Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "X" — 2319 resultados ✕ Limpiar búsqueda
13,566
Total alertas
3081
Críticas
10213
Altas
8
Ransomware
1780
Esta semana
RSS
M Crítico vulnerabilidad
04/08/2026
[CVE-2026-70552] MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher…
MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints by supplying any X-Requested-With header and requesting a base64-encoded path resolving to any *-ajax.php file in the codebase. Attackers can exploit this dispatcher bypass to reach privileged plugin endpoints without credentials…
M Crítico vulnerabilidad
04/08/2026
[CVE-2026-49435] Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauth…
Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet and execute arbitrary code with administrative privileges.
M Crítico vulnerabilidad
04/08/2026
[CVE-2026-0163] In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. Th…
In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
M Crítico vulnerabilidad
04/08/2026
[CVE-2017-20241] Keysight IxChariot Endpoint before 9.5.102 contains a heap-based buffer overflow. An unauthenticated…
Keysight IxChariot Endpoint before 9.5.102 contains a heap-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpoint or potentially execute arbitrary code.
M Crítico vulnerabilidad
04/08/2026
[CVE-2017-20242] Keysight IxChariot Endpoint before 9.5.102 contains a stack-based buffer overflow. An unauthenticate…
Keysight IxChariot Endpoint before 9.5.102 contains a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpoint or potentially execute arbitrary code.
M Crítico vulnerabilidad
04/08/2026
[CVE-2026-24254] NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attack…
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
M Crítico vulnerabilidad
04/08/2026
[CVE-2026-63455] Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow…
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target system.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
04/08/2026
[CVE-2026-63456] Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow…
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target system.
M Crítico vulnerabilidad
04/08/2026
[CVE-2025-29296] H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R0…
H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100R016, and H3C NE36 Pro V100R002 contain multiple command injection vulnerabilities in the /api/esps request handler. The affected object interfaces and methods are esps.dhcpd.vlan (getlist, delete), esps.filter.url (add, modify), esps.apcm.version (de…
M Crítico vulnerabilidad
04/08/2026
[CVE-2026-69098] kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection e…
kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ field. Attackers can exploit this to override the __type__ field with subprocess.check_output and arbitrary arguments, achieving remote code execution with appli…
M Crítico vulnerabilidad
04/08/2026
[CVE-2026-25289] Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Disco…
Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.
M Crítico vulnerabilidad
04/08/2026
[CVE-2026-61514] Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability t…
Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthenticated attackers to access device functions by sending protocol-conforming packets over TCP port 23456 without credentials. Attackers can exploit the unvalidated Session field in the proprietary control protocol header to access live video streams, control pan and tilt motors, ac…
M Crítico vulnerabilidad
04/08/2026
[CVE-2026-61515] Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vul…
Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by sending a crafted JSON payload to the DebugShell interface exposed on TCP port 34567. Attackers can exploit the lack of authentication and input sanitization in the binary protocol service to pass arbitrary com…
M Crítico vulnerabilidad
04/08/2026
Vulnerabilidad crítica en HUMANIST Digital Human Resources por clave criptográfica codificada
Se detectó una vulnerabilidad de severidad alta (CVSS 9.1) en HUMANIST Digital Human Resources versiones 26.0 anteriores a 26.1, que permite a atacantes leer constantes sensibles dentro del ejecutable mediante claves criptográficas hardcodeadas. Esto expone credenciales y datos confidenciales de recursos humanos en empresas de México y LATAM. La vulnerabilidad afecta principalmente a organizaciones que usan este sistema para gestión de nómina y personal.
M Crítico vulnerabilidad
04/08/2026
Vulnerabilidad crítica en HUMANIST Digital Human Resources: almacenamiento en texto plano e inyección SQL
HUMANIST Digital Human Resources (versiones 26.0 a 26.0.x) contiene una vulnerabilidad crítica (CVSS 9.8) que permite el almacenamiento de información sensible en texto plano y inyección SQL. Esta falla afecta directamente sistemas de gestión de recursos humanos en empresas LATAM, exponiendo credenciales, datos de nómina y información personal de empleados. La vulnerabilidad es explotable remotamente sin autenticación previa.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
04/08/2026
Vulnerabilidad crítica de carga de archivos peligrosos en HUMANIST Digital Human Resources
HUMANIST Digital Human Resources (versiones 26.0 a 26.0.x) contiene una vulnerabilidad de carga sin restricciones que permite a atacantes subir shells web al servidor. Esta falla afecta directamente a departamentos de Recursos Humanos en México y LATAM que gestionen nómina y datos sensibles de empleados. El CVSS 9.8 indica riesgo crítico de compromiso total del sistema.
M Crítico vulnerabilidad
04/08/2026
Clave RSA estática incrustada en firmware afecta servidores Lighttpd (CVE-2026-18753)
Firmware de múltiples fabricantes contiene una clave privada RSA estática utilizada por el servidor web Lighttpd para terminación TLS. Su exposición permite a atacantes descifrar tráfico HTTPS, suplantar servidores y comprometer la confidencialidad e integridad de comunicaciones. Afecta especialmente infraestructuras de borde y dispositivos IoT en datacenters LATAM.
M Crítico vulnerabilidad
04/08/2026
Clave RSA privada incrustada en firmware afecta servidores Lighttpd (CVE-2026-18754)
El firmware de múltiples dispositivos contiene una clave RSA privada estática utilizada por el servidor web Lighttpd para terminación TLS. La exposición de esta clave permite a atacantes descifrar comunicaciones HTTPS, suplantar servidores y comprometer la confidencialidad e integridad de datos sensibles en tránsito. Impacta infraestructuras críticas y plataformas de comercio electrónico en LATAM que dependen de este servicio web.
M Crítico vulnerabilidad
04/08/2026
[CVE-2026-16618] The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking …
The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file content type while writing the file with the attacker-supplied extension into a publicly accessible directory, allowing unauthenticated users to upload executable PHP files and achieve remote code execution.
M Crítico vulnerabilidad
04/08/2026
[CVE-2026-15958] The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization check…
The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions that it also registers for unauthenticated users, allowing an unauthenticated attacker to list, download and upload arbitrary files across the connected Dropbox account and to read the connected account and administrator email addresses.