Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 3 min
Buscando: "X" — 3561 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-93643] When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an …
When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned save fields to perform path-traversal writes and execute commands as zimbra.
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-93647] An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. …
An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. Selecting the message in Zimbra Classic triggers stored XSS, allowing the attacker to access mailbox data and act as the victim.
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-100075] In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: Fix srpt_alloc_rw_ct…
In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters When srpt_alloc_rw_ctxs() fails partway through a multi-buffer indirect descriptor, the unwind path destroys RDMA contexts but leaves stale n_rw_ctx and n_rdma values (and a dangling rw_ctxs pointer). Later sq_wr_avail accounting in srpt_queue_response() or srpt_write_pending()…
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-92609] Session fixation in HTTP management authentication allows remote attackers to gain unauthorized acce…
Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session via reuse of a session identifier retained across successful authentication. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue.
M Crítico vulnerabilidad
25/09/2026
CVE-2026-32157 Remote Desktop Client Remote Code Execution Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-32157 Remote Desktop Client Remote Code Execution Vulnerability. Tipo: Ejecución Remota de Código (RCE).
M Crítico vulnerabilidad
25/09/2026
Vulnerabilidad crítica en plugin Bookly para WordPress permite acceso no autorizado a datos de reservas
El plugin Bookly para WordPress (versiones hasta 28.2) contiene una vulnerabilidad de Referencia Directa a Objetos (IDOR) en acciones AJAX que permite a atacantes acceder y manipular datos de reservas, sesiones y órdenes sin autenticación. Afecta directamente a negocios de servicios en LATAM que usan este plugin para gestionar citas y pagos online, exponiendo información de clientes y transacciones.
? Crítico alerta
25/09/2026
CISA Adds One Known Exploited Vulnerability to Catalog
CISA emite alerta de seguridad: CISA Adds One Known Exploited Vulnerability to Catalog. CVEs relacionados: CVE-2026-87902.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
? Crítico alerta
25/09/2026
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA emite alerta de seguridad: CISA Adds Two Known Exploited Vulnerabilities to Catalog. CVEs relacionados: CVE-2026-65660, CVE-2026-67279.
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-95699] Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users acce…
Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT topics, which can expose other users' device data and allow the attacker to start and stop other connected users' devices. This risked exposing user profile information and potential scalding due to unintended device activation.
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-93291] Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-m…
Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code.
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-13249] An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web manageme…
An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows upload of attacker controlled files without requiring authentication. An attacker could potentially exploit this vulnerability, leading to the execution of malicious files and commands. Honeywell also recommends updati…
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-61741] http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]` instances that parse XML message bodies…
http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]` instances that parse XML message bodies. Prior to versions 0.24.1 and 1.0.0-M39, these decoders used a `javax.xml.parsers.SAXParserFactory` obtained from `SAXParserFactory.newInstance` without any security configuration. With the JDK's default settings, the parser resolves DOCTYPE declarations, external general and parameter entities, a…
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-97413] In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Fix integer unde…
In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Fix integer underflow in process_read and process_write usr_len is read from a network-supplied message field (le16_to_cpu) and used to compute data_len = off - usr_len without validating that usr_len off causing an integer underflow, resulting in data_len wrappin…
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-79766] Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capa…
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.4.1 until 2.5.1, an authenticated Termix administrator can store attacker-controlled domain and email values through PATCH /users/acme-ssl-settings and trigger their interpolation into a certbot shell command through POST /users/acme-ssl-request. In src/backend/database/routes/acme-…
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-93228] In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reject Write/Reply chu…
In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reject Write/Reply chunks with segcount 0 A peer can send a Write or Reply chunk whose segcount field is zero. xdr_check_write_chunk() only rejects segcount > rc_maxpages, so zero passes the range check, and xdr_inline_decode(stream, 0) returns the current (non-NULL) cursor without advancing. The function returns true a…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-93207] In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Zero rpc_gss_wire_cred …
In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry svcauth_gss_decode_credbody() writes the caller's rpc_gss_wire_cred field by field and assigns gc_ctx.len only on the success tail. The caller storage is svcdata->clcred, which lives in the per-svc_rqst gss_svc_data and is reused across requests. Early decod…
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-81549] IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain se…
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of the X-Forwarded-Proto header.
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-97359] HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload h…
HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve remote code execution by embedding malicious template syntax in a filename. Attackers can craft a filename containing a closing template quoting sequence followed by an exec macro, which bypasses the authorization check in the dispatcher to exe…
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-97360] HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that …
HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has filesystem access outside the shared folder. Attackers can exploit the macro dispatcher's lack of authorization model combined with the path resolver's failure to confine absolute paths to …
M Crítico vulnerabilidad
24/09/2026
Vulnerabilidad crítica de inclusión de archivos en Visual Composer Website Builder para WordPress
El plugin Visual Composer Website Builder para WordPress (versiones hasta 45.16.0) contiene una vulnerabilidad de inclusión local de archivos (LFI) que permite a atacantes no autenticados ejecutar código PHP arbitrario en el servidor. Esta falla afecta directamente a miles de sitios web en México y LATAM que utilizan este constructor visual, comprometiendo datos sensibles y permitiendo control total del servidor.