Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 24 min
Buscando: "X" — 3563 resultados ✕ Limpiar búsqueda
22,345
Total alertas
4745
Críticas
16970
Altas
8
Ransomware
1213
Esta semana
RSS
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-81048] Dell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutralization of Special Elemen…
Dell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote Code execution
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-88877] Traefik is a HTTP reverse proxy and load balancer. In versions >= v3.7.0 and <= v3.7.11, the Kuberne…
Traefik is a HTTP reverse proxy and load balancer. In versions >= v3.7.0 and
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-88869] AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scriptin…
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the AD_Server plugin's log.php endpoint that fails to escape the label parameter before storage. An unauthenticated attacker can inject malicious HTML through the label parameter, which is later rendered unsanitized in the admin Ad Types report using jQuery .html(), allowing execu…
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-88864] Capgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed th…
Capgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed through Supabase PostgREST. A holder of an ordinary Capgo full API key can insert a row with status='active' and enforce_sso=true, bypassing the intended backend SSO provisioning route (supabase/functions/_backend/private/sso/providers.ts) and its controls: the Enterprise plan requirement, SSO provide…
M Crítico vulnerabilidad
10/09/2026
Vulnerabilidad de redirección abierta (Open Redirect) en Access Control System de Armiya
Se ha identificado una vulnerabilidad de redirección abierta en Access Control System de Armiya Information Technologies (versiones anteriores a la 2.0) que permite a atacantes redirigir usuarios a sitios no confiables y falsificar la fuente de datos. Esta falla afecta principalmente sistemas de control de acceso implementados en instalaciones de seguridad física en México y Latinoamérica, exponiendo credenciales y sesiones de usuarios autorizados.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-88285] Cámara GeoVision GV-LPC2211 V1.13 expone control PTZ sin autenticación
La cámara GeoVision GV-LPC2211 versión 1.13 expone un servicio de control PTZ (Pan-Tilt-Zoom) accesible por red sin requerir autenticación, permitiendo a atacantes remotos recuperar información de posicionamiento e inyectar comandos PTZ o comandos seriales arbitrarios. Esta vulnerabilidad afecta sistemas de vigilancia en infraestructura crítica, oficinas corporativas y centros de datos en México y Latinoamérica. Con CVSS 9.4, representa riesgo crítico de compromiso del perímetro de seguridad física y acceso no autorizado a sistemas de monitoreo.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-44950] fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph's bitmap in…
fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph's bitmap into a single buffer. Existing checks validates only that the source slice (position, length) lies within the source bitmap buffer. It does not check whether the running destination cursor has exceeded the allocation. A malicious font server can send overlapping source offsets -- for example 1000 gly…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-59679] fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character enc…
fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents in the separate FS_QueryXExtents16 reply. The two CARD32 fields are never cross-checked. A malicious or compromised font server can send a small num_extents (e.g. 1) in …
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-80351] Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability…
Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability in Apache Camel K. An improper neutralization of directives in dynamically evaluated Maven configuration allows tenant-controlled repository content to influence code execution within the operator pod, potentially enabling tenants to execute arbitrary code with the privileges of the operator. …
? Crítico alerta
10/09/2026
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA emite alerta de seguridad: CISA Adds Two Known Exploited Vulnerabilities to Catalog. CVEs relacionados: CVE-2026-67277, CVE-2026-86060.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-49364] An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrativ…
An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-57967] An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an exi…
An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ongoing execution of the previously authenticated session. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-67593] A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a qu…
A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes …
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-19583] Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the…
Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. However, no such check was implemented for client monitoring artifacts. Additionally there was no requirement that client monitoring artifacts carry the CLIENT_EVENTS …
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-18351] The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary Fi…
The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function. This is due to insufficient file type validation in the is_file_type_valid() function, which uses the attacker-controlled 'type' parameter as regex keys in the MIME allowlist, allowing blacklist bypass via …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
09/09/2026
[CVE-2026-87911] An OS command injection weakness in the read-only enforcement of the SQL validation component in Ama…
An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operating system commands on the host of a self-managed PostgreSQL server by placing a crafted COPY ... TO PROGRAM statement into content that is processed when an authenticated user interacts with the MCP s…
M Crítico vulnerabilidad
09/09/2026
[CVE-2026-54694] SkillTree is a micro-learning gamification platform. Prior to version 4.4.2, two independent code fl…
SkillTree is a micro-learning gamification platform. Prior to version 4.4.2, two independent code flaws combine into a single exploitable attack chain, with three distinct exploitation paths of escalating impact. `StringHighlighter.js` builds an HTML string by interpolating raw `value` substrings directly into a template literal with no HTML entity encoding. `HighlightedValue.vue` renders that str…
M Crítico vulnerabilidad
09/09/2026
[CVE-2026-87929] MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config…
MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge administrator session cookies. Attackers can mint a malicious ci_session cookie with administrator privileges by computing an HMAC-SHA1 using the publicly known encryption key, bypassing authentication checks…
M Crítico vulnerabilidad
09/09/2026
[CVE-2026-67401] A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root thr…
A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component
M Crítico vulnerabilidad
09/09/2026
[CVE-2026-85102] Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway…
Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.