Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Quest" — 436 resultados ✕ Limpiar búsqueda
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1013
Esta semana
RSS
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-53953] GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of…
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In version 3.3.22, the password reset endpoint can be accessed without authentication. When a reset request is submitted for an existing user, the application generates a new temporary password and immediately stores its hash as the user's new password. The temporary password is generated…
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-104286] An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in F…
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-102628] The Cadmos LTI application hosted at cadmos.eummena.io had Laravel debug mode enabled (APP_DEBUG=tru…
The Cadmos LTI application hosted at cadmos.eummena.io had Laravel debug mode enabled (APP_DEBUG=true, APP_ENV=local) in a publicly accessible environment. An unauthenticated attacker could send a GET request and trigger an unhandled exception, causing Laravel to expose the entire server environment, including all .env configuration variables, in plaintext. Fixed on or before 2026-09-02.
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-96659] A flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer p…
A flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer permissions to cause unauthorized information disclosure by submitting requests to template preview endpoints. By exploiting this issue, the user can access sensitive data, such as host root passwords. Furthermore, under insecure system configurations where Safemode protections are disabled, the flaw…
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-103255] n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path…
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in the Supabase node where the tableId parameter is inserted into request paths without validation. Attackers can exploit workflows binding tableId to untrusted input to traverse to Auth and Storage APIs using the administrative serviceRole key, bypassing Row Level Security …
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-103248] n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a filt…
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a filter injection vulnerability in the Supabase node's Filters (String) mode that fails to escape field values. Attackers can inject filter expressions from untrusted input to read all table rows, update all records, or delete entire tables in a single request.
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-102102] Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery…
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise unintended network destinations. The requests are triggered while the gateway retrieves…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-102103] Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery…
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise unintended network destinations. The requests are triggered while the gateway retrieves…
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-102104] Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery…
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise unintended network destinations. The requests are triggered while the gateway performs …
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-102105] Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery…
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise unintended network destinations. The requests are triggered while the gateway renders m…
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-102095] Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery…
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery. Kiteworks Email Protection Gateway performed server-side fetches of URLs contained in the message content it processed, without adequately restricting the fetch destination. A remote, unauthenticated sender could craft a message that caused the gateway to issue requests to internal services and cl…
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-62308] Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6,…
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6, Tugtainer allows an authenticated user to make the backend server send outbound HTTP requests to arbitrary user-supplied URLs through the notification test endpoint. The /settings/test_notification endpoint accepts a urls field and passes it directly to Apprise without restricting protocols, hostna…
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-55494] Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.4,…
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.4, Tugtainer Agent allows unauthenticated access to Docker management APIs when AGENT_SECRET is not configured. The Agent uses request signatures to protect its API routes. However, in agent/auth.py, the signature verification function returns successfully if Config.AGENT_SECRET is empty. This causes …
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-55181] Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.3,…
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.3, Tugtainer's OIDC authentication can still be initiated even when OIDC_ENABLED=false. The /auth/oidc/enabled endpoint correctly reports that OIDC is disabled. However, a direct request to /auth/oidc/login still starts the OIDC login flow, returns HTTP 302, sets an oidc_state cookie, and redirects th…
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-76504] A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager …
A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a spe…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-71379] The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by …
The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by sending a crafted POST request.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-53988] Dockhand before 1.0.40 contains an authentication bypass vulnerability in its git webhook endpoints …
Dockhand before 1.0.40 contains an authentication bypass vulnerability in its git webhook endpoints that allows unauthenticated remote attackers to trigger arbitrary stack redeployments by exploiting a null webhook secret guard condition. Attackers can enumerate sequential stack IDs and send unsigned webhook requests to force git clone and docker compose operations, enabling denial of service or, …
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-100291] In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, several ONVIF service endpoints process manageme…
In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, several ONVIF service endpoints process management requests without enforcing required authentication. This could allow an unauthorized attacker to access sensitive device operations.
M Crítico vulnerabilidad
29/09/2026
Vulnerabilidad crítica de autenticación en Hitachi Energy RTU500 permite carga de firmware no autorizada
Se ha identificado una vulnerabilidad de omisión de autenticación (CVE-2026-8065, CVSS 9.1) en el endpoint de actualización de firmware de Hitachi Energy RTU500 que permite a atacantes no autenticados cargar firmware malicioso mediante solicitudes POST modificadas. La explotación exitosa podría comprometer la funcionalidad operativa, integridad y disponibilidad del dispositivo, afectando principalmente infraestructuras críticas de energía, agua y telecomunicaciones en LATAM que dependen de estos controladores RTU.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-102361] mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoi…
mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated attackers to reset any storefront account password. Attackers can supply a target username in the request body to overwrite passwords without verification, enabling account takeover and access to orders and personal data.