Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 3 min
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-93088] SGLang's multimodal generation runtime is vulnerable to unauthenticated arbitrary code execution bec…
SGLang's multimodal generation runtime is vulnerable to unauthenticated arbitrary code execution because the disaggregated-diffusion orchestrator's DiffusionServer binds an unauthenticated ZeroMQ ROUTER socket to a network interface and passes the final frame of received multipart messages directly to pickle.loads() before any validation occurs.
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-84388] A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Ext…
A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4 all versions may allow attacker to information disclosure via remote unauthenticated attack
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-79313] webpy web.py 0.76 is vulnerable to Insufficient Session Expiration. The application's session manage…
webpy web.py 0.76 is vulnerable to Insufficient Session Expiration. The application's session management relies on periodic cleanup to expire sessions instead of checking the last-access time when a session is loaded. As a result, an expired session whose record has not yet been cleaned up can still be replayed and used, allowing an attacker holding a previously valid session cookie to continue ac…
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-65113] NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause us…
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of hard-coded credentials. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, denial of service, and information disclosure.
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-95675] D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code execution …
D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted requests to the device's web management interface without valid credentials. Attackers can fully compromise the device to persistently modify its configuration and use it as a pivot point into the loc…
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-12718] Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i…
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Karel Electronic Industry and Trade Inc. KarelIPS allows Blind SQL Injection. This issue affects KarelIPS: through 22092026. NOTE: The vendor was contacted and it was learned that the product is not supported.
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-93616] A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and…
A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
22/09/2026
Vulnerabilidad crítica de ejecución remota de código en Zohocorp ManageEngine ADSelfService Plus (CVE-2026-74849)
Zohocorp ManageEngine ADSelfService Plus en versiones anteriores a la build 7001 presenta una vulnerabilidad de ejecución remota de código (RCE) con CVSS 9.8 en el cliente GINA. Esta falla permite a atacantes ejecutar comandos arbitrarios sin autenticación previa, afectando principalmente a empresas en LATAM que utilizan esta solución para gestión de identidades y acceso en entornos Active Directory. El impacto es crítico en infraestructuras de TI medianas y grandes.
M Crítico vulnerabilidad
22/09/2026
CVE-2026-25254: Autorización deficiente permite Ejecución Remota de Código vía SocketIO
Una vulnerabilidad crítica (CVSS 9.8) en la interfaz SocketIO de múltiples productos permite a atacantes ejecutar código remoto explotando controles de autorización inadecuados. Este vector afecta principalmente servidores web y aplicaciones en tiempo real expuestas en LATAM. La exposición es inmediata si los sistemas están conectados a internet sin restricciones de acceso.
M Crítico vulnerabilidad
22/09/2026
Vulnerabilidad crítica en VeloCloud Orchestrator (VCO) on-prem permite acceso remoto no autorizado
VeloCloud Orchestrator (VCO) on-prem contiene una vulnerabilidad crítica (CVSS 10.0) que permite a atacantes remotos acceder a funcionalidades internas privilegiadas y comprometer la integridad del orquestador. La explotación exitosa impacta confidencialidad, integridad y disponibilidad de datos gestionados. Versiones hosted y dedicadas fueron afectadas, con implicaciones directas para proveedores de conectividad SD-WAN en México y LATAM que dependen de VCO para operaciones críticas.
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-87078] Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the output buffer on every rejecte…
Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the output buffer on every rejected label in decode_punycode. The XS backend allocates the scalar it returns before it validates the input, sizing the buffer at twice the input length. The scalar is released only on the success path, so each of the three croaks that reject a label leaves the scalar and its buffer allocated. Nothing…
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-87080] Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name containing …
Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name containing a character it never encoded in decode_punycode. The pure-Perl decoder reads one digit at a time with four-argument substr and tests the result with defined to detect the end of the input. substr on an exhausted string returns the empty string rather than undef, so decoding continues past the end. …
M Crítico vulnerabilidad
22/09/2026
[CVE-2016-15059] Net::IDN::Punycode versions before 2.301 for Perl allow a heap buffer overflow via unchecked writes …
Net::IDN::Punycode versions before 2.301 for Perl allow a heap buffer overflow via unchecked writes past the output buffer in encode_punycode. The XS backend builds the encoded label in the string buffer of the scalar it returns, sized from the input length. The loop that emits the digits of each code point checks for room before every write, but the write of the last digit of each round and the …
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-19658] The Give Tributes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, …
The Give Tributes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.3.1 via deserialization of untrusted input . This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is i…
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-13355] The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to Administrator in vers…
The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 3.11.0. This is due to a chained flaw: the populate_via_query_string() function in the mb-frontend-submission component unconditionally overrides the form's target object_id from the GET parameter 'rwmb_frontend_field_object_id' without any authorization check, and Form::p…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-94493] A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unkno…
A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unknown processing of the file /index.html of the component WebSocket Service. The manipulation results in missing authentication. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Crítico vulnerabilidad
21/09/2026
[CVE-2026-79916] MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.5-lts, authenticated workspace me…
MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.5-lts, authenticated workspace members can inject control characters into AWS Bedrock access_key_id and secret_access_key fields that _update_aws_credentials writes to /root/.aws/credentials without safe parsing. An attacker can append a new AWS profile containing credential_process, then select that profile during a later model-va…
M Crítico vulnerabilidad
21/09/2026
[CVE-2026-77521] MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a …
MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool, skill, or sub-application use SandboxShellBackend, which exposes an execute shell tool without excluding it and omits execute from interrupt_on, so human approval is not required. Untrusted chat or ingested content can therefore cause command execution; source deployments with MAXKB_…
M Crítico vulnerabilidad
21/09/2026
[CVE-2026-58491] Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.5, the /@warpg…
Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.5, the /@warpgate/api/sso/providers/:name/start endpoint stores an attacker-controlled next parameter that the POST /@warpgate/api/sso/return handler inserts without HTML escaping into the response generated by warpgate-protocol-http/src/api/sso_provider_list.rs. A victim who follows a crafted link and completes …
M Crítico vulnerabilidad
21/09/2026
[CVE-2026-79920] Ajenti is a Linux & BSD modular server admin panel. Prior to version 2.2.16, any authenticated user …
Ajenti is a Linux & BSD modular server admin panel. Prior to version 2.2.16, any authenticated user can call /api/core/tasks/start to enqueue InstallPlugin, UnInstallPlugin, or UpgradeAll from plugins/plugins/tasks.py without plugin-management authorization. InstallPlugin and UnInstallPlugin construct a pip package specification from unvalidated name and version fields, and the task worker invokes…