Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
Buscando: "Ni" — 1486 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-78573] IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker to gain administrativ…
IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker to gain administrative access due to the use of default credentials.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-45764] Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M…
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, a protocol change while processing HTTP/2 traffic could lead to type confusion in Suricata. Crafted traffic may cause Suricata to crash, resulting in denial of service. Versions 7.0.16 and 8.0.5 contain a fix. As a workaround, disable HTTP/2 pars…
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-89049] A server-side request forgery issue due to improper validation of equivalent address representations…
A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms might allow an authenticated remote user to bypass the remote destination denylist and reach link-local endpoints, potentially obtaining the temporary IAM role cre…
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-85228] An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from…
An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain information from adjacent process memory or cause a denial of service via a crafted tensor payload. To remediate this issue, users should upgrade to version 0.37.0 or above.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-81046] Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure vulnerability…
Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Arbitrary Code Execution within the application context.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-88869] AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scriptin…
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the AD_Server plugin's log.php endpoint that fails to escape the label parameter before storage. An unauthenticated attacker can inject malicious HTML through the label parameter, which is later rendered unsanitized in the admin Ad Types report using jQuery .html(), allowing execu…
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-88864] Capgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed th…
Capgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed through Supabase PostgREST. A holder of an ordinary Capgo full API key can insert a row with status='active' and enforce_sso=true, bypassing the intended backend SSO provisioning route (supabase/functions/_backend/private/sso/providers.ts) and its controls: the Enterprise plan requirement, SSO provide…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
10/09/2026
Vulnerabilidad de redirección abierta (Open Redirect) en Access Control System de Armiya
Se ha identificado una vulnerabilidad de redirección abierta en Access Control System de Armiya Information Technologies (versiones anteriores a la 2.0) que permite a atacantes redirigir usuarios a sitios no confiables y falsificar la fuente de datos. Esta falla afecta principalmente sistemas de control de acceso implementados en instalaciones de seguridad física en México y Latinoamérica, exponiendo credenciales y sesiones de usuarios autorizados.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-88285] Cámara GeoVision GV-LPC2211 V1.13 expone control PTZ sin autenticación
La cámara GeoVision GV-LPC2211 versión 1.13 expone un servicio de control PTZ (Pan-Tilt-Zoom) accesible por red sin requerir autenticación, permitiendo a atacantes remotos recuperar información de posicionamiento e inyectar comandos PTZ o comandos seriales arbitrarios. Esta vulnerabilidad afecta sistemas de vigilancia en infraestructura crítica, oficinas corporativas y centros de datos en México y Latinoamérica. Con CVSS 9.4, representa riesgo crítico de compromiso del perímetro de seguridad física y acceso no autorizado a sistemas de monitoreo.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-44950] fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph's bitmap in…
fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph's bitmap into a single buffer. Existing checks validates only that the source slice (position, length) lies within the source bitmap buffer. It does not check whether the running destination cursor has exceeded the allocation. A malicious font server can send overlapping source offsets -- for example 1000 gly…
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-77770] The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does…
The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validated transaction before deleting site options whose names come from unauthenticated request input, allowing any visitor to delete arbitrary options, which can lock every administrator out of the dashboard or deactivate every miniOrange 2FA WordPress plugin before 6.3.1, miniOran…
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-84939] Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can sp…
Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier to FreeMarker, and the localized lookup configuration setting is enabled (it's by default enabled). This issue affects Apache FreeMarker from 2.2.0 through 2.3.34. Users are recommended to upgrade to version 2.3.35. Disabling localized lookup in previ…
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-49364] An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrativ…
An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-67593] A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a qu…
A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes …
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-19583] Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the…
Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. However, no such check was implemented for client monitoring artifacts. Additionally there was no requirement that client monitoring artifacts carry the CLIENT_EVENTS …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-87931] A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearabl…
A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple Notification Center Service Event Handler. The manipulation leads to buffer overflow. The attack must be carried out from within the local network. The vendor was contacted early about this disclosure but did not respond in any…
M Crítico vulnerabilidad
09/09/2026
[CVE-2026-54694] SkillTree is a micro-learning gamification platform. Prior to version 4.4.2, two independent code fl…
SkillTree is a micro-learning gamification platform. Prior to version 4.4.2, two independent code flaws combine into a single exploitable attack chain, with three distinct exploitation paths of escalating impact. `StringHighlighter.js` builds an HTML string by interpolating raw `value` substrings directly into a template literal with no HTML entity encoding. `HighlightedValue.vue` renders that str…
M Crítico vulnerabilidad
09/09/2026
[CVE-2026-87929] MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config…
MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge administrator session cookies. Attackers can mint a malicious ci_session cookie with administrator privileges by computing an HMAC-SHA1 using the publicly known encryption key, bypassing authentication checks…
M Crítico vulnerabilidad
09/09/2026
[CVE-2026-16272] Use of less trusted source vulnerability in PayTR Payment and Electronic Money Institution Inc. PayT…
Use of less trusted source vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Exploitation of Trusted Identifiers. This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3.
M Crítico vulnerabilidad
09/09/2026
[CVE-2026-53939] OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In ve…
OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In versions 0.6.1 through 0.6.2.5, when cjose encrypts a JWE using an AES-CBC-HMAC content-encryption algorithm (`A128CBC-HS256`, `A192CBC-HS384`, or `A256CBC-HS512`) together with any key-management algorithm that generates a fresh content-encryption key (CEK), the CEK is all zero bytes instead of being…