Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
Buscando: "Ni" — 1486 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-53581] OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1.9 of opnsense/core …
OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1.9 of opnsense/core and version 26.4_20 of BE/opnsense/core, a path traversal vulnerability in the NTP configuration module allows an attacker to overwrite arbitrary files on the system as the root user. By manipulating the GPS or PPS serial port parameter, an attacker with access to the NTP configuration can escape th…
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-19232] Adobe Experience Manager is affected by an Incorrect Authorization vulnerability that could result i…
Adobe Experience Manager is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. A low-privileged attacker could exploit this vulnerability to gain elevated access or control over the victim's account or session. Exploitation of this…
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-76200] Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused…
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-76201] Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused…
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-75156] Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of A…
Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login. Deployments are affected only when the FAB auth manager is configured with Azure AD as an OAuth provider. Because the signing keys are fetched from Microsoft's **multi-tenant** JWKS endpoint, an `id_token` minted in *any* Azure tenant — including one the attac…
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-61516] Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that…
Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the administrator password by sending a request to the sysinfo action in the web management interface without a valid session. Attackers can replay the exposed credential against the login handler to establish a fully authenticated administrator session …
M Crítico vulnerabilidad
08/09/2026
Vulnerabilidad crítica en hawtio-operator expone claves de firma de OpenShift
Se encontró una flaw en hawtio-operator que permite la lectura no autorizada de la clave privada de firma de la autoridad certificadora (CA) de servicios de OpenShift desde el namespace openshift-service-ca. Un atacante con permisos de creación de recursos Hawtio en cualquier namespace puede falsificar certificados de cliente con CN arbitrario, escalando privilegios en clústeres OpenShift. Esta vulnerabilidad afecta directamente a empresas en LATAM que ejecutan plataformas de contenedores en OpenShift.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
08/09/2026
Vulnerabilidad crítica de inyección de argumentos en Cosminexus Component Container (CVE-2026-71377)
Se ha identificado una vulnerabilidad de inyección de comandos en Cosminexus Component Container con puntuación CVSS 9.8, afectando múltiples versiones desde la 11-70-01 hasta la 09-80. Esta vulnerabilidad permite a atacantes ejecutar comandos arbitrarios en servidores afectados, comprometiendo la integridad y disponibilidad de aplicaciones empresariales críticas. En Latinoamérica, las organizaciones financieras, de telecomunicaciones y sector público que utilizan este componente enfrentan riesgo inmediato de exfiltración de datos y acceso no autorizado.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-86510] A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params …
A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-86509] A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of t…
A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack can only be done within the local network. The exploit has been published and may be used.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-66768] SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked fro…
SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating a connected backend system to trigger affected functionality. This could allow arbitrary command execution on the victim's machine, leading to a high impact on the confidentiality, integrity, and avai…
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-44756] A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Und…
A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availabil…
F Crítico vulnerabilidad
08/09/2026
JWT used for authentication in web GUI signed with static key
Fortinet PSIRT publica advisory de seguridad: JWT used for authentication in web GUI signed with static key. Tipo: Vulnerabilidad de seguridad. Producto afectado: Fortimonitor.
M Crítico vulnerabilidad
07/09/2026
[CVE-2026-18922] A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried…
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect pas…
M Crítico vulnerabilidad
07/09/2026
[CVE-2026-80238] Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5…
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary Privileges vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass. This vulnerability is considered critical because a low-privileged operator with SSH access …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
07/09/2026
Inyección de comandos OS crítica en Linksys RE7000 2.0.15 permite ejecución remota
Se ha identificado una vulnerabilidad crítica (CVSS 9.9) en el repetidor inalámbrico Linksys RE7000 versión 2.0.15. Un atacante remoto puede inyectar comandos del sistema operativo manipulando parámetros de prueba ping (pingTestIp, pingTestPktSize, pingTestTimes) en el componente /cgi-bin/json.cgi?PingTest. El exploit es público y activamente explotado, afectando infraestructuras de redes corporativas y MiPyMEs en México y Latinoamérica que dependan de este dispositivo.
M Crítico vulnerabilidad
07/09/2026
Vulnerabilidad crítica de desbordamiento de búfer en D-Link DIR-822A A_101
Se ha identificado una vulnerabilidad de desbordamiento de búfer en la pila (stack-based buffer overflow) en el componente udhcpcd del router D-Link DIR-822A versión A_101, específicamente en la función strcpy del archivo udhcpcd/serverpacket.c. Esta falla puede ser explotada remotamente sin autenticación, permitiendo a atacantes ejecutar código arbitrario con privilegios del dispositivo. El exploit se encuentra públicamente disponible y actualmente es explotable en infraestructuras de empresas en México y LATAM que utilicen este modelo de router.
M Crítico vulnerabilidad
07/09/2026
Vulnerabilidad crítica en controladores Advantech WISE-6610 afecta sistemas industriales
Se identificó una vulnerabilidad crítica (CVSS 9.9) en múltiples modelos de controladores Advantech WISE-6610 (versión 1.2.1_20251110) que afecta la librería Node-RED. La vulnerabilidad permite manipulación de argumentos en la función nodered_lib_apply, comprometiendo sistemas de automación industrial en plantas, manufactura y infraestructura crítica en LATAM. Afecta aplicaciones desplegadas en entornos operacionales que dependen de estos dispositivos para monitoreo y control remoto.
M Crítico vulnerabilidad
07/09/2026
Vulnerabilidad crítica en controladores Advantech WISE-6610 permite manipulación de certificados
Se identificó una vulnerabilidad crítica (CVSS 9.9) en múltiples modelos de controladores industriales Advantech WISE-6610 (versión 1.2.1_20251110) que afecta el manejador de eliminación de certificados de estación base. Esta vulnerabilidad permite a atacantes manipular funciones críticas de autenticación en sistemas de control industrial, poniendo en riesgo infraestructuras críticas, plantas de manufactura y sistemas de energía en operación en México y Latinoamérica.
M Crítico vulnerabilidad
06/09/2026
Inyección de comandos OS crítica en Tenda HG10 (CVE-2026-86167)
Se identificó una vulnerabilidad crítica (CVSS 9.9) en el router Tenda HG10 modelo 300001138 que permite inyección de comandos del sistema operativo a través del parámetro fmgpon_loid en la función formgponConf. La vulnerabilidad es explotable remotamente y cuenta con exploits públicos disponibles. Afecta principalmente a pequeñas y medianas empresas en LATAM que utilizan estos equipos en infraestructuras de acceso a internet.