Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 3 horas
Buscando: "Quest" — 435 resultados ✕ Limpiar búsqueda
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1000
Esta semana
RSS
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-76423] A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remot…
A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain administrative access to an affected device. This vulnerability is due to the REST API web service being exposed with insufficient authorization checks. An attacker could exploit this vulnerability by sending a crafted HTTP request to the exposed REST API port. A successful exp…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-73456] Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampli…
Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full administrative control over the compromised switch.
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-92395] @fastify/proxy-addr is a Fastify plugin that determines a request's client address behind trusted re…
@fastify/proxy-addr is a Fastify plugin that determines a request's client address behind trusted reverse proxies, and it backs Fastify request.ip and request.ips. In versions 3.0.0 through 5.1.0, a trust subnet written in IPv4-mapped IPv6 notation with an IPv4-sized prefix, such as ::ffff:10.0.0.0/8 instead of the correct ::ffff:10.0.0.0/104, is accepted without error but trusts every IPv4 addres…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-90011] In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Reserve a …
In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Reserve a terminator byte for the login payload iscsi_target_check_login_request() rejects a login PDU whose DataSegmentLength exceeds MAX_KEY_VALUE_PAIRS, but the test is '>' and login->req_buf is allocated with exactly MAX_KEY_VALUE_PAIRS bytes. Since iscsit_get_login_rx() receives payload_length + padding…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-89857] In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Hold qpair lock …
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject qla_nvme_ls_reject_iocb() allocates from and advances the request ring through __qla2x00_alloc_iocbs() (which assumes the hardware_lock is held) and qla2x00_start_iocbs() (which advances the ring and rings the request-in doorbell), but takes no lock itself. Two of its ca…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-73447] A privileged attacker can exploit certain operation to execute arbitrary commands with root privileg…
A privileged attacker can exploit certain operation to execute arbitrary commands with root privileges, leading to full device compromise. An authenticated user can exploit gRPC Network Security Interface (gNSI) Certz service on Arista EOS-based products to escalate privileges and execute arbitrary OS commands via a crafted Certz Rotate request. The Bootz service is also affected.
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-61559] `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and …
`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior to version 2.1.27, when the environment variable `ENABLE_DYNAMIC_API_URL=true` is set, the server reads the `X-GitLab-API-URL` HTTP request header and uses it as the base URL for all outbound GitLab API calls made within that request. The server validates that the value is a well-formed URL (`…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-61568] `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to 2.1.30 expos…
`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to 2.1.30 expose the Streamable HTTP MCP endpoint without an effective Host or Origin allowlist. A malicious web page can use DNS rebinding to route browser requests to a victim's local MCP listener while preserving an attacker-controlled `Host` and `Origin`. The server accepts those headers and reaches the MCP in…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-89040] Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a cr…
Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device. An attacker who uploads a webshell can execute arbitrary code as root.
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-76672] A vulnerability exists in the SD-WAN Orchestrator that may lead to the exposure of sensitive configu…
A vulnerability exists in the SD-WAN Orchestrator that may lead to the exposure of sensitive configuration information. An authenticated remote attacker with read-only privileges could exploit this vulnerability by sending a specially crafted request to the cache synchronization endpoint. Successful exploitation could result in the disclosure of sensitive third-party API tokens and credentials, po…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-45579] DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0…
DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, the RequestManagementSystem/Service/ReqManagerHandler.py export_getRequestCountersWeb function passes an authenticated caller-controlled groupingAttribute to RequestManagementSystem/DB/RequestDB.py getRequestCountersWeb. An unrecognized value is resolved against the Request …
M Crítico vulnerabilidad
15/09/2026
[CVE-2023-54398] Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.fi…
Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageServlet component that allows remote unauthenticated attackers to execute arbitrary OS commands by sending a serialized payload via POST request. Attackers can exploit the doAction method, which passes raw HTTP request body data directly to ObjectInputStream.readObject() without f…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-91949] FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allow…
FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers can send incompatible protocol requests, receive negotiation failures, then complete TLS handshake and enter RDSTLS to bypass pre-authentication transport restrictions.
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-55158] Conflibot warns in advance when merging a pull request will cause conflicts in other open pull reque…
Conflibot warns in advance when merging a pull request will cause conflicts in other open pull requests. Prior to 1.2.1, src/index.ts builds git checkout, git merge, and git format-patch commands by interpolating the attacker-controlled pull request head.ref value into strings passed to exec. In the documented pull_request_target configuration, an attacker can open a pull request, including from a…
M Crítico vulnerabilidad
15/09/2026
Vulnerabilidad crítica en PraisonAI permite ejecución remota sin autenticación (CVE-2026-57139)
PraisonAI versiones 1.5.0 a 1.7.2 contienen una falla de seguridad crítica (CVSS 9.8) en MCPServer.startHttp() que expone funciones de herramientas, recursos y prompts sin validación de autenticación. Cualquier cliente en red con acceso al puerto puede ejecutar comandos arbitrarios en sistemas que utilicen esta plataforma de agentes múltiples, afectando servidores en producción en México y Latinoamérica que procesen datos sensibles.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
15/09/2026
Ejecución de código arbitrario en PraisonAI anterior a 1.7.2 (CVE-2026-57141)
PraisonAI, plataforma de orquestación de agentes IA, contiene una vulnerabilidad crítica (CVSS 9.8) en la herramienta codeMode que permite ejecución de código JavaScript arbitrario. Un atacante puede eludir el blocklist de expresiones regulares mediante Function('return this')() y acceder dinámicamente al módulo child_process, logrando control total del servidor. Afecta versiones previas a 1.7.2 y compromete sistemas que ejecuten agentes IA en producción en LATAM.
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-90711] proxy-addr is a Node.js module that determines a request's client address behind trusted reverse pro…
proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and it backs Express req.ip and req.ips. In versions 1.1.0 through 2.0.7, a trust subnet written in IPv4-mapped IPv6 notation with an IPv4-sized prefix, such as ::ffff:10.0.0.0/8 instead of the correct ::ffff:10.0.0.0/104, is accepted without error but trusts every IPv4 address on the internet…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-57127] PraisonAI is a multi-agent teams system. Prior to 4.6.58, recipe serve installs APIKeyAuthMiddleware…
PraisonAI is a multi-agent teams system. Prior to 4.6.58, recipe serve installs APIKeyAuthMiddleware or JWTAuthMiddleware when an operator selects api-key or JWT authentication, but each middleware forwards requests when PRAISONAI_API_KEY or PRAISONAI_JWT_SECRET and the corresponding recipe value are absent. Unauthenticated clients can then reach recipe execution, input, and output surfaces and ma…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-82439] Description The DRPC server kept a map from function name to request queue and created an entry the…
Description The DRPC server kept a map from function name to request queue and created an entry the first time a function name was seen. No code path ever removed an entry: request cleanup removed the request from its queue, and the shutdown path drained queues, but the queue object and its map entry remained for the life of the process. Function names come from the client and are not constraine…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-73579] Incorrect Authorization vulnerability in Apache Syncope. Any search requests are transformed into…
Incorrect Authorization vulnerability in Apache Syncope. Any search requests are transformed into SQL, Neo4J or Elasticsearch / Opensearch queries, depending on the actual deployment configuration. An important component of such transformation is the Realms filter, which ensures that the search results are matching the requester's permissions. For non-recursive search requests it is possible th…