directly address crafted message cont…
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-54627] SAIL is a cross-platform library for loading and saving images with support for animation, metadata,…
SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, psd_private_sail_pixel_format() in src/sail-codecs/psd/helpers.c resolves a one-channel PSD in Bitmap color mode to SAIL_PIXEL_FORMAT_BPP1_INDEXED without requiring the file depth to be one, so the pixel buffer uses one-bit rows while sail_codec_load_frame_v…
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-54752] NetBox Device Type Library is a collection of community-sourced device type definitions for import i…
NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The validation test harness can deserialize pull-request-controlled tracked pickle cache files through pickle.load in the read_pickle_data function in tests/pickle_operations.py. An unauthenticated contributor can change USE_LOCAL_KNOWN_SLUGS in tests/test_configuration.py and supply a c…
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-54626] SAIL is a cross-platform library for loading and saving images with support for animation, metadata,…
SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, the TGA_INDEXED_RLE path selected by image_type == 9 allocates an image buffer using the one-byte-per-pixel SAIL_PIXEL_FORMAT_BPP8_INDEXED format returned by tga_private_sail_pixel_format() in src/sail-codecs/tga/helpers.c, while sail_codec_load_frame_v8_tga…
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-54053] Many Notes is a Markdown note-taking web application designed for simplicity. Prior to 0.16.0, the Z…
Many Notes is a Markdown note-taking web application designed for simplicity. Prior to 0.16.0, the ZIP vault import implemented in app/Actions/ProcessImportedVault.php accepts archive filenames containing parent-directory traversal segments. An authenticated user can write arbitrary files outside the importing user's vault and into other users' vaults, including overwriting existing files. Disguis…
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-92956] vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a default `new VM()` sand…
vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a default `new VM()` sandbox when running on Node.js 26. WebAssembly.compileStreaming and WebAssembly.instantiateStreaming can produce a raw host-realm Promise that rejects with a host-realm error object; by controlling Symbol.species via Promise.prototype.finally, sandbox code receives that raw host error, walks from the h…
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-92957] vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when evaluating user-suppl…
vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when evaluating user-supplied negative (deny) entries in a NodeVM wildcard require policy. Although NodeVM strips the `node:` prefix during require() resolution, negative wildcard entries are matched by exact string comparison against the canonical builtin names, so a policy such as `new NodeVM({ require: { builtin: ['*', '-…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-92947] vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host m…
vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by Buffer.from, Buffer.concat, and related allocations. Sandboxed code can read and write to host-realm buffers by acquiring ArrayBuffers from small allocations, leading to sensitive data exposure and potential denial-of-service.
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-92941] vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing a…
vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() and replace process-wide certificate authorities. Attackers with access to allowed tls and url builtins can use URLSearchParams to create host-realm arrays and manipulate the TLS trust store, enabling subsequent host HTTPS clients to accept attacker-co…
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-92937] vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host Node.js pr…
vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host Node.js process. The fix for GHSA-m283-3h24-438v is incomplete: the bridge gate at lib/bridge.js:1624 identity-checks only the direct call target when deciding whether to rebuild/sanitise a rejected host Promise value. Registering the rejection handler through Function.prototype.call or .apply indirection (e.…
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-92938] vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to code running in NodeV…
vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to code running in NodeVM when that builtin is permitted, either explicitly or through builtin: ['*']. The module is wrapped with vm.readonly(), which prevents property assignment but leaves host-authority callables reachable; in addition, the resolver treats any request starting with 'node:' as a core-module request and t…
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-92934] vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that allows sandbox escape…
vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that allows sandbox escape when revisited host-wrapped AggregateError objects are caught within a single exception handler traversal. Attackers can exploit cycle detection bypass in handleException to access unsanitized host proxies embedded in the errors array, enabling full remote code execution and process information dis…