Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-103475] yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting …
yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting allowedIPs to ['*'] in its default development configuration. Unauthenticated remote attackers can access the debug endpoint to read sensitive data including session cookies and database queries, or access the Gii endpoint to generate and write PHP files into the application directory.
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-100512] Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions.
Contributor PHP Object Injection in Nested Pages
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-62308] Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6,…
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6, Tugtainer allows an authenticated user to make the backend server send outbound HTTP requests to arbitrary user-supplied URLs through the notification test endpoint. The /settings/test_notification endpoint accepts a urls field and passes it directly to Apprise without restricting protocols, hostna…
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-55494] Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.4,…
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.4, Tugtainer Agent allows unauthenticated access to Docker management APIs when AGENT_SECRET is not configured. The Agent uses request signatures to protect its API routes. However, in agent/auth.py, the signature verification function returns successfully if Config.AGENT_SECRET is empty. This causes …
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-55176] Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.…
Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, two authentication helpers in /app/server.js — verifyContainerAuth() and authenticateWorkspaceHttp() — accept the global CONTAINER_SHARED_SECRET as a bearer token without verifying which workspace the caller belongs to. Because that secret is set identically on every container in the …
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-55181] Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.3,…
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.3, Tugtainer's OIDC authentication can still be initiated even when OIDC_ENABLED=false. The /auth/oidc/enabled endpoint correctly reports that OIDC is disabled. However, a direct request to /auth/oidc/login still starts the OIDC login flow, returns HTTP 302, sets an oidc_state cookie, and redirects th…
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-18782] Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i…
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Command Line Execution through SQL Injection. This issue affects Trex MES: through 2026-09-29.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-103395] LightLLM through 1.2.0 visual_only deployments expose an unauthenticated RPyC service with allow_pic…
LightLLM through 1.2.0 visual_only deployments expose an unauthenticated RPyC service with allow_pickle enabled that deserializes attacker-supplied arguments in the remote_infer_images method. Attackers can reach the visual RPyC port and pass objects with __reduce__ methods to execute arbitrary code with service account privileges.
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-82307] Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i…
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Dolusoft Software Technologies SOPLOG allows SQL Injection. This issue affects SOPLOG: before Soplog 2026.9.4.1.
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-97274] Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client) <= 7.1.2 versions.
Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client)
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-97248] Unauthenticated PHP Object Injection in Booking Activities <= 1.18.7.1 versions.
Unauthenticated PHP Object Injection in Booking Activities
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-96822] Unauthenticated SQL Injection in Books Gallery <= 4.8.3 versions.
Unauthenticated SQL Injection in Books Gallery
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-96350] Subscriber Privilege Escalation in Estatik <= 4.3.5 versions.
Subscriber Privilege Escalation in Estatik
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-96349] Unauthenticated Remote Code Execution (RCE) in SiteSkite <= 2.1.8 versions.
Unauthenticated Remote Code Execution (RCE) in SiteSkite
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-94389] Unauthenticated Remote Code Execution (RCE) in AcyMailing SMTP Newsletter <= 11.0.5 versions.
Unauthenticated Remote Code Execution (RCE) in AcyMailing SMTP Newsletter

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-89238] WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the …
WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-76504] A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager …
A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a spe…
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-87830] In the StAX streaming WS-SecurityPolicy validator, certain relative or unsupported XPath expressions…
In the StAX streaming WS-SecurityPolicy validator, certain relative or unsupported XPath expressions can be converted into paths that never match the actual XML element path. A remote SOAP peer may therefore send a required element without the expected signature or encryption. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-88920] An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote…
An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML sender-vouches assertion containing an attacker-controlled key. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
M Crítico vulnerabilidad
30/09/2026
Omisión de validación en Apache MINA SSHD permite eludir autenticación LDAP
Apache MINA SSHD versiones 1.2.0 a 2.19.0 y 3.0.0-M1 a 3.0.0-M5 contienen una falla en LdapPasswordAuthenticator que permite bypass de autenticación. Afecta servidores SSH en Java que integren LDAP para validación de credenciales, comprometiendo el acceso a sistemas críticos de infraestructura en organizaciones latinoamericanas.