Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Multiple Vendors" — 3530 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Crítico vulnerabilidad
20/09/2026
[CVE-2026-93958] A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function syst…
A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used.
M Crítico vulnerabilidad
20/09/2026
[CVE-2026-94083] Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code…
Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This requires app-layer.protocols.doh2 to be enabled, which is the default in 8.x versions.
M Crítico vulnerabilidad
20/09/2026
[CVE-2026-94084] Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by r…
Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.
M Crítico vulnerabilidad
19/09/2026
Vulnerabilidad crítica de escape de sandbox en OpenPanel js-runtime (CVE-2026-93985)
OpenPanel js-runtime contiene una vulnerabilidad de escape de sandbox (CVSS 9.9) en el validador de plantillas webhook de JavaScript que permite a atacantes con acceso de escritura al proyecto ejecutar código arbitrario mediante notación de propiedad computada para acceder a la cadena de constructores. Esta falla afecta principalmente a empresas que utilizan OpenPanel para orquestación de aplicaciones y webhooks en entornos críticos de México y Latinoamérica.
M Crítico vulnerabilidad
19/09/2026
[CVE-2026-78030] DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm att…
DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value names a module. require treats a path-shaped string as a literal filename and does not consult @INC, so the attribute chooses the file that Perl loads and runs. The MLDBM::…
M Crítico vulnerabilidad
19/09/2026
Vulnerabilidad crítica de inyección de comandos en Totolik A3002MU
Se ha identificado una debilidad en el enrutador Totolik A3002MU versión Hh-B20211125.1046 que permite inyección de comandos remotos a través del parámetro localPin en la función formWsc del archivo /boafrm/formWsc. La vulnerabilidad tiene puntuación CVSS 9.9 (crítica) y ya cuenta con exploits públicamente disponibles, exponiendo a empresas en LATAM que utilizan este dispositivo a acceso no autorizado e infiltración de redes.
M Crítico vulnerabilidad
19/09/2026
[CVE-2026-86591] The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its…
The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to update arbitrary WordPress options with arbitrary values, which could lead to privilege escalation and a full site takeover. The same route also allows unauthenticated users to store arbitrary web scripts which are then executed on every page of the si…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
19/09/2026
Vulnerabilidad crítica de desbordamiento de búfer en router Totolink A3002MU
Se ha descubierto una falla de seguridad crítica (CVSS 10.0) en el router Totolik A3002MU versión Hh-B20211125.1046 que permite desbordamiento de búfer remoto a través del parámetro submit-url en la función formWlWds. El exploit está disponible públicamente, aumentando significativamente el riesgo de compromiso en infraestructuras de pequeñas y medianas empresas en Latinoamérica que utilizan este dispositivo como gateway de red.
M Crítico vulnerabilidad
19/09/2026
Vulnerabilidad crítica en plugin Forminator para WordPress permite ejecución arbitraria de shortcodes
El plugin Forminator Forms para WordPress (versiones hasta 1.57.2) es vulnerable a ejecución arbitraria de shortcodes debido a validación insuficiente en la función do_shortcode. Atacantes no autenticados pueden ejecutar código malicioso en sitios web afectados, comprometiendo la integridad de formularios de contacto y pago. Esta vulnerabilidad impacta directamente a empresas en LATAM que utilizan este plugin en formularios críticos de recolección de datos y procesamiento de pagos.
M Crítico vulnerabilidad
19/09/2026
Vulnerabilidad crítica en WP Recipe Maker: ejecución arbitraria de shortcodes en WordPress
El plugin WP Recipe Maker para WordPress (versiones hasta 10.8.1) permite la ejecución arbitraria de shortcodes a través del campo reviewBody en metadatos de recetas. Un atacante puede inyectar código malicioso mediante comentarios que se procesan sin sanitización adecuada, comprometiendo sitios web de empresas, blogs corporativos y plataformas de contenido culinario en LATAM. El impacto afecta la integridad del contenido y puede derivar en acceso no autorizado a datos sensibles.
M Crítico vulnerabilidad
19/09/2026
Vulnerabilidad crítica de carga arbitraria de archivos en Gravity Forms para WordPress (CVE-2026-84434)
El plugin Gravity Forms para WordPress es vulnerable a carga arbitraria de archivos en versiones hasta 3.1.0.4. Un defecto en la validación de extensiones permite eludir controles de seguridad en campos ocultos de carga, exponiendo servidores a ejecución de código remoto. Afecta principalmente a empresas, agencias digitales y e-commerce en LATAM que dependen de formularios de contacto y recopilación de datos en WordPress.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-75885] A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/d…
A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Request Forgery (SSRF), where the console pod makes requests to internal services and reflects partial responses to the attacker. Additionally, by sending repeated large requests withou…
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-93739] A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function form…
A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation of the argument submit-url can lead to buffer overflow. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-93740] A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formW…
A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-93738] A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSched…
A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boafrm/formSchedule. Performing a manipulation of the argument webpage results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been made public and could be used.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-93839] LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket…
LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation. Attackers can disclose full user prompts routed to their socket, trigger denial of service by replacing legitimate nodes, or make the PD Master issue requests to int…
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-84075] IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due …
IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authentication for the ChangeTrackerServlet.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-84078] IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the Loa…
IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An unauthenticated user can access privileged load-balancer operations, potentially resulting in unauthorized actions and impact to the integrity and availability of the affected system.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-84082] IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands du…
IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-84031] IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary c…
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.