Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,345
Total alertas
4745
Críticas
16970
Altas
8
Ransomware
1213
Esta semana
RSS
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-89778] In the Linux kernel, the following vulnerability has been resolved: isofs: fix out-of-bounds page a…
In the Linux kernel, the following vulnerability has been resolved: isofs: fix out-of-bounds page array access on empty zisofs block zisofs_uncompress_block()'s empty-block fast path returns pcount
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-89779] In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate ef->size cov…
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate ef->size covers the record's name and value When an EA record has a non-zero ef->size, ntfs_read_ea() only checks that the record fits in the remaining buffer (ea_size > bytes), not that ef->size is large enough to hold the record's own name_len + 1 + elength. A crafted image can pass validation with, e.g., e…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-89783] In the Linux kernel, the following vulnerability has been resolved: xfrm6: fix out-of-bounds write …
In the Linux kernel, the following vulnerability has been resolved: xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full The depth check in xfrm6_input_addr() is off by one: if (1 + sp->len == XFRM_MAX_DEPTH) goto drop; ... sp->xvec[sp->len++] = x; xfrm_input() can leave sp->len == XFRM_MAX_DEPTH, and the transport-mode receive path re-enters IPv6 input via…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-89775] In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Handle negative S1 …
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation Computing the effects of a TLB invalidation involves looking at the size of the mapping cached by the TLB. For S1 mappings such as VNCR, this is deducted from the combination of the base granule size and the mapping level. However, this implies that the S1 M…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-27565] An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell…
An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges. The shell script remains active even after a reboot.
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-27546] An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function…
An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured.
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-73447] A privileged attacker can exploit certain operation to execute arbitrary commands with root privileg…
A privileged attacker can exploit certain operation to execute arbitrary commands with root privileges, leading to full device compromise. An authenticated user can exploit gRPC Network Security Interface (gNSI) Certz service on Arista EOS-based products to escalate privileges and execute arbitrary OS commands via a crafted Certz Rotate request. The Bootz service is also affected.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-14349] The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to auth…
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to modify the email address of arbitrary user accounts, including administrators, which …
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-12793] The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Esc…
The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.6.2. This is due to the plugin not validating that a submitted form ID belongs to a JetFormBuilder form before parsing the referenced post's content as form schema and executing an Advanced Validation server-side callback. This makes it possible for un…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-81855] A hardcoded cryptographic client authentication key vulnerability exists in the robot testing framew…
A hardcoded cryptographic client authentication key vulnerability exists in the robot testing framework component of Wärtsilä FOS-Onboard.
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-78225] A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller compo…
A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller component of Wärtsilä FOS-Onboard.
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-61560] `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version 2.1.27, the S…
`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version 2.1.27, the SSE transport mode (`SSE=true`) exposes all MCP tools without any authentication. The `upload_markdown` tool reads arbitrary files from the server's local filesystem via an unsanitized `file_path` parameter and uploads them to a GitLab project. Combined, any unauthenticated network-reachable attacker…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-73437] On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay confi…
On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay configured, an unauthenticated attacker with network access could send a crafted DHCP reply packet from an IP address that is not configured as a helper address, and the relay agent would forward it to clients without validating the source. This could allow the attacker to supply clients with malicious n…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-73807] The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functi…
The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthenticated attacker with network access to the affected API could exploit this vulnerability to access privileged management functions.
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-91749] Use after free in Workers in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to poten…
Use after free in Workers in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-91939] Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes r…
Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can exploit PHP object injection through crafted serialized payloads to trigger gadget chains and achieve database manipulation or code execution.
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-91728] Integer overflow in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute …
Integer overflow in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-66890] The affected products use hard-coded credentials, which could allow remote access to files with root…
The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable.
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-61559] `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and …
`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior to version 2.1.27, when the environment variable `ENABLE_DYNAMIC_API_URL=true` is set, the server reads the `X-GitLab-API-URL` HTTP request header and uses it as the base URL for all outbound GitLab API calls made within that request. The server validates that the value is a well-formed URL (`…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-61568] `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to 2.1.30 expos…
`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to 2.1.30 expose the Streamable HTTP MCP endpoint without an effective Host or Origin allowlist. A malicious web page can use DNS rebinding to route browser requests to a victim's local MCP listener while preserving an attacker-controlled `Host` and `Origin`. The server accepts those headers and reaches the MCP in…