Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-89238] WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the …
WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-76504] A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager …
A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a spe…
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-87830] In the StAX streaming WS-SecurityPolicy validator, certain relative or unsupported XPath expressions…
In the StAX streaming WS-SecurityPolicy validator, certain relative or unsupported XPath expressions can be converted into paths that never match the actual XML element path. A remote SOAP peer may therefore send a required element without the expected signature or encryption. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-88920] An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote…
An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML sender-vouches assertion containing an attacker-controlled key. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
M Crítico vulnerabilidad
30/09/2026
Omisión de validación en Apache MINA SSHD permite eludir autenticación LDAP
Apache MINA SSHD versiones 1.2.0 a 2.19.0 y 3.0.0-M1 a 3.0.0-M5 contienen una falla en LdapPasswordAuthenticator que permite bypass de autenticación. Afecta servidores SSH en Java que integren LDAP para validación de credenciales, comprometiendo el acceso a sistemas críticos de infraestructura en organizaciones latinoamericanas.
M Crítico vulnerabilidad
30/09/2026
Bypass de autenticación por inyección LDAP en Apache MINA SSHD afecta múltiples versiones
Apache MINA SSHD, biblioteca Java para SSH, contiene una vulnerabilidad crítica (CVSS 9.1) en su componente opcional sshd-ldap que permite eludir autenticación mediante inyección LDAP. Las versiones afectadas incluyen 1.2.0 a 2.19.0 y 3.0.0-M1 a 3.0.0-M5. Empresas en LATAM que integren LDAP para autenticación SSH en servidores están expuestas a acceso no autorizado.
M Crítico vulnerabilidad
30/09/2026
Omisión de autenticación en Apache MINA SSHD 2.0.0 a 3.0.0-M5 (CVE-2026-77185)
Apache MINA SSHD, librería Java para implementar servidores SSH, contiene una vulnerabilidad crítica (CVSS 9.1) que permite eludir la autenticación en configuraciones específicas de autenticación asincrónica. Afecta principalmente a servidores SSH personalizados en entornos de infraestructura crítica, plataformas de acceso remoto y soluciones de integración en LATAM. La explotación podría comprometer la integridad de sistemas de gestión de infraestructura, bases de datos y servidores de aplicaciones.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
30/09/2026
Vulnerabilidad crítica de deserialización insegura en EasyFlow .NET de Digiwin (CVE-2026-102455)
EasyFlow .NET contiene una vulnerabilidad de deserialización insegura que permite a atacantes no autenticados ejecutar código arbitrario en servidores. El riesgo es crítico (CVSS 9.8) para empresas manufactureras y de logística en LATAM que usan esta plataforma de automatización de flujos. Los atacantes pueden comprometer completamente infraestructuras empresariales sin requerir credenciales.
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-102458] Vulnerabilidad crítica de autenticación ausente en EasyFlow .NET de Digiwin
EasyFlow .NET contiene una vulnerabilidad de autenticación ausente (CVSS 9.8) que permite a atacantes remotos no autenticados obtener contraseñas en texto plano de otros usuarios a través de una API específica. Esta falla afecta directamente a empresas en México y Latinoamérica que utilizan esta plataforma para gestión de flujos de trabajo, exponiendo credenciales de usuarios y datos sensibles sin requerir validación de identidad.
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-97196] Improper Validation of Unsafe Equivalence in Input vulnerability in Liquid Web / StellarWP GiveWP al…
Improper Validation of Unsafe Equivalence in Input vulnerability in Liquid Web / StellarWP GiveWP allows Authentication Bypass. This issue affects GiveWP: from n/a through 4.16.9.
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-75873] The Zella Theme WordPress theme before 2.6.3 does not perform any capability or nonce check on one o…
The Zella Theme WordPress theme before 2.6.3 does not perform any capability or nonce check on one of its font upload actions, which is available to unauthenticated users, allowing them to upload arbitrary files, including PHP ones, and achieve remote code execution.
? Crítico alerta
30/09/2026
CISA Adds One Known Exploited Vulnerability to Catalog  
CISA emite alerta de seguridad: CISA Adds One Known Exploited Vulnerability to Catalog  . CVEs relacionados: CVE-2026-76504.
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-103110] Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation that …
Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation that allows a remote attacker to execute code remotely as an unprivileged user on a Pexip Infinity Conferencing Node.
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-102911] A flaw has been found in zosmaai pi-llm-wiki up to 0.11.7. Affected is an unknown function of the fi…
A flaw has been found in zosmaai pi-llm-wiki up to 0.11.7. Affected is an unknown function of the file mcp/index.ts of the component wiki_capture_source MCP tool. Executing a manipulation of the argument url can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used. Upgrading to version 0.11.8 is able to address this issue. This patch is …
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-103056] AiSOC versions 7.2.0 before 12.0.0 contain a command injection vulnerability in the actions service …
AiSOC versions 7.2.0 before 12.0.0 contain a command injection vulnerability in the actions service that builds CrowdStrike Real Time Response command strings by interpolating unescaped action parameters in crowdstrike_rtr.py and endpoint.py. Authenticated users can inject single quotes into file_path, path, script_name, or script_args parameters to break out of quoted arguments and execute arbitr…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-102794] A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown proces…
A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file /api/ZRnetwork/ping. Such manipulation of the argument url leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-102793] A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects the function set_tim…
A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects the function set_time_zone of the file /api/ZRFirmware/set_time_zone. This manipulation of the argument hostname/zonename causes command injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in …
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-102792] A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. This affects the function set_syslog of …
A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. This affects the function set_syslog of the file /api/ZRnetwork/set_syslog. The manipulation of the argument conloglevel/log_size results in command injection. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-103040] LightLLM through 1.2.0 contains a remote code execution vulnerability in the router profiler service…
LightLLM through 1.2.0 contains a remote code execution vulnerability in the router profiler service when started with --enable_profiling flag. The service exposes an unauthenticated RPyC server with pickle deserialization enabled, allowing attackers to execute arbitrary code by sending crafted serialized objects to the profiler command queue.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-103041] LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pick…
LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Attackers can send crafted serialized objects to exposed cache methods to execute arbitrary code with service privileges.