Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 16 min
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-72507] The "reportType" parameter in the product summary report feature within the balancing reports sectio…
The "reportType" parameter in the product summary report feature within the balancing reports section is susceptible to a time-based blind SQL injection vulnerability.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-72510] The "supplier_no" parameter used in the business allocation search feature is vulnerable to time-bas…
The "supplier_no" parameter used in the business allocation search feature is vulnerable to time-based blind SQL injection.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-71379] The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by …
The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by sending a crafted POST request.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-70356] The TMS file upload endpoint fails to enforce server-side file type restrictions, allowing an attack…
The TMS file upload endpoint fails to enforce server-side file type restrictions, allowing an attacker to upload and execute arbitrary PHP files on the web server.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-68954] The "pattern" parameter used in search function in the home page of the TMS application is vulnerabl…
The "pattern" parameter used in search function in the home page of the TMS application is vulnerable to time-based blind SQL injection vulnerability.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-68068] The "screenID" parameter in the electronic transaction queue viewer feature within the manual transa…
The "screenID" parameter in the electronic transaction queue viewer feature within the manual transactions section is susceptible to a time-based blind SQL injection vulnerability.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-63713] The "search" parameter in the view audit logs feature within the utilities section is susceptible to…
The "search" parameter in the view audit logs feature within the utilities section is susceptible to a time-based blind SQL injection vulnerability.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-96587] The Viidure Android application embeds permanent, plaintext cloud storage credentials within its com…
The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide full access to critical platform storage, including the ability to read, modify, or delete operational files such as firmware and application binaries.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-79538] metatool-ai MetaMCP up to and including 2.4.22 is vulnerable to Code Execution in the internal MCP i…
metatool-ai MetaMCP up to and including 2.4.22 is vulnerable to Code Execution in the internal MCP inspector proxy endpoint GET /mcp-proxy/server/stdio (createTransport, STDIO branch, routers/mcp-proxy/server.ts).
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-76721] Buffer overflow vulnerability exists in the affected interface of HPE Networking Instant ON that cou…
Buffer overflow vulnerability exists in the affected interface of HPE Networking Instant ON that could allow an unauthenticated remote attacker to run arbitrary code on the underlying host. Successful exploitation could allow an attacker to execute arbitrary code as a privileged user on the underlying operating system.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-76722] Uncontrolled Format string vulnerabilities exist in the affected interface of HPE Networking Instant…
Uncontrolled Format string vulnerabilities exist in the affected interface of HPE Networking Instant ON APs that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation could result in a Denial-of-service or potential remote code execution.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-76723] Buffer overflow vulnerabilities exist in the affected interface of HPE Networking Instant ON APS tha…
Buffer overflow vulnerabilities exist in the affected interface of HPE Networking Instant ON APS that could allow an unauthenticated adjacent attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-76724] A command injection vulnerability exists in CLI of the affected HPE Networking Instant ON APs that c…
A command injection vulnerability exists in CLI of the affected HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to perform command injection by sending specially crafted packets. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-76725] A vulnerability has been identified in a management protocol of HPE Networking Instant ON APs that c…
A vulnerability has been identified in a management protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing authentication controls. Successful exploitation could result in a complete bypass of security restrictions, potentially leading to remote code execution with elevated privileges.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-39117] An issue in AltumCode 66Uptime before v.54.0.0 and 66Uptime ping-servers plugin before v.2.0.0 allow…
An issue in AltumCode 66Uptime before v.54.0.0 and 66Uptime ping-servers plugin before v.2.0.0 allows a remote attacker to execute arbitrary code via the index.php

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-53988] Dockhand before 1.0.40 contains an authentication bypass vulnerability in its git webhook endpoints …
Dockhand before 1.0.40 contains an authentication bypass vulnerability in its git webhook endpoints that allows unauthenticated remote attackers to trigger arbitrary stack redeployments by exploiting a null webhook secret guard condition. Attackers can enumerate sequential stack IDs and send unsigned webhook requests to force git clone and docker compose operations, enabling denial of service or, …
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-102331] Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote atta…
Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-102316] Use after free in Views in Google Chrome prior to 154.0.8037.92 allowed a remote attacker leveraging…
Use after free in Views in Google Chrome prior to 154.0.8037.92 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-102304] Use after free in Passwords in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to exe…
Use after free in Passwords in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-102306] Use after free in Bluetooth in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to pot…
Use after free in Bluetooth in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)