Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Crítico vulnerabilidad
21/09/2026
[CVE-2026-85751] Mailu is a mail server distributed as a set of Docker images. From Mailu 2.0 until 2024.06.55 and pr…
Mailu is a mail server distributed as a set of Docker images. From Mailu 2.0 until 2024.06.55 and prior to Mailu helm-charts 2.7.3, deployments with PROXY_AUTH_WHITELIST configured but REAL_IP_HEADER unset trusted a client-controlled X-Forwarded-By header for header-based proxy authentication. The proxy_hide_header directive in the nginx template at core/nginx/conf/proxy.conf hid the header from u…
M Crítico vulnerabilidad
21/09/2026
[CVE-2026-94301] The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypa…
The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committed to the  2.2.X branch only. The 2.0.X and 2.1.X maintenance branches never received the resolveProxyClass() override, so the 2.0.29 and 2.1.13 artifacts listed a…
M Crítico vulnerabilidad
21/09/2026
[CVE-2026-86473] Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token co…
Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie. When a client logs out presenting its credential as an Authorization bearer header instead, the endpoint returns its normal logout response but revokes nothing, so the token remains valid until it expires. An attacker who already holds a copy of that token keeps the victim's access after the v…
M Crítico vulnerabilidad
21/09/2026
[CVE-2026-82187] The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extens…
The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extension of uploaded files, and hands the token protecting those uploads to any visitor who asks for it, allowing unauthenticated attackers to upload arbitrary files, including PHP ones, and run code on the server.
? Crítico alerta
21/09/2026
CISA Adds One Known Exploited Vulnerability to Catalog
CISA emite alerta de seguridad: CISA Adds One Known Exploited Vulnerability to Catalog. CVEs relacionados: CVE-2026-7273.
M Crítico vulnerabilidad
21/09/2026
Vulnerabilidad crítica de desbordamiento de búfer en Netcore NBR200V2 1.3.241127.071246
Se ha identificado una vulnerabilidad crítica (CVSS 9.9) en el enrutador Netcore NBR200V2 versión 1.3.241127.071246. La falla existe en la función vlan_load_form_uci del archivo /usr/bin/routerd, permitiendo un desbordamiento de búfer mediante manipulación del parámetro wan_num. El ataque es remoto, el exploit está públicamente disponible y el fabricante fue notificado previamente. Esta vulnerabilidad afecta directamente a infraestructuras de conectividad en empresas mexicanas y latinoamericanas que utilizan este dispositivo como gateway de red.
M Crítico vulnerabilidad
21/09/2026
Vulnerabilidad crítica de desbordamiento de búfer en Netcore NBR200V2 (CVE-2026-94100)
Se identificó una debilidad crítica (CVSS 9.9) en el enrutador Netcore NBR200V2 versión 1.3.241127.071246 que afecta la función wan_config_set_vlan del componente de reconfiguración VLAN WAN. Un atacante remoto puede manipular el parámetro vlan_wanX.ports para provocar un desbordamiento de búfer y potencialmente ejecutar código arbitrario. El exploit está disponible públicamente, aumentando significativamente el riesgo para dispositivos expuestos en redes corporativas e ISPs de la región.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
21/09/2026
[CVE-2026-94098] A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This vulnerability affects unk…
A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This vulnerability affects unknown code of the file /www/cgi-bin/upgrade of the component Firmware Upgrade CGI Endpoint. Such manipulation of the argument QUERY_STRING leads to command injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this di…
M Crítico vulnerabilidad
21/09/2026
[CVE-2026-94099] A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. This issue affects some u…
A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. This issue affects some unknown processing of the file restore.cgi of the component Backup Restore. Performing a manipulation of the argument QUERY_STRING results in command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was c…
M Crítico vulnerabilidad
21/09/2026
[CVE-2026-94095] A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vulnerability…
A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vulnerability is an unknown functionality of the file /usr/bin/network_tools of the component Traceroute Diagnostic Feature. The manipulation of the argument url leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacte…
M Crítico vulnerabilidad
21/09/2026
[CVE-2026-94096] A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by this issue is some unkn…
A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by this issue is some unknown functionality of the file /usr/bin/network_tools of the component LAN IP Configuration Handler. The manipulation of the argument ipv4 results in command injection. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this d…
M Crítico vulnerabilidad
21/09/2026
[CVE-2026-94097] A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part o…
A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file /www/cgi-bin/network_tools of the component CGI Diagnostic Endpoint. This manipulation of the argument param/key/val causes command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about t…
M Crítico vulnerabilidad
20/09/2026
[CVE-2026-94089] A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of…
A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authentication Handler. Executing a manipulation of the argument id/password can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
M Crítico vulnerabilidad
20/09/2026
[CVE-2026-90817] An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing a…
An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could potentially exploit it by manipulating HTTP requests to access an unintended controller route from a public survey context and by supplying a crafted file-path/stream parameter during import handling. If successfully exploited, this co…
M Crítico vulnerabilidad
20/09/2026
Vulnerabilidad crítica de desbordamiento de búfer en Comfast CF-N1-S 2.6.0.1
Se ha identificado una vulnerabilidad crítica (CVSS 10.0) en los routers Comfast CF-N1-S versión 2.6.0.1 que afecta la interfaz web de gestión. Un desbordamiento de búfer en la función get_css_path_from_uri del archivo /cgi-bin/mbox-config permite a atacantes remotos ejecutar código arbitrario sin autenticación. La vulnerabilidad ha sido divulgada públicamente y explotada activamente.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
20/09/2026
[CVE-2026-93958] A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function syst…
A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used.
M Crítico vulnerabilidad
20/09/2026
[CVE-2026-94083] Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code…
Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This requires app-layer.protocols.doh2 to be enabled, which is the default in 8.x versions.
M Crítico vulnerabilidad
20/09/2026
[CVE-2026-94084] Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by r…
Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.
M Crítico vulnerabilidad
19/09/2026
Vulnerabilidad crítica de escape de sandbox en OpenPanel js-runtime (CVE-2026-93985)
OpenPanel js-runtime contiene una vulnerabilidad de escape de sandbox (CVSS 9.9) en el validador de plantillas webhook de JavaScript que permite a atacantes con acceso de escritura al proyecto ejecutar código arbitrario mediante notación de propiedad computada para acceder a la cadena de constructores. Esta falla afecta principalmente a empresas que utilizan OpenPanel para orquestación de aplicaciones y webhooks en entornos críticos de México y Latinoamérica.
M Crítico vulnerabilidad
19/09/2026
[CVE-2026-78030] DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm att…
DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value names a module. require treats a path-shaped string as a literal filename and does not consult @INC, so the attribute chooses the file that Perl loads and runs. The MLDBM::…