Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1052
Esta semana
RSS
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-10858] IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denia…
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer underflow when processing multi-segment messages.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-10747] IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute a…
IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.
M Crítico vulnerabilidad
18/09/2026
[CVE-2025-53837] XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki sy…
XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Prior to versions 14.10.2 and 15.0 RC1, any user who can edit their own user profile or any other document can execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestricted read and write …
M Crítico vulnerabilidad
18/09/2026
[CVE-2025-15399] IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 …
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-93603] vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the appl…
vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridge (lib/bridge.js): when sandboxed code calls a host-provided non-strict (sloppy-mode) function without a receiver — e.g. `fn()`, a detached method, `fn.call()`, `fn.apply(undefined)`, `Reflect.apply(fn, undefined, [])`, or `fn.bind()()` — the undefined receiver is passed straight …
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-93605] vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTIN…
vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-spawning modules. Attackers can require child_process and execute arbitrary commands on the host system when NodeVM is configured with builtin:['*'] or explicit child_process allowance.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-93606] vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedde…
vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host API that returns a host-realm Promise, the bridge's rejection sanitizer (hostPromiseSanitizeReject / makeSanitizedPromiseCallback / normalizeHostPromiseCallbacks in lib/bridge.js) only wraps `then`/`catch` rejection slots that hold a function, and the sandbox-side `Symbol.species`/`…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-93019] Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 327…
Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read. The reader unpacks the two-byte colour map length into a signed short, so a length of 32768 or more becomes negative. tga_palette_read() casts that value to size_t and asks mymalloc() for a size near SIZE_MAX. The allocation fails and Imager's allocator calls exit(3)…
M Crítico vulnerabilidad
18/09/2026
Vulnerabilidad crítica en Synology DiskStation Manager permite lectura/escritura de archivos arbitrarios
Una falla en la codificación de salida del componente SCGI en Synology DSM afecta versiones anteriores a 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 y 7.4-90075, permitiendo a atacantes remotos leer, modificar archivos arbitrarios y ejecutar ataques de negación de servicio. Empresas en LATAM que usan NAS Synology para almacenamiento centralizado están en riesgo inmediato de exposición de datos sensibles e interrupciones operativas.
M Crítico vulnerabilidad
18/09/2026
Vulnerabilidad crítica en Synology DiskStation Manager permite lectura/escritura de archivos arbitrarios
Se identificó una vulnerabilidad de entropía insuficiente en la lógica de autenticación de Synology DSM (versiones anteriores a 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 y 7.4-90075) que permite a atacantes remotos acceder, modificar archivos arbitrarios y ejecutar ataques de denegación de servicio sin credenciales válidas. Afecta directamente a servidores NAS en entornos corporativos, PyMES y centros de datos en LATAM que dependen de estos dispositivos para almacenamiento centralizado.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-67100] HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure fla…
HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject database commands to extract sensitive system details, as well as manipulate request values to gain unauthorized access to full personal profile data and PII across different organizations.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-67101] HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in i…
HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could allow an attacker to force the application server to send requests to internal systems that are not accessible from the internet.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-84738] The AF Companion WordPress plugin before 2.2.0 does not validate the type of files uploaded through…
The AF Companion WordPress plugin before 2.2.0 does not validate the type of files uploaded through one of its import features, allowing users with a low-privileged store-management role to upload arbitrary files, including PHP ones, leading to Remote Code Execution.
? Crítico alerta
18/09/2026
CISA Adds One Known Exploited Vulnerability to Catalog
CISA emite alerta de seguridad: CISA Adds One Known Exploited Vulnerability to Catalog. CVEs relacionados: CVE-2025-39682.
? Crítico alerta
18/09/2026
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA emite alerta de seguridad: CISA Adds Two Known Exploited Vulnerabilities to Catalog. CVEs relacionados: CVE-2025-39964, CVE-2026-53266.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-93467] The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote…
The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-85878] Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate pri…
Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-69843] Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate pri…
Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-62874] Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to e…
Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-85885] Improper neutralization of special elements used in a command ('command injection') in M365 Copilot …
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.