Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-87799] Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixe…
Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client that can create instances or custom storage volumes in a project, or a malicious migration source server, to write attacker-controlled files to arbitrary paths on the target host as root, leading to full host compromise. T…
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-90924] Use of default credentials vulnerability in Innotim Software, Telecommunications and Consultancy Tra…
Use of default credentials vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Try Common or Default Usernames and Passwords. This issue affects Logsign SIEM: from 6.4.101 before 6.4.117.
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-85185] Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.1…
Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create instances in a project to delete arbitrary files on the host as root. On hosts whose root filesystem is btrfs, the client can also place attacker-controlled content at arbitrary host paths, leading to full …
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-85526] Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authen…
Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace arbitrary files and directories on the host filesystem as root via a crafted subvolumes[].path entry in backup/optimized_header.yaml during a btrfs optimized backup import.
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-101072] A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects the function system …
A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects the function system of the file /ap_ip.cgi of the component CGI Handler. Such manipulation of the argument ip leads to os command injection. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Crítico vulnerabilidad
28/09/2026
Vulnerabilidad crítica de desbordamiento de buffer en FAST FAC1200R 5.0
Se identificó una vulnerabilidad de desbordamiento de búfer basado en pila (CVSS 9.9) en el analizador MmtAtePrase del dispositivo FAST FAC1200R versión 5.0_20201119_1.0.2, permitiendo explotación remota sin autenticación. El exploit se encuentra públicamente disponible y el fabricante no ha respondido a notificaciones previas. Esta vulnerabilidad afecta principalmente a empresas de telecomunicaciones, ISPs y proveedores de servicios en México y LATAM que utilizan equipos FAST en infraestructuras críticas.
M Crítico vulnerabilidad
28/09/2026
Vulnerabilidad crítica en FAST FAC1900R 20190827_2.0.2 permite desbordamiento de búfer remoto
Se identificó un desbordamiento de búfer basado en pila (stack-based buffer overflow) en la función copy_msg_element del servicio devdiscover de FAST FAC1900R versión 20190827_2.0.2. La vulnerabilidad permite ejecución remota de código sin autenticación (CVSS 10.0) y cuenta con exploits públicamente disponibles. El fabricante no ha respondido a reportes de divulgación responsable, elevando el riesgo inmediato para infraestructuras que dependan de este dispositivo en centros de datos y operaciones críticas de LATAM.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
28/09/2026
Vulnerabilidad crítica de desbordamiento de búfer en FAST FAC1200R 5.0
Se ha identificado un desbordamiento de búfer basado en pila (stack-based buffer overflow) en la función parse_advertisement_frame del servicio devdiscover del dispositivo FAST FAC1200R versión 5.0_20201119_1.0.2, con puntuación CVSS 9.9. La vulnerabilidad puede ser explotada remotamente sin autenticación, permitiendo ejecución de código arbitrario en routers empresariales y de pequeños negocios ampliamente desplegados en México y Latinoamérica. El exploit es público y el fabricante no ha respondido a solicitudes de parche.
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-82384] Deserialization of Untrusted Data in Apache Roller 6.1.5 allows an unauthenticated remote attacker t…
Deserialization of Untrusted Data in Apache Roller 6.1.5 allows an unauthenticated remote attacker to cause deserialization of attacker-controlled bytes, because the XML-RPC endpoint accepts vendor extension types that are deserialized during request parsing, before authentication. The servlet is mapped unconditionally, so parsing occurs even when the global XML-RPC feature is set to disabled; no …
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-82377] Missing Authorization in Apache Roller 6.1.5 allows an authenticated user to read, modify, or delete…
Missing Authorization in Apache Roller 6.1.5 allows an authenticated user to read, modify, or delete weblog content belonging to other weblogs through the legacy XML-RPC Blogger and MetaWeblog APIs, because the handlers authenticate the caller but do not verify the caller's permission on the weblog or entry actually affected. Only installations that enable the non-default global XML-RPC setting ar…
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-82378] Incorrect Authorization in the OAuth 1.0a authorization endpoint of Apache Roller 6.1.5 allows an un…
Incorrect Authorization in the OAuth 1.0a authorization endpoint of Apache Roller 6.1.5 allows an unauthenticated remote attacker who learns an outstanding request token for a configured site-wide consumer to bind that token to an arbitrary user account, including an administrator, by submitting an unsigned authorization request. The endpoint derives the authorizing identity from a request-supplie…
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-101008] A vulnerability was found in aaPanel BaoTa up to 11.8.0. Impacted is the function merge_split_file o…
A vulnerability was found in aaPanel BaoTa up to 11.8.0. Impacted is the function merge_split_file of the file /www/server/panel/class/files.py of the component File Merge Handler. Performing a manipulation of the argument split_file_path results in command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted ear…
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-101002] A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. Affected is the function …
A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. Affected is the function system of the file /usr/bin/network_tools of the component Tools Ping Handler. Performing a manipulation of the argument url results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early …
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-101000] A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.…
A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.apply of the file /usr/share/rpcd/acl.d/unauthenticated.json of the component ACL Handler. This manipulation of the argument section causes missing authorization. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted ear…
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-101001] A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This impacts the function eval…
A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This impacts the function eval of the file /www/cgi-bin/network_tools of the component Web Management Interface. Such manipulation of the argument QUERY_STRING leads to os command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about thi…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-100896] A weakness has been identified in TOTOLINK N150RT 3.4.0-B20201030. The affected element is the funct…
A weakness has been identified in TOTOLINK N150RT 3.4.0-B20201030. The affected element is the function system of the file /boafrm/formWlSiteSurvey of the component Web Management Interface. This manipulation of the argument wlanif causes os command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
M Crítico vulnerabilidad
27/09/2026
[CVE-2026-100886] A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. …
A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. The affected element is an unknown function of the component Debug Service. Such manipulation leads to improper authentication. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any wa…
M Crítico vulnerabilidad
27/09/2026
[CVE-2026-101090] Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the ne…
Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional dashboard_host setting is empty, /api/v1/oauth2/{provider} (cmd/dashboard/controller/oauth2.go) reflects the attacker-supplied HTTP Host header into the redirect_uri sent to the identity provider instead of falling back to the configured install_host. An attacker who induces a victim to b…
M Crítico vulnerabilidad
27/09/2026
[CVE-2026-101065] Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, th…
Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart command documented in the README starts the container listening on 0.0.0.0:8080 with authentication disabled by default. When authentication is disabled, every request is mapped to a synthetic "nobody" user that holds the Owner and Admin roles, so any unauthenticated party who ca…
M Crítico vulnerabilidad
27/09/2026
[CVE-2026-101084] obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allo…
obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID. Attackers can bypass authorization checks to access and manipulate sensitive backend systems through MCP tool calls using stored OAuth credentials.