Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1023
Esta semana
RSS
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-19658] The Give Tributes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, …
The Give Tributes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.3.1 via deserialization of untrusted input . This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is i…
M Crítico vulnerabilidad
21/09/2026
[CVE-2026-94301] The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypa…
The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committed to the  2.2.X branch only. The 2.0.X and 2.1.X maintenance branches never received the resolveProxyClass() override, so the 2.0.29 and 2.1.13 artifacts listed a…
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-81657] IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary…
IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
M Crítico vulnerabilidad
18/09/2026
[CVE-2025-66455] LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in ver…
LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2 and prior to version 0.16.0, LMDeploy's PyTorch DistServe/PD-disaggregation control plane used `recv_pyobj()` to deserialize messages received through a ZeroMQ PULL socket. PyZMQ implements `recv_pyobj()` using Python pickle deserialization, which can execute arbitrary code while reconstr…
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-93467] The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote…
The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-54752] NetBox Device Type Library is a collection of community-sourced device type definitions for import i…
NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The validation test harness can deserialize pull-request-controlled tracked pickle cache files through pickle.load in the read_pickle_data function in tests/pickle_operations.py. An unauthenticated contributor can change USE_LOCAL_KNOWN_SLUGS in tests/test_configuration.py and supply a c…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-20341] A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software cou…
A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software could allow an authenticated, remote attacker to obtain root privileges. This vulnerability is due to unsecured deserialization of untrusted data over the sftunnel management connection. An attacker could exploit this vulnerability by sending crafted sftunnel remote procedure calls (RPCs). A su…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-20211] A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary comm…
A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid high-privileged administrative credentials. This vulnerability is due to insecure deserialization of Java objects by the affected software. An attacker could exploit this vul…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-20242] A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (…
A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary commands as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream from a host that is configured in the external database access list. An attacke…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-20307] A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, rem…
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least low-privileged administrative credentials. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream.…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-70416] Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerabil…
Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
M Crítico vulnerabilidad
16/09/2026
[CVE-2025-59953] LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in ver…
LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior to version 0.10.2, the LMdeploy implements an rpc server (AsyncRPCServer in zmq_rpc.py) for supporting the RPC communications. In its core functionality call_and_response(), I found it will directly use the pickles.loads() to deserialize the received messages without any sanitiz…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-91939] Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes r…
Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can exploit PHP object injection through crafted serialized payloads to trigger gadget chains and achieve database manipulation or code execution.
M Crítico vulnerabilidad
15/09/2026
[CVE-2023-54398] Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.fi…
Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageServlet component that allows remote unauthenticated attackers to execute arbitrary OS commands by sending a serialized payload via POST request. Attackers can exploit the doAction method, which passes raw HTTP request body data directly to ObjectInputStream.readObject() without f…
M Crítico vulnerabilidad
14/09/2026
Vulnerabilidad crítica de ejecución remota de código en LightLLM hasta versión 1.2.0
LightLLM versiones anteriores a 1.2.1 contiene una vulnerabilidad de ejecución remota de código (RCE) en el endpoint WebSocket /visual_register del Config Server sin autenticación. Un atacante con acceso a la red puede enviar un payload malicioso serializado con método __reduce__ a pickle.loads() para ejecutar código arbitrario con privilegios del proceso Config Server. Este riesgo afecta directamente a infraestructuras de IA/ML en empresas de México y LATAM que ejecuten LightLLM en entornos de producción o desarrollo expuestos a la red interna o internet.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
12/09/2026
Vulnerabilidad crítica de ejecución remota de código en The Events Calendar para WordPress hasta versión 6.17.4
The Events Calendar plugin para WordPress es vulnerable a ejecución remota de código (RCE) en todas las versiones hasta 6.17.4. La falla reside en la función is_safe_widget_instance que puede ser eludida mediante métodos mágicos de PHP durante el pre-parseo, permitiendo a atacantes no autenticados ejecutar código arbitrario. Empresas en LATAM que operan sitios WordPress con este plugin están expuestas a compromisos críticos de integridad y disponibilidad.
M Crítico vulnerabilidad
12/09/2026
[CVE-2026-82845] The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metad…
The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of a class shipped in a library bundled with the Masteriyo LMS WordPress plugin before 3.4.1, write and execute arbitrary code on the server. A weaker form of the s…
M Crítico vulnerabilidad
12/09/2026
Vulnerabilidad crítica en GitLab EE permite acceso a credenciales sensibles (CVE-2026-87719)
GitLab Enterprise Edition presenta una falla de seguridad en versiones 18.3 a 19.3.1 que permite a usuarios autenticados con acceso a Duo Chat obtener configuraciones de Advanced Search y credenciales sensibles mediante argumentos GraphQL especialmente diseñados. La vulnerabilidad afecta principalmente a empresas LATAM que utilizan GitLab EE para almacenar código crítico y secretos de aplicaciones. Con puntuación CVSS 9.9, esta falla requiere atención inmediata en infraestructuras de DevOps.
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-62103] Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions.
Unauthenticated PHP Object Injection in Everest Forms
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-62105] Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.
Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.