Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-102361] mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoi…
mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated attackers to reset any storefront account password. Attackers can supply a target username in the request body to overwrite passwords without verification, enabling account takeover and access to orders and personal data.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-101264] A vulnerability was determined in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the…
A vulnerability was determined in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the file /api/ZRnetwork/set_passwd. This manipulation of the argument password1 causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-101263] A vulnerability was found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing …
A vulnerability was found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file /api/ZRQos/set_online_client. The manipulation of the argument mac results in command injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-101261] A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This affects an unknown part of the file /api/Z…
A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This affects an unknown part of the file /api/ZRnetwork/firstSetup_wifi. Executing a manipulation of the argument login_pwd can lead to command injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-101262] A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects unknown cod…
A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects unknown code of the file /api/ZRQos/set_online_client. The manipulation of the argument ip leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any wa…
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-101260] A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. Affected by this issue is some unknown f…
A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. Affected by this issue is some unknown functionality of the file /api/ZRnetwork/firstLogin. Performing a manipulation of the argument firstLogin results in command injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respon…
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-102268] PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, is_pem_format in jwt/…
PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, is_pem_format in jwt/utils.py is affected because is_pem_format does not recognize every PEM representation accepted by the cryptography loader. This occurs when an application mixes HMAC and asymmetric algorithms and supplies a mutated public-key PEM as raw key bytes. As a result, HMACAlgorithm.prepare_key treats the u…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-101187] A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects the functio…
A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects the function pop_usb_device of the file usr/lib/lua/luci/controller/api/zrUsb.lua of the component USB Device Management API. This manipulation of the argument path causes command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used f…
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-49994] Bluehood monitors local bluetooth activity. Prior to version 0.7.1, when auth_enabled is set in Blue…
Bluehood monitors local bluetooth activity. Prior to version 0.7.1, when auth_enabled is set in Bluehood, only the HTML page handlers enforced session validation. The /api/* handlers (settings, devices, groups, per-device endpoints including /api/device/{mac}/notes) called no auth check at all. A network attacker reachable on the dashboard port could read Bluetooth tracking data and modify applica…
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-101894] The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decomp…
The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API relies on lexical containment checks that do not account for the kernel following a planted symlink chain. An attacker can supply a crafted archive containing chained symlink entries so that a later entry resolves outside the output directory. This allows files outside output…
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-101081] A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability affects the function…
A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability affects the function menu_nat_more_asp of the file menu_nat_more.asp of the component Web Administration Service. The manipulation of the argument opt results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-88804] An unauthenticated update of public UI settings could be used by remote attackers to execute a store…
An unauthenticated update of public UI settings could be used by remote attackers to execute a stored cross-site scripting attack in the Rancher UI, in SUSE Rancher 2.15 before 2.15.2, 2.14 before 2.14.6, 2.13 before 2.13.10, 2.12 before 2.12.14 and 2.11 before 2.11.18.
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-12342] This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated user remote code…
This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated user remote code execution on the IdentityIQ server due to improper input validation of submitted web service API content.
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-101077] A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the…
A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp Handler. This manipulation causes missing authentication. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-101076] A vulnerability was detected in Netcore NR289-GE 1.4.5102. This affects the function system of the f…
A vulnerability was detected in Netcore NR289-GE 1.4.5102. This affects the function system of the file /set_ntp_server_ip.cgi of the component CGI Handler. The manipulation of the argument ntp_ip results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-101075] A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The impacted element is the…
A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The impacted element is the function system of the file /location_time.cgi of the component Location Time Handler. The manipulation of the argument mac leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about thi…
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-101074] A weakness has been identified in Netcore NR289-GE 1.4.5102. The affected element is the function pa…
A weakness has been identified in Netcore NR289-GE 1.4.5102. The affected element is the function password-check of the file /bin/boa of the component Authentication. Executing a manipulation of the argument Username can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted…
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-87799] Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixe…
Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client that can create instances or custom storage volumes in a project, or a malicious migration source server, to write attacker-controlled files to arbitrary paths on the target host as root, leading to full host compromise. T…
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-90924] Use of default credentials vulnerability in Innotim Software, Telecommunications and Consultancy Tra…
Use of default credentials vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Try Common or Default Usernames and Passwords. This issue affects Logsign SIEM: from 6.4.101 before 6.4.117.
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-85185] Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.1…
Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create instances in a project to delete arbitrary files on the host as root. On hosts whose root filesystem is btrfs, the client can also place attacker-controlled content at arbitrary host paths, leading to full …