Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
Buscando: "X" — 3563 resultados ✕ Limpiar búsqueda
22,340
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1208
Esta semana
RSS
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-89857] In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Hold qpair lock …
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject qla_nvme_ls_reject_iocb() allocates from and advances the request ring through __qla2x00_alloc_iocbs() (which assumes the hardware_lock is held) and qla2x00_start_iocbs() (which advances the ring and rings the request-in doorbell), but takes no lock itself. Two of its ca…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-89846] In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Bound rsp_info_l…
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read In qla2x00_status_entry(), the FWI2 status path advances sense_data and shrinks par_sense_len by rsp_info_len: if (IS_FWI2_CAPABLE(ha)) { sense_data += rsp_info_len; par_sense_len -= rsp_info_len; } rsp_info_len is a 32-bit value taken directly from the targe…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-89847] In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Avoid double com…
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Avoid double completion in async IOCB timeout qla2x00_async_iocb_timeout() tries to abort a timed-out async IOCB. When qla24xx_async_abort_cmd() fails, both the SRB_LOGIN_CMD path and the SRB_CTRL_VP/default path scan outstanding_cmds[] for the SRB and then call sp->done(sp, QLA_FUNCTION_TIMEOUT) unconditionally, …
M Crítico vulnerabilidad
16/09/2026
CVE-2026-86106: Ejecución remota no autenticada en unidades Edge con Alta Disponibilidad
Una vulnerabilidad crítica (CVSS 9.6) permite a actores no autenticados con acceso a la interconexión privada de HA activar funciones sensibles sin verificación, resultando en ejecución de comandos elevados en unidades Edge donde HA está habilitada. Afecta principalmente a infraestructuras de borde en centros de datos y cloud híbrido en LATAM.
M Crítico vulnerabilidad
16/09/2026
Vulnerabilidad crítica en Arista EOS con P4Runtime permite ejecución remota de código
Una vulnerabilidad de puntuación CVSS 10 en Arista EOS permite que clientes no autenticados ejecuten código arbitrario con privilegios administrativos en switches configurados con P4Runtime. Aunque P4Runtime está deshabilitado por defecto, equipos que lo han activado para programabilidad de red enfrentan riesgo crítico. Esta falla afecta especialmente a proveedores de servicios y operadores de centros de datos en Latinoamérica que utilizan infraestructura Arista.
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-89786] In the Linux kernel, the following vulnerability has been resolved: ext4: fix out-of-bounds read in…
In the Linux kernel, the following vulnerability has been resolved: ext4: fix out-of-bounds read in ext4_read_inline_dir() ext4_read_inline_dir() can read a dirent header past the end of its inline buffer, triggering a slab-out-of-bounds read during getdents64(): BUG: KASAN: slab-out-of-bounds in __ext4_check_dir_entry Read of size 2 at addr ffff88800f3dd23c by task exploit/148 ... __…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-89788] In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix tree connection use-…
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix tree connection use-after-free in smb2_tree_connect() ksmbd_tree_conn_connect() publishes a new tree connection in sess->tree_conns with a single reference and returns its pointer to smb2_tree_connect(). The handler continues to initialize the object and build the response after publication. A concurrent session logof…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-89778] In the Linux kernel, the following vulnerability has been resolved: isofs: fix out-of-bounds page a…
In the Linux kernel, the following vulnerability has been resolved: isofs: fix out-of-bounds page array access on empty zisofs block zisofs_uncompress_block()'s empty-block fast path returns pcount
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-89779] In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate ef->size cov…
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate ef->size covers the record's name and value When an EA record has a non-zero ef->size, ntfs_read_ea() only checks that the record fits in the remaining buffer (ea_size > bytes), not that ef->size is large enough to hold the record's own name_len + 1 + elength. A crafted image can pass validation with, e.g., e…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-89783] In the Linux kernel, the following vulnerability has been resolved: xfrm6: fix out-of-bounds write …
In the Linux kernel, the following vulnerability has been resolved: xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full The depth check in xfrm6_input_addr() is off by one: if (1 + sp->len == XFRM_MAX_DEPTH) goto drop; ... sp->xvec[sp->len++] = x; xfrm_input() can leave sp->len == XFRM_MAX_DEPTH, and the transport-mode receive path re-enters IPv6 input via…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-89775] In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Handle negative S1 …
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation Computing the effects of a TLB invalidation involves looking at the size of the mapping cached by the TLB. For S1 mappings such as VNCR, this is deducted from the combination of the base granule size and the mapping level. However, this implies that the S1 M…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-27565] An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell…
An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges. The shell script remains active even after a reboot.
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-27546] An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function…
An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured.
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-73447] A privileged attacker can exploit certain operation to execute arbitrary commands with root privileg…
A privileged attacker can exploit certain operation to execute arbitrary commands with root privileges, leading to full device compromise. An authenticated user can exploit gRPC Network Security Interface (gNSI) Certz service on Arista EOS-based products to escalate privileges and execute arbitrary OS commands via a crafted Certz Rotate request. The Bootz service is also affected.
? Crítico alerta
16/09/2026
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA emite alerta de seguridad: CISA Adds Two Known Exploited Vulnerabilities to Catalog. CVEs relacionados: CVE-2026-76460, CVE-2026-87886.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
? Crítico alerta
16/09/2026
CISA Adds One Known Exploited Vulnerability to Catalog
CISA emite alerta de seguridad: CISA Adds One Known Exploited Vulnerability to Catalog. CVEs relacionados: CVE-2026-58704.
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-12793] The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Esc…
The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.6.2. This is due to the plugin not validating that a submitted form ID belongs to a JetFormBuilder form before parsing the referenced post's content as form schema and executing an Advanced Validation server-side callback. This makes it possible for un…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-81855] A hardcoded cryptographic client authentication key vulnerability exists in the robot testing framew…
A hardcoded cryptographic client authentication key vulnerability exists in the robot testing framework component of Wärtsilä FOS-Onboard.
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-78225] A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller compo…
A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller component of Wärtsilä FOS-Onboard.
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-61560] `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version 2.1.27, the S…
`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version 2.1.27, the SSE transport mode (`SSE=true`) exposes all MCP tools without any authentication. The `upload_markdown` tool reads arbitrary files from the server's local filesystem via an unsanitized `file_path` parameter and uploads them to a GitLab project. Combined, any unauthenticated network-reachable attacker…