Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "X" — 3563 resultados ✕ Limpiar búsqueda
22,345
Total alertas
4745
Críticas
16970
Altas
8
Ransomware
1213
Esta semana
RSS
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-55209] resdata is software for reading and writing result files from the Eclipse reservoir simulator. Prior…
resdata is software for reading and writing result files from the Eclipse reservoir simulator. Prior to 6.2.9, resdata insufficiently validates numeric fields, grid dimensions, keyword sizes, and array indexes while parsing untrusted GRDECL files in lib/resdata/rd_kw_grdecl.cpp and lib/resdata/rd_grid.cpp. Malformed COORD, ZCORN, CORSNUM, ACTNUM, or MAPAXES data can reach rd_grid_alloc_GRDECL_kw__…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-54334] UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file sys…
UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Prior to 1.14, ReadCLen() in uefi_firmware/compression/Tiano/Decompress.c reads Number from GetBits(Sd, CBIT) with CBIT = 9 and can obtain 511 entries for the 510-element Sd->mCLen heap array because its loop does not enforce Index < NC. The CharC == 2 run-length path can additional…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-54333] UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file sys…
UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Prior to 1.14, MakeTable() in uefi_firmware/compression/Tiano/Decompress.c does not validate that bit-length values read from a crafted Tiano or EFI compressed firmware bitstream remain within the expected range from 0 through 16. The normal CompressedSection.process() to efi_compre…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-90945] Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be over…
Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid administrator tokens to access administrative APIs and execute code on worker nodes.
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-90942] Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /…
Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it. Attackers can use the exposed private key to forge JWT tokens for any user in any organization, including global administrators.
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-76461] A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could …
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that co…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-57131] PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts pr…
PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts praisonai.jobs.router.create_router under /api/v1/runs without authentication or per-job authorization. Network clients can submit attacker-controlled prompts and agent configuration, list and read jobs, stream results, and cancel or delete other jobs, exposing service credentials and connected tool c…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-57124] PraisonAI is a multi-agent teams system. Prior to 4.6.59, the default UI host applications expose PO…
PraisonAI is a multi-agent teams system. Prior to 4.6.59, the default UI host applications expose POST /api/mcp/connect without mandatory authentication and accept caller-controlled command and args values that PraisonAIUI passes to StdioMCPClient to start a local process. Because the UI commands bind to 0.0.0.0 by default, a reachable unauthenticated client can execute commands as the UI service …
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-57127] PraisonAI is a multi-agent teams system. Prior to 4.6.58, recipe serve installs APIKeyAuthMiddleware…
PraisonAI is a multi-agent teams system. Prior to 4.6.58, recipe serve installs APIKeyAuthMiddleware or JWTAuthMiddleware when an operator selects api-key or JWT authentication, but each middleware forwards requests when PRAISONAI_API_KEY or PRAISONAI_JWT_SECRET and the corresponding recipe value are absent. Unauthenticated clients can then reach recipe execution, input, and output surfaces and ma…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-57125] PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.59 and praisonaiagents 1.6.59, the u…
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.59 and praisonaiagents 1.6.59, the unauthenticated POST /api/v1/runs Jobs API accepts attacker-controlled agent_yaml, and the approve field can mark execute_command as YAML-approved before @require_approval checks critical tools. This chain allows a remote caller to cause a configured language model agent to invoke arbitrary operating…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-90937] froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowi…
froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives. Attackers can supply URLs containing literal newlines that are written verbatim into vhost config files during cron rebuild, enabling web server configuration corruption, denial of service, or hijacking of HTTP …
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-77051] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i…
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized entityKey and opEvent parameters. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-78299] In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS p…
In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extraction can extract files to locations outside of the pack, allowing writing of arbitrary files to other locations on disk.
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-75030] Missing Authorization vulnerability in Apache Syncope. An administrator with task execution entit…
Missing Authorization vulnerability in Apache Syncope. An administrator with task execution entitlements might be able to mass (de)provision group members, regardless of their group-related administration capabilities. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.…
M Crítico vulnerabilidad
14/09/2026
Vulnerabilidad crítica de ejecución remota de código en LightLLM hasta versión 1.2.0
LightLLM versiones anteriores a 1.2.1 contiene una vulnerabilidad de ejecución remota de código (RCE) en el endpoint WebSocket /visual_register del Config Server sin autenticación. Un atacante con acceso a la red puede enviar un payload malicioso serializado con método __reduce__ a pickle.loads() para ejecutar código arbitrario con privilegios del proceso Config Server. Este riesgo afecta directamente a infraestructuras de IA/ML en empresas de México y LATAM que ejecuten LightLLM en entornos de producción o desarrollo expuestos a la red interna o internet.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-82232] Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i…
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized sort clauses for Task search. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-86460] Cypher injection vulnerability in the Neo4j persistence layer when processing some FIQL search condi…
Cypher injection vulnerability in the Neo4j persistence layer when processing some FIQL search conditions. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-87802] Improper verification of cryptographic signature vulnerability in Apache Syncope. When SRA is con…
Improper verification of cryptographic signature vulnerability in Apache Syncope. When SRA is configured for OAuth 2.0 without JWKS set URI assigned, an attacker can forge arbitrary JWTs to impersonate any user identity and permissions, gaining full access to services proxied by SRA. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 thr…
M Crítico vulnerabilidad
14/09/2026
Inyección de comandos OS en D-Link DWR-M921 1.1.52 permite ejecución remota
Se ha identificado una vulnerabilidad crítica (CVSS 9.1) en el router D-Link DWR-M921 versión 1.1.52 que permite inyección de comandos del sistema operativo a través de la función /boafrm/formDiskFormat. Un atacante remoto puede manipular el parámetro 'partition' para ejecutar comandos arbitrarios sin autenticación. El exploit está publicado y activamente en uso.
M Crítico vulnerabilidad
14/09/2026
Inyección de comandos OS en D-Link DWR-M921 versión 1.1.52 (CVE-2026-90703)
Se ha identificado una vulnerabilidad crítica (CVSS 9.1) en el router D-Link DWR-M921 1.1.52 que permite inyección de comandos del sistema operativo a través del parámetro folderpath en la función de creación de comparticiones de disco. El ataque es remotamente exploitable y el exploit público ya circula en la comunidad de seguridad. Esta vulnerabilidad afecta principalmente a PyMES y empresas en LATAM que utilizan estos equipos como gateways de red.