Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
Buscando: "Ni" — 890 resultados ✕ Limpiar búsqueda
13,539
Total alertas
3075
Críticas
10192
Altas
8
Ransomware
1756
Esta semana
RSS
B Crítico vulnerabilidad
05/06/2026
[CVE-2026-9270] DataDog::DogStatsd versions through 0.07 for Perl allow metric injections. DataDog::DogStatsd does …
DataDog::DogStatsd versions through 0.07 for Perl allow metric injections. DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from untrusted sources. The send_stats method does not remove newlines from metric names ($stat variable), allowing attackers to change the metric name prefix. The send_stats method does not validate the content of the value ($delta v…
M Crítico vulnerabilidad
05/06/2026
[CVE-2026-6274] Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerabi…
Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electronics Industry and Trade Ltd. Co. Redline WR3200 allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Redline WR3200: from 7.1.3 before 7.1.8.
? Crítico alerta
05/06/2026
CISA registra nueva vulnerabilidad explotada activamente (CVE-2026-28318)
La Agencia de Ciberseguridad e Infraestructura Crítica de EE.UU. (CISA) ha añadido a su catálogo de vulnerabilidades conocidas y explotadas activamente la CVE-2026-28318, indicando que esta brecha ya está siendo aprovechada por atacantes en entornos reales. Aunque no se especifica el producto afectado en el advisory, su inclusión en el catálogo implica riesgo inmediato para infraestructura crítica en México y Latinoamérica. Las organizaciones deben priorizar esta vulnerabilidad en sus ciclos de parchado.
M Crítico vulnerabilidad
05/06/2026
[CVE-2026-7762] A heap-based buffer overflow vulnerability in the dot11ah.ko HaLow Wi-Fi kernel driver in Morse Micr…
A heap-based buffer overflow vulnerability in the dot11ah.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attacker within radio range to cause a Denial of Service (kernel panic) or potentially achieve Remote Code Execution via a crafted 802.11ah beacon or probe response frame containing a malformed S1G Capabilities Information El…
M Crítico vulnerabilidad
05/06/2026
[CVE-2026-7763] A heap-based buffer overflow vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro …
A heap-based buffer overflow vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attacker within radio range to cause a Denial of Service (kernel panic) or potentially achieve Remote Code Execution via a crafted 802.11ah beacon frame containing a malformed Traffic Indication Map (TIM) Information Element. T…
G Crítico vulnerabilidad
04/06/2026
Vulnerabilidad crítica en Android OS (CVE-2026-11167) - CVSS 9.6
Google publicó un parche de seguridad para una vulnerabilidad crítica en Android OS con puntuación CVSS 9.6. La falla afecta más del 80% de dispositivos móviles en México y Latinoamérica, exponiendo sistemas corporativos y personales a explotación remota. Se recomienda actualización inmediata en todos los terminales.
G Crítico vulnerabilidad
04/06/2026
Vulnerabilidad crítica Use-After-Free en Android OS (CVE-2026-11131) - CVSS 9.6
Se ha identificado una vulnerabilidad de tipo Use-After-Free (UAF) en Android OS con puntuación CVSS 9.6, afectando más del 80% del parque de dispositivos móviles en México y Latinoamérica. Esta falla permite a atacantes ejecutar código arbitrario con privilegios elevados, comprometiendo la integridad de datos corporativos y personales. El parche está disponible a través de actualizaciones del sistema en todos los dispositivos Android.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
G Crítico vulnerabilidad
04/06/2026
Vulnerabilidad crítica en Android OS (CVE-2026-11082) - CVSS 9.6
Se ha identificado una vulnerabilidad crítica en Android OS con puntuación CVSS de 9.6 que afecta más del 80% de los dispositivos móviles en México y Latinoamérica. Esta falla de seguridad impacta directamente la confidencialidad, integridad y disponibilidad de datos en equipos corporativos y personales. Se recomienda aplicar parches de seguridad inmediatamente en todos los dispositivos.
M Crítico vulnerabilidad
04/06/2026
[CVE-2024-27892] Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when…
Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected. This can result in unexpected configuration being applied to the switch.
M Crítico vulnerabilidad
04/06/2026
[CVE-2024-27890] Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when…
Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected. This can result in unexpected configuration being applied to the switch.
M Crítico vulnerabilidad
04/06/2026
[CVE-2025-71316] SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Windows C runtime converts Unico…
SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Windows C runtime converts Unicode characters to ANSI codepages. An attacker could use the '-L' option to load an arbitrary DLL with a crafted command line argument string that results in command line file arguments being misinterpreted as command line options. Fixed on or around 2025-12-26.
N Crítico vulnerabilidad
04/06/2026
[CVE-2026-48040] The netty incubator codec.bhttp is a java language binary http parser. The library implements Oblivi…
The netty incubator codec.bhttp is a java language binary http parser. The library implements Oblivious HTTP (RFC 9458) using BoringSSL's HPKE C library via JNI. When deriving native memory addresses for cryptographic operations versions prior to 0.0.22.Final provide a fallback path for direct ByteBufs that do not expose their memory address through `hasMemoryAddress()`. This fallback occurs when …
M Crítico vulnerabilidad
04/06/2026
[CVE-2026-10880] OSNexus QuantaStor SDS Manager is vulnerable to SQL injection in the login endpoint. The username fi…
OSNexus QuantaStor SDS Manager is vulnerable to SQL injection in the login endpoint. The username field is not properly sanitized before being incorporated into a SQL query, allowing an unauthenticated remote attacker to bypass authentication and log in as an administrator without supplying a valid password.
M Crítico vulnerabilidad
04/06/2026
[CVE-2025-67447] The network diagnosis (ping) module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerabl…
The network diagnosis (ping) module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to OS command injection. The application does not properly sanitize user input in the IP address field before passing it to the system's ping command. An attacker can inject arbitrary OS commands, which will be executed with the privileges of the web server.
M Crítico vulnerabilidad
04/06/2026
[CVE-2026-43986] Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.1…
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose a public `/image/` route that resolves attacker-controlled entries from `image_hash_lookup` and replays them through the same server-side image fetch logic used by authenticated image proxying. A low-privilege guest user can seed a malicious external image URL into this lookup table…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
P Crítico vulnerabilidad
04/06/2026
[CVE-2026-8037] OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an u…
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints
M Crítico vulnerabilidad
04/06/2026
[CVE-2019-25738] WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vulnerability that allow…
WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vulnerability that allows unauthenticated attackers to modify WordPress options by exploiting the hc_ajax_save_option action. Attackers can send POST requests to the admin-ajax.php endpoint with the action parameter set to hc_ajax_save_option to enable user registration and set the default role to administrator, enabling a…
M Crítico vulnerabilidad
04/06/2026
[CVE-2019-25727] WordPress Plugin ad manager wd 1.0.11 contains an arbitrary file download vulnerability that allows …
WordPress Plugin ad manager wd 1.0.11 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensitive files by manipulating the path parameter. Attackers can send GET requests to the edit.php endpoint with export=export_csv and a malicious path parameter to read arbitrary files like wp-config.php accessible to the web server.
M Crítico vulnerabilidad
04/06/2026
[CVE-2019-25729] PDF Signer 3.0 contains a server-side template injection vulnerability that allows unauthenticated a…
PDF Signer 3.0 contains a server-side template injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP commands through the CSRF-TOKEN cookie parameter. Attackers can craft malicious cookie values containing template injection payloads like shell_exec() to execute system commands and retrieve sensitive information from the server.
A Crítico vulnerabilidad
04/06/2026
[CVE-2026-50225] The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious…
The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database.