Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 13 min
Buscando: "Ni" — 1487 resultados ✕ Limpiar búsqueda
22,340
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1210
Esta semana
RSS
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-77540] A malicious actor with access to the network and high privileges could exploit an Improper Input Val…
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute a Command Injection on the host device.
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-77533] A malicious actor with access to the network and low privileges could exploit an Improper Input Vali…
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-58096] LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the…
LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717. Undersized options would trigger an out-of-bounds write. A malicious PPP peer can exploit CVE-2026-58095 and CVE-2026-58096 to crash ppp(8) or potentially execute arbitrary code as root.
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-19632] The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulner…
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.1 via the 'trp_get_translations_regular' AJAX action. This makes it possible for unauthenticated attackers to extract the raw administrator password-reset URL — including the plaintext reset key and login parameters sto…
M Crítico vulnerabilidad
25/08/2026
Vulnerabilidad crítica de desbordamiento de búfer en TOTOLINK N600R 4.3.0cu.7647_B20210106
Se ha identificado una vulnerabilidad de desbordamiento de búfer en pila (stack-based buffer overflow) en el controlador CGI del router TOTOLINK N600R versión 4.3.0cu.7647_B20210106. La falla reside en la función setSystemConfig del archivo /cgi-bin/cstecgi.cgi y puede ser explotada remotamente manipulando el parámetro Hostname. Con CVSS 10.0, esta vulnerabilidad permite ejecución de código remoto sin autenticación y afecta a equipos de red en empresas, ISPs y centros de datos en toda Latinoamérica.
M Crítico vulnerabilidad
25/08/2026
Vulnerabilidad crítica de traversal de directorios en DB-GPT permite ejecución de código remoto
DB-GPT construye rutas de destino para habilidades cargadas usando nombres de archivo sin validación, permitiendo ataques de traversal de directorios. Un atacante puede escribir archivos fuera del directorio designado e inyectar código malicioso. Afecta infraestructuras de IA/ML en empresas mexicanas y latinoamericanas que utilizan esta plataforma para procesamiento de datos.
G Crítico vulnerabilidad
25/08/2026
[CVE-2026-78935] Use of uninitialized variable in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a …
Use of uninitialized variable in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
25/08/2026
Vulnerabilidad crítica de escape de sandbox en NVIDIA OpenShell para Linux (CVE-2026-65093)
NVIDIA OpenShell para Linux contiene una vulnerabilidad que permite a atacantes escapar del sandbox e ejecutar código arbitrario con privilegios elevados. El impacto incluye ejecución remota de código, escalada de privilegios, manipulación de datos y divulgación de información sensible. Empresas en LATAM que utilicen OpenShell en entornos containerizados o de virtualización deben considerar este vector de alto riesgo.
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-65083] NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attack…
NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, data tampering, and denial of service.
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-55546] QWED-MCP is a deterministic verification gateway for MCP. Prior to 0.2.1, verify_math_expression() i…
QWED-MCP is a deterministic verification gateway for MCP. Prior to 0.2.1, verify_math_expression() in src/qwed_mcp/engines/math_engine.py passes attacker-controlled expression and claimed_result strings directly to SymPy's parse_expr() after only normalizing caret syntax to Python exponent syntax, without restricting global_dict, removing Python built-ins, or validating the expression AST. Because…
M Crítico vulnerabilidad
25/08/2026
[CVE-2025-71407] Nokogiri before 1.18.3 contains a stack buffer overflow vulnerability in libxml2 when reporting DTD …
Nokogiri before 1.18.3 contains a stack buffer overflow vulnerability in libxml2 when reporting DTD validation errors with long QName prefixes, and a use-after-free vulnerability during validation against untrusted XML Schemas. Attackers can trigger these vulnerabilities by providing malicious DTD content or untrusted XSD files to cause denial of service or potential code execution.
M Crítico vulnerabilidad
25/08/2026
[CVE-2022-51000] Nokogiri before 1.13.2 (CRuby, when using packaged libraries) ships vendored libxml2 2.9.12 and libx…
Nokogiri before 1.13.2 (CRuby, when using packaged libraries) ships vendored libxml2 2.9.12 and libxslt 1.1.34, which are affected by two upstream CVEs. Via CVE-2021-30560 in libxslt, an application transforming XML with untrusted XSL stylesheets is vulnerable to a denial-of-service attack. Via CVE-2022-23308 in libxml2, an application parsing an untrusted document with parse option DTDVALID set t…
M Crítico vulnerabilidad
25/08/2026
Vulnerabilidad crítica de ejecución remota en NLTK anteriores a 3.10.3
NLTK versiones anteriores a 3.10.3 contienen una vulnerabilidad de ejecución remota de código (RCE) en cargadores pickle que confían en espacios de nombres completos en lugar de funciones seguras específicas. Atacantes pueden crear cargas pickle maliciosas invocando funciones peligrosas como ReppTokenizer._execute y numpy.f2py.crackfortran.myeval durante la carga de modelos o tokens, comprometiendo servidores de procesamiento de lenguaje natural en empresas de LATAM que procesen datos no verificados.
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-49845] SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on …
SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on all platforms allows authenticated users with access to Hive Metastore APIs to read, modify, or affect unintended partition metadata (including statistics updates, truncation targets, and file-metadata cache operations) via crafted partition names in metastore RPC requests when direct SQL is enabled…
M Crítico vulnerabilidad
25/08/2026
Vulnerabilidad crítica de escalada de privilegios en plugin Total Donations para WordPress (CVE-2026-78570)
El plugin Total Donations para WordPress (versiones hasta 2.0.5) contiene una vulnerabilidad de escalada de privilegios con puntuación CVSS 9.8 que permite a atacantes no autenticados obtener permisos de administrador. Esto afecta directamente a sitios de ONG, iglesias y organizaciones benéficas en LATAM que dependen de este plugin para recaudación de fondos. La explotación no requiere autenticación previa, aumentando significativamente el riesgo de compromisos totales del sitio.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-63586] The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Ba…
The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication username, taken directly from the Authorization header without sanitization, is inserted into a shell command string executed via the system() function. By submitting a specially crafted username containing shell metacharacters, an unauthenticated attacker with network access to t…
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-78477] The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and includ…
The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-78683] NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerabili…
NLTK before 3.10.0 (affected versions
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-56705] Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowi…
Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write PHP code to the web root, achieving remote code execution when the trace file is accessed.
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-77915] rConfig 8.0.0 before 8.2.13 contains an authentication bypass vulnerability that allows unauthentica…
rConfig 8.0.0 before 8.2.13 contains an authentication bypass vulnerability that allows unauthenticated attackers to self-register accounts with full Administrator privileges due to a duplicate bare Auth::routes() call in routes/web.php that re-enables the POST /register route after it was explicitly disabled. Attackers can register a new account that is immediately authenticated with Admin-level …