Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Rti" — 121 resultados ✕ Limpiar búsqueda
13,539
Total alertas
3075
Críticas
10192
Altas
8
Ransomware
1790
Esta semana
RSS
M Crítico vulnerabilidad
17/08/2026
Vulnerabilidad crítica en openssl_encrypt < 1.4.0 compromete descifrado de datos
openssl_encrypt en versiones anteriores a 1.4.0 contiene una falla crítica en el módulo pqc.py que causa que fallos en desencapsulación KEM retrocedan silenciosamente a modo simulación, generando claves compartidas determinísticas a partir de solo 16 bytes de la clave privada. Un atacante que obtenga estos 16 bytes puede calcular la clave compartida y descifrar todos los textos cifrados, comprometiendo confidencialidad de datos sensibles en sistemas financieros, gubernamentales y empresariales de LATAM.
M Crítico vulnerabilidad
17/08/2026
Vulnerabilidad crítica de autenticación en openssl_encrypt anterior a v1.4.0
openssl_encrypt versiones anteriores a 1.4.0 contiene un fallo grave en la función verify_api_token que acepta cualquier token Bearer sin validación, permitiendo a atacantes cargar claves públicas arbitrarias, enumerar todas las claves existentes y revocar accesos de otros usuarios. Esta vulnerabilidad afecta directamente sistemas de encriptación y gestión de certificados críticos en infraestructuras de LATAM, especialmente en sectores financiero, salud y gobierno que dependen de esta librería para autenticación API.
M Crítico vulnerabilidad
16/08/2026
[CVE-2026-74790] Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter change…
Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to expose members that should be hidden. Attackers can access filtered properties and fields by reusing a TemplateContext after tightening its MemberFilter, bypassing sandbox policies across requests or tenants.
M Crítico vulnerabilidad
16/08/2026
[CVE-2026-73061] Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that al…
Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. Attackers can modify properties with private, internal, or init-only setters, and perform mass assignment on public-setter properties, permanently altering live host objects after template rendering.
M Crítico vulnerabilidad
15/08/2026
Vulnerabilidad crítica de bypass de autenticación en plugin User Session Synchronizer para WordPress (CVE-2026-15341)
El plugin User Session Synchronizer para WordPress en versiones hasta 1.4.0 contiene una vulnerabilidad de bypass de autenticación (CVSS 9.8) que permite la toma de control de cuentas sin validación de nonce, permisos o secretos compartidos. Un atacante puede explotar parámetros sin protección (`ussync-key`, `ussync-token`, `ussync-ref`) ejecutados en cada solicitud para secuestrar sesiones de usuarios, incluidas administrativas. Afecta directamente a medianas y grandes empresas en LATAM que alojan WordPress en infraestructura local o en la nube con este plugin activo.
M Crítico vulnerabilidad
14/08/2026
[CVE-2026-49457] erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not au…
erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared against the certificate, so `verify` was effectively a no-op on the client. A man-in-the-middle on the network path could pr…
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-73842] OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and …
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api/exec/, and /api/wirelogs/ on an internal listener without requiring a client certificate or token, allowing any network-reachable caller to read tenant Kubernetes Secrets, mutate workloads, and execute commands across connected…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-66465] Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.
Unauthenticated Broken Authentication in Cartify
M Crítico vulnerabilidad
12/08/2026
[CVE-2026-66898] A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during back…
A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained within the archive metadata. An attacker can exploit this flaw by supplying a crafted backup archive with malicious instance or volume names containing pa…
M Crítico vulnerabilidad
12/08/2026
[CVE-2026-63293] A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write op…
A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or unpacking an image archive, LXD fails to validate whether the metadata.yaml file is a symbolic link. An attacker can exploit this flaw by providing a crafted image archive with a symlinked metadata.yaml file pointing to target file paths on the host sys…
M Crítico vulnerabilidad
12/08/2026
[CVE-2026-73299] Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the T…
Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controlled template could traverse constructor and prototype properties to execute JavaScript in the host Node.js process. This issue is fixed in versions 0.1.5 and 2.0.0-…
M Crítico vulnerabilidad
12/08/2026
[CVE-2026-26035] An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through …
An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password
F Crítico vulnerabilidad
12/08/2026
Broken access control in the RADIUS type admin group
Fortinet PSIRT publica advisory de seguridad: Broken access control in the RADIUS type admin group. Tipo: Vulnerabilidad de seguridad. Producto afectado: Fortiweb.
F Crítico vulnerabilidad
12/08/2026
Content-Encoding WAF Evasion
Fortinet PSIRT publica advisory de seguridad: Content-Encoding WAF Evasion. Tipo: Vulnerabilidad de seguridad. Producto afectado: Fortiweb.
F Crítico vulnerabilidad
12/08/2026
FGFM Authentication Weakening via CLI Configuration
Fortinet PSIRT publica advisory de seguridad: FGFM Authentication Weakening via CLI Configuration. Tipo: Bypass de Autenticación. Producto afectado: Fortigate.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
F Crítico vulnerabilidad
12/08/2026
Heap overflow in kernel driver due to missing size validation
Fortinet PSIRT publica advisory de seguridad: Heap overflow in kernel driver due to missing size validation. Tipo: Desbordamiento de Heap. Producto afectado: Forticlient.
F Crítico vulnerabilidad
12/08/2026
Stack buffer overflow in WAD
Fortinet PSIRT publica advisory de seguridad: Stack buffer overflow in WAD. Tipo: Desbordamiento de Búfer. Producto afectado: Fortios.
F Crítico vulnerabilidad
12/08/2026
UI DoS attack
Fortinet PSIRT publica advisory de seguridad: UI DoS attack. Tipo: Vulnerabilidad de seguridad. Producto afectado: Fortios.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-69102] MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in appli…
MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.properties that allows unauthenticated attackers to forge valid JWT tokens and authenticate as any user by exploiting the password-skipped login endpoint. Attackers can craft a JWT token signed with the publicly known default secret, submit it to the /sign/login/jwt/trust endpoint, and…
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-10579] A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged …
A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role. This could lead to information disclosure, access to restricted operations, or other flaws.