Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ni" — 1489 resultados ✕ Limpiar búsqueda
22,298
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1168
Esta semana
RSS
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-75431] PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT signing key for HS256-base…
PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT signing key for HS256-based authentication. This allows a remote attacker to execute arbitrary code.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-44402] Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in …
Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary commands as root by uploading a crafted tar archive without valid credentials. Attackers can supply a malicious tar archive containing arbitrary executable files that are extracted to a privileged directory and…
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-85684] marker through 2.0.0 contains a path traversal vulnerability in the FastAPI /marker/upload handler t…
marker through 2.0.0 contains a path traversal vulnerability in the FastAPI /marker/upload handler that fails to sanitize the file.filename parameter. Unauthenticated attackers can supply filenames containing directory traversal sequences to write arbitrary files to any location or delete existing files on the system.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-85672] zerox 1.1.20 contains an OS command injection vulnerability in the file download mechanism where the…
zerox 1.1.20 contains an OS command injection vulnerability in the file download mechanism where the temporary file extension derived from document URLs is interpolated unsanitized into shell commands executed by poppler utilities. Attackers can craft document URLs with malicious file extensions containing command substitution syntax to execute arbitrary OS commands before document processing occu…
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-85085] The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView…
The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with Canva using the user’s session.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85430] MOOS essential-moos through 10.0.1 contains an authentication bypass vulnerability in pShare that ac…
MOOS essential-moos through 10.0.1 contains an authentication bypass vulnerability in pShare that accepts UDP datagrams from any source and republishes them with the attacker-claimed identity intact. Attackers can send crafted UDP datagrams to pShare input routes to inject messages into the local MOOS community under spoofed identities, or send malformed datagrams to crash the pShare process.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85425] MOOS-IvP iSay through 24.8.1 contains a remote code execution vulnerability in the SAY_MOOS variable…
MOOS-IvP iSay through 24.8.1 contains a remote code execution vulnerability in the SAY_MOOS variable handler that passes unsanitized text to a shell command. Attackers can publish SAY_MOOS messages containing backticks or command substitution syntax to execute arbitrary commands as the iSay process user.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85426] MOOS-IvP uMemWatch through 24.8.1 constructs shell commands from attacker-chosen MOOS client names w…
MOOS-IvP uMemWatch through 24.8.1 constructs shell commands from attacker-chosen MOOS client names without sanitization. Attackers can inject shell metacharacters into client names to execute arbitrary commands as the uMemWatch process user through unquoted redirection targets in system calls.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85223] A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functio…
A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Performing a manipulation of the argument callback_url/sync_interval results in os command injection. The attack can be initiated remotely. The exploit has been made public and could be used.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85224] A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part o…
A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executing a manipulation of the argument fileurl can lead to os command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85061] MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanit…
MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/dom.ts iterates elem.attributes as a live NamedNodeMap while removeAttributes() removes attributes from the same collection, shifting indexes and skipping an adjacent dangerous attribute. An attacker who controls untrusted third-party style attribution strings or user-supplied cust…
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85222] A vulnerability has been found in D-Link DNS-340L 1.01B04. Affected by this vulnerability is an unkn…
A vulnerability has been found in D-Link DNS-340L 1.01B04. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/addon_center.cgi of the component Add-On Center. Such manipulation of the argument f_name/f_url/f_flag/f_login_user leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85394] python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepti…
python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's public key can forge HS256 tokens that pass verification when algorithms are not explicitly restricted. This is an incomplete fix for CVE-2024-33663.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85391] Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows u…
Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use the published secret to mint valid tokens for arbitrary user IDs and access protected endpoints without credentials.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-82526] R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attacke…
R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL statements by manipulating the index name parameter in the vector index creation endpoint. The index name is interpolated directly into a CREATE INDEX statement via string formatting without identifier quoting or allowlist validation, enabling arbitrary DDL and DML execut…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85109] A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of…
A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of the file /boaform/formLogin of the component Boa Web Server. Executing a manipulation of the argument Username can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85154] WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a…
WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that grants full administrator session access to the video owner's account. Attackers who obtain a video_id_hash can replay it indefinitely to authenticate as the video owner with full privileges, and the credential remains valid even after the owner changes…
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85031] A vulnerability was found in TOTOLINK CP450 4.1.0. The impacted element is an unknown function of th…
A vulnerability was found in TOTOLINK CP450 4.1.0. The impacted element is an unknown function of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument topicurl results in buffer overflow. Remote exploitation of the attack is possible.
M Crítico vulnerabilidad
02/09/2026
Vulnerabilidad crítica en autenticación FIDO2 permite suplantación de identidad en despliegues locales
Una vulnerabilidad de puntuación CVSS 9.8 en sistemas FIDO2 permite a atacantes registrar credenciales maliciosas contra cuentas objetivo y autenticarse como el usuario legítimo. El riesgo afecta únicamente despliegues on-premises. Empresas en LATAM que implementen autenticación FIDO2 en infraestructura interna deben evaluar inmediatamente su exposición, especialmente en sectores financiero, gubernamental y de telecomunicaciones.
M Crítico vulnerabilidad
02/09/2026
Vulnerabilidad crítica en Submariner: inyección de configuración en modo cert-auth
Se identificó una falla en Submariner que permite inyección de configuración arbitraria en modo autenticación por certificados. Un cluster malicioso puede explotar esta vulnerabilidad publicando un CableName con saltos de línea y directivas de ipsec.conf sin validación previa, comprometiendo la seguridad de redes híbridas y multi-cluster. El impacto afecta directamente a empresas en LATAM con infraestructuras Kubernetes distribuidas en cloud público y privado.