Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 3 horas
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1000
Esta semana
RSS
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-57124] PraisonAI is a multi-agent teams system. Prior to 4.6.59, the default UI host applications expose PO…
PraisonAI is a multi-agent teams system. Prior to 4.6.59, the default UI host applications expose POST /api/mcp/connect without mandatory authentication and accept caller-controlled command and args values that PraisonAIUI passes to StdioMCPClient to start a local process. Because the UI commands bind to 0.0.0.0 by default, a reachable unauthenticated client can execute commands as the UI service …
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-57127] PraisonAI is a multi-agent teams system. Prior to 4.6.58, recipe serve installs APIKeyAuthMiddleware…
PraisonAI is a multi-agent teams system. Prior to 4.6.58, recipe serve installs APIKeyAuthMiddleware or JWTAuthMiddleware when an operator selects api-key or JWT authentication, but each middleware forwards requests when PRAISONAI_API_KEY or PRAISONAI_JWT_SECRET and the corresponding recipe value are absent. Unauthenticated clients can then reach recipe execution, input, and output surfaces and ma…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-82431] Description `SimpleACLAuthorizer` evaluated the user-level command set by returning early when `nim…
Description `SimpleACLAuthorizer` evaluated the user-level command set by returning early when `nimbus.users` was empty, before `nimbus.groups` was considered. An operator who restricted cluster access by group alone, leaving `nimbus.users` unset, therefore received no restriction at all: every authenticated principal was permitted every user-level operation, including `submitTopology`, `beginFil…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-82435] Description The worker's Netty message decoder is installed ahead of the SASL authentication handle…
Description The worker's Netty message decoder is installed ahead of the SASL authentication handlers in the pipeline and acts on frames before any authentication has taken place. It allocated buffers sized from a length field carried in the frame, so a single frame from an unauthenticated peer able to reach a worker slot port could drive a large allocation. `storm.messaging.netty.authentication…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-57123] PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, ToolsMCPServer.run_sse and…
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, ToolsMCPServer.run_sse and launch_tools_mcp_server bind to 0.0.0.0 and create /sse and /messages/ routes without invoking the available SecurityConfig authentication, origin-validation, or DNS-rebinding controls. Any reachable client can list and invoke registered tools, and a browser can target a local instance through DNS …
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-57125] PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.59 and praisonaiagents 1.6.59, the u…
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.59 and praisonaiagents 1.6.59, the unauthenticated POST /api/v1/runs Jobs API accepts attacker-controlled agent_yaml, and the approve field can mark execute_command as YAML-approved before @require_approval checks critical tools. This chain allows a remote caller to cause a configured language model agent to invoke arbitrary operating…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-82439] Description The DRPC server kept a map from function name to request queue and created an entry the…
Description The DRPC server kept a map from function name to request queue and created an entry the first time a function name was seen. No code path ever removed an entry: request cleanup removed the request from its queue, and the shutdown path drained queues, but the queue object and its map entry remained for the life of the process. Function names come from the client and are not constraine…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-82441] Description A submitted topology carries two lists of blobstore keys, `dependency_jars` and `depend…
Description A submitted topology carries two lists of blobstore keys, `dependency_jars` and `dependency_artifacts`, which the client fills in after uploading the corresponding blobs. Nimbus performed no validation of their contents on the submission path, yet acts on them in two places. During cleanup of a finished topology, Nimbus deletes the keys named in those lists, and the deletion is perfo…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-73370] Incorrect Authorization vulnerability in Apache Syncope. Delegated administration security checks…
Incorrect Authorization vulnerability in Apache Syncope. Delegated administration security checks performed by Reconciliation service's pull and push, being incomplete, could accept calls by administrator not provided with adequate entitlements. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended …
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-90937] froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowi…
froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives. Attackers can supply URLs containing literal newlines that are written verbatim into vhost config files during cron rebuild, enabling web server configuration corruption, denial of service, or hijacking of HTTP …
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-78330] Incorrect privilege assignment vulnerability in Apache Syncope. When the configured JWKS settings f…
Incorrect privilege assignment vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can obtain admin privileges after completing a successful authentication and obtaining a valid low-privileges JWT. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, fr…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-77051] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i…
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized entityKey and opEvent parameters. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-77181] Incorrect Authorization vulnerability in Apache Syncope. An administrator with ClientApp's update…
Incorrect Authorization vulnerability in Apache Syncope. An administrator with ClientApp's update entitlement is unable to perform the related operation, while ClientApp's create entitlement is checked both for create and update operations on ClientApp. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are reco…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-78299] In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS p…
In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extraction can extract files to locations outside of the pack, allowing writing of arbitrary files to other locations on disk.
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-73470] Improper Privilege Management vulnerability in Apache Syncope. Delegations can be created or up…
Improper Privilege Management vulnerability in Apache Syncope. Delegations can be created or updated with Roles not owned by the delegating User, or not for the same Realm subtree under the delegation management was granted for. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to ve…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-73579] Incorrect Authorization vulnerability in Apache Syncope. Any search requests are transformed into…
Incorrect Authorization vulnerability in Apache Syncope. Any search requests are transformed into SQL, Neo4J or Elasticsearch / Opensearch queries, depending on the actual deployment configuration. An important component of such transformation is the Realms filter, which ensures that the search results are matching the requester's permissions. For non-recursive search requests it is possible th…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-73668] Incorrect Authorization vulnerability in Apache Syncope. An administrator with adequate entitle…
Incorrect Authorization vulnerability in Apache Syncope. An administrator with adequate entitlements in a given Realm may be able to read via REST the full Connector configuration, confidential properties included, scoped in another Realm and thus be able to effectively duplicate such Connector instance into the Realm they have administration rights for. This issue affects Apache Syncope: fr…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-75030] Missing Authorization vulnerability in Apache Syncope. An administrator with task execution entit…
Missing Authorization vulnerability in Apache Syncope. An administrator with task execution entitlements might be able to mass (de)provision group members, regardless of their group-related administration capabilities. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.…
M Crítico vulnerabilidad
14/09/2026
Vulnerabilidad crítica de ejecución remota de código en LightLLM hasta versión 1.2.0
LightLLM versiones anteriores a 1.2.1 contiene una vulnerabilidad de ejecución remota de código (RCE) en el endpoint WebSocket /visual_register del Config Server sin autenticación. Un atacante con acceso a la red puede enviar un payload malicioso serializado con método __reduce__ a pickle.loads() para ejecutar código arbitrario con privilegios del proceso Config Server. Este riesgo afecta directamente a infraestructuras de IA/ML en empresas de México y LATAM que ejecuten LightLLM en entornos de producción o desarrollo expuestos a la red interna o internet.
M Crítico vulnerabilidad
14/09/2026
Vulnerabilidad crítica en Bifrost permite ejecución remota de código sin autenticación
Bifrost permite registrar clientes MCP a través de su API de gestión sin requerir handshake MCP ni autenticación cuando governance.auth_config.is_enabled=false (configuración por defecto). Un atacante puede ejecutar comandos arbitrarios como el usuario del proceso Bifrost mediante una única solicitud POST /api/mcp/client no autenticada, comprometiendo completamente servidores y gateways en empresas de LATAM que usen esta solución.