Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1054
Esta semana
RSS
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-93228] In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reject Write/Reply chu…
In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reject Write/Reply chunks with segcount 0 A peer can send a Write or Reply chunk whose segcount field is zero. xdr_check_write_chunk() only rejects segcount > rc_maxpages, so zero passes the range check, and xdr_inline_decode(stream, 0) returns the current (non-NULL) cursor without advancing. The function returns true a…
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-93207] In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Zero rpc_gss_wire_cred …
In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry svcauth_gss_decode_credbody() writes the caller's rpc_gss_wire_cred field by field and assigns gc_ctx.len only on the success tail. The caller storage is svcdata->clcred, which lives in the per-svc_rqst gss_svc_data and is reused across requests. Early decod…
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-81549] IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain se…
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of the X-Forwarded-Proto header.
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-97359] HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload h…
HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve remote code execution by embedding malicious template syntax in a filename. Attackers can craft a filename containing a closing template quoting sequence followed by an exec macro, which bypasses the authorization check in the dispatcher to exe…
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-97360] HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that …
HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has filesystem access outside the shared folder. Attackers can exploit the macro dispatcher's lack of authorization model combined with the path resolver's failure to confine absolute paths to …
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-19072] Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the …
Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each endpoint in the hunt. Although the field "compiled_collector_args" is an internal field, Velociraptor allowed the field to be set from a user API call. This allows another user who can schedule a hunt (minimal role of "investigator" ) to set the compiled VQL statements for the hun…
M Crítico vulnerabilidad
24/09/2026
Vulnerabilidad crítica de inclusión de archivos en Visual Composer Website Builder para WordPress
El plugin Visual Composer Website Builder para WordPress (versiones hasta 45.16.0) contiene una vulnerabilidad de inclusión local de archivos (LFI) que permite a atacantes no autenticados ejecutar código PHP arbitrario en el servidor. Esta falla afecta directamente a miles de sitios web en México y LATAM que utilizan este constructor visual, comprometiendo datos sensibles y permitiendo control total del servidor.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
24/09/2026
Vulnerabilidad crítica de autenticación en DIAEnergie permite bypass de acceso (CVE-2026-78308)
DIAEnergie anterior a versión 1.11.00.022 contiene una vulnerabilidad de autenticación impropia (CVSS 9.8) que permite a atacantes eludir controles de acceso sin credenciales válidas. Afecta directamente a operadores de infraestructura energética, distribuidoras y gestores de demanda en México y Latinoamérica. El riesgo es crítico en entornos de control industrial y sistemas SCADA.
M Crítico vulnerabilidad
24/09/2026
Vulnerabilidad crítica de Path Traversal en DIAEnergie anterior a versión 1.11.00.022
DIAEnergie es software utilizado en sistemas de gestión energética en empresas de servicios e infraestructura de LATAM. La vulnerabilidad de Path Traversal (CVSS 9.1) permite a atacantes acceder a archivos y directorios del sistema sin autorización, comprometiendo datos sensibles de clientes y operaciones críticas. Afecta versiones anteriores a 1.11.00.022.
? Crítico alerta
24/09/2026
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA emite alerta de seguridad: CISA Adds Two Known Exploited Vulnerabilities to Catalog. CVEs relacionados: CVE-2026-5430, CVE-2026-71362.
M Crítico vulnerabilidad
24/09/2026
Vulnerabilidad crítica en D-Link DIR-825 permite escritura fuera de límites
Se identificó una vulnerabilidad de severidad crítica (CVSS 9.8) en el enrutador D-Link DIR-825 versión 3.00b32, específicamente en la función tunnel_set_params del componente rp-l2tp. Un atacante remoto puede explotar el parámetro peer_hostname para ejecutar escritura fuera de límites de memoria, comprometiendo la integridad del dispositivo. Esta vulnerabilidad afecta principalmente infraestructuras de pequeñas y medianas empresas en LATAM que utilizan este modelo como gateway de acceso.
M Crítico vulnerabilidad
24/09/2026
Vulnerabilidad crítica de escalada de privilegios en plugin Paytium para WordPress
El plugin 'Paytium: Mollie payment forms & donations' para WordPress contiene una vulnerabilidad de escalada de privilegios (CVSS 9.8) en versiones hasta 5.0.3 que permite a atacantes eludir mecanismos de validación de firmas y obtener privilegios administrativos. Afecta directamente a tiendas de e-commerce, plataformas de donaciones y sistemas de pago integrados con Mollie en México y Latinoamérica.
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-89078] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 …
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to a double free issue when parsing a specially crafted regular expression in a CI/CD configuration.
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-93577] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 …
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to an integer overflow issue when compiling a specially crafted regular expression in a CI/CD configuration.
M Crítico vulnerabilidad
23/09/2026
[CVE-2026-93352] Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .ph…
Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extension is absent from the forbidden_extensions blocklist in config/mediable.php. The blocklist introduced to address CVE-2026-49972 includes phpt but omits pht, which Apache executes as PHP via the default FilesMatch directive on Debian and Ubuntu systems. An attacker can upload a .pht file tha…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
23/09/2026
[CVE-2026-6730] IBM Concert 1.0.0 through 3.0.0 is vulnerable to a buffer overflow, caused by improper bounds checki…
IBM Concert 1.0.0 through 3.0.0 is vulnerable to a buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.
M Crítico vulnerabilidad
23/09/2026
[CVE-2026-6928] IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed. This allows a…
IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed. This allows an attacker who can influence program execution or input may exploit this condition to corrupt memory, cause application crashes, or execute arbitrary code.
M Crítico vulnerabilidad
23/09/2026
[CVE-2026-6721] IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attacker can supply specially craft…
IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attacker can supply specially crafted input that is incorporated into OS commands, resulting in arbitrary command execution on the underlying system. Successful exploitation allows remote code execution with the privileges of the affected application.
M Crítico vulnerabilidad
23/09/2026
[CVE-2026-84719] A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplat…
A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory, unified_job_template, and credentials of each cloned node and fails to check the instance_groups (and execution_environment and labels) that were preserved from the original. A user with organization workflow-admin permiss…
M Crítico vulnerabilidad
23/09/2026
[CVE-2026-75884] A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist th…
A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only restricts automountServiceAccountToken, allowing injection of initContainers, serviceAccountName overrides, and projected service account token volumes. An AAP platform administrator can exploit this to escalate privileges to OpenShift namespace-level access and exfiltrate namespace secrets.