Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ni" — 1486 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-73946] Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentic…
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impa…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-73948] Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Compose…
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact addit…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-71133] Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentic…
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impa…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-71163] Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentic…
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impac…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-61667] DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0…
DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, DataManagementSystem/Service/FileCatalogHandler.py checkDataset forwards an authenticated caller-controlled datasets value to DatasetManager.py __checkDataset, where datasetName is interpolated into an FC_MetaDatasets SQL query without parameterization. The injected query ca…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-45579] DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0…
DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, the RequestManagementSystem/Service/ReqManagerHandler.py export_getRequestCountersWeb function passes an authenticated caller-controlled groupingAttribute to RequestManagementSystem/DB/RequestDB.py getRequestCountersWeb. An unrecognized value is resolved against the Request …
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-89026] The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf cont…
The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens. Attackers can use the forged token to call the manager originate endpoint with the System application parameter, c…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
15/09/2026
[CVE-2024-58385] Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php…
Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpoint where the DontCheckLogin=1 parameter bypasses authentication and the id parameter is incorporated into SQL queries without sanitization. Attackers can exploit this flaw to execute arbitrary SQL commands and, on Microsoft SQL Server deployments with xp_cmdshell enabled, write …
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-39919] Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 outp…
Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows attackers to cause memory corruption by supplying a crafted PDF containing a JPEG 2000 image with mismatched component subsampling factors. When image components declare different subsampling values, the non-samescale sub-byte-depth output path allocates…
M Crítico vulnerabilidad
15/09/2026
Vulnerabilidad crítica de bypass de autorización en Casdoor 4.4.0 y anteriores
Casdoor versiones hasta 4.4.0 presenta una vulnerabilidad de bypass de autorización en el endpoint /api/mcp que permite a atacantes con credenciales válidas (clientId y clientSecret) de cualquier aplicación acceder sin restricciones a la administración de usuarios en todas las organizaciones. Los atacantes pueden enumerar registros de usuarios incluyendo salts de contraseñas y direcciones de correo, crear cuentas administrativas, modificar y eliminar usuarios existentes. Este riesgo es crítico para empresas en LATAM que utilizan Casdoor en entornos de producción con múltiples organizaciones o tenants.
M Crítico vulnerabilidad
15/09/2026
Vulnerabilidad crítica de autenticación en Pig anterior a 4.1.0 permite control administrativo
Pig versiones anteriores a 4.1.0 presentan una vulnerabilidad de omisión de autenticación en el endpoint /register/password que descarta la verificación de contraseña actual, permitiendo a atacantes remotos reescribir credenciales de cualquier cuenta incluyendo administrador con CVSS 9.1. Esta falla expone sistemas de gestión de identidades en empresas LATAM a toma de control administrativo completo sin credenciales válidas.
M Crítico vulnerabilidad
15/09/2026
Vulnerabilidad crítica en PraisonAI permite ejecución remota de código malicioso
PraisonAI versiones 1.4.0 a 1.7.2 contienen una vulnerabilidad de ejecución de código no autorizado (CVSS 9.9) en el módulo code-mode.ts. Un atacante puede eludir el sandbox de JavaScript utilizando técnicas de prototipado para recuperar el constructor Function real y acceder a process, comprometiendo completamente sistemas que ejecuten agentes multi-IA. Este riesgo afecta directamente a empresas en LATAM que implementan automatización con PraisonAI en entornos productivos.
M Crítico vulnerabilidad
15/09/2026
Vulnerabilidad crítica en PraisonAI permite falsificación de tokens JWT sin autenticación
PraisonAI versiones anteriores a 0.1.6 utiliza una clave HS256 predeterminada y pública cuando las variables de entorno no están configuradas, permitiendo que atacantes sin autenticación firmen tokens JWT arbitrarios. Esta falla afecta a sistemas que ejecuten plataformas de agentes multiequipo en configuraciones de desarrollo accidentalmente expuestas en producción, comprometiendo completamente el control de acceso.
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-91003] A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the …
A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the file /rzgl.asp of the component CGI Service. This manipulation of the argument redirct_url causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-91001] A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of t…
A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the component DDNS Configuration. Performing a manipulation of the argument serv/user/host/wild/mx/bmx/cust/ip results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-90847] A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown functio…
A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown function of the file iux_set.cgi of the component System Setup. This manipulation causes os command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-12944] IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root…
IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports. This enables: (1) AWS credential theft via IMDSv1 SSRF with full IAM role permissions, (2) arbitrary file exfiltration from the container filesystem, and (3) lateral movement to internal services…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-90945] Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be over…
Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid administrator tokens to access administrative APIs and execute code on worker nodes.
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-90942] Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /…
Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it. Attackers can use the exposed private key to forge JWT tokens for any user in any organization, including global administrators.
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-76440] As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Em…
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76440 are related to…