Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ui" — 666 resultados ✕ Limpiar búsqueda
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1019
Esta semana
RSS
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-75728] Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could resu…
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction.
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-73369] Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injecti…
Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-75699] Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injecti…
Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-75703] Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injecti…
Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-43641] Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerabil…
Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in the billing module handler that allows unauthenticated remote attackers to execute arbitrary commands as root by bypassing authentication through specific parameter combinations. Attackers can deserialize a crafted billing_data POST field and inject shell payloads through the uid field, which…
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-84388] A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Ext…
A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4 all versions may allow attacker to information disclosure via remote unauthenticated attack
M Crítico vulnerabilidad
22/09/2026
Vulnerabilidad crítica de ejecución remota de código en Zohocorp ManageEngine ADSelfService Plus (CVE-2026-74849)
Zohocorp ManageEngine ADSelfService Plus en versiones anteriores a la build 7001 presenta una vulnerabilidad de ejecución remota de código (RCE) con CVSS 9.8 en el cliente GINA. Esta falla permite a atacantes ejecutar comandos arbitrarios sin autenticación previa, afectando principalmente a empresas en LATAM que utilizan esta solución para gestión de identidades y acceso en entornos Active Directory. El impacto es crítico en infraestructuras de TI medianas y grandes.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
22/09/2026
[CVE-2016-15059] Net::IDN::Punycode versions before 2.301 for Perl allow a heap buffer overflow via unchecked writes …
Net::IDN::Punycode versions before 2.301 for Perl allow a heap buffer overflow via unchecked writes past the output buffer in encode_punycode. The XS backend builds the encoded label in the string buffer of the scalar it returns, sized from the input length. The loop that emits the digits of each code point checks for room before every write, but the write of the last digit of each round and the …
M Crítico vulnerabilidad
21/09/2026
[CVE-2026-77521] MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a …
MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool, skill, or sub-application use SandboxShellBackend, which exposes an execute shell tool without excluding it and omits execute from interrupt_on, so human approval is not required. Untrusted chat or ingested content can therefore cause command execution; source deployments with MAXKB_…
M Crítico vulnerabilidad
20/09/2026
[CVE-2026-94083] Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code…
Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This requires app-layer.protocols.doh2 to be enabled, which is the default in 8.x versions.
M Crítico vulnerabilidad
19/09/2026
[CVE-2026-78030] DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm att…
DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value names a module. require treats a path-shaped string as a literal filename and does not consult @INC, so the attribute chooses the file that Perl loads and runs. The MLDBM::…
M Crítico vulnerabilidad
19/09/2026
Vulnerabilidad crítica en plugin Forminator para WordPress permite ejecución arbitraria de shortcodes
El plugin Forminator Forms para WordPress (versiones hasta 1.57.2) es vulnerable a ejecución arbitraria de shortcodes debido a validación insuficiente en la función do_shortcode. Atacantes no autenticados pueden ejecutar código malicioso en sitios web afectados, comprometiendo la integridad de formularios de contacto y pago. Esta vulnerabilidad impacta directamente a empresas en LATAM que utilizan este plugin en formularios críticos de recolección de datos y procesamiento de pagos.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-58264] FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6…
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6, the FluidSynth command handler accepts a pitch_bend_range command whose channel argument is not bounds checked before the supplied value is written through the selected synth channel. An out-of-range channel can therefore cause an out-of-bounds heap write, leading to denial of service or possible …
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-75031] In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was fou…
In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the “quick question” admin feature. In default installations arbitrary Perl code can be injected and executed server-side by unauthenticated users. The Perl code normally runs within a Safe container which limits the scope of what it can do, unless the non-default AllowGlobal directive is …
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-93605] vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTIN…
vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-spawning modules. Attackers can require child_process and execute arbitrary commands on the host system when NodeVM is configured with builtin:['*'] or explicit child_process allowance.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-54670] WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatc…
WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/contribuicao/controller/control.php accepts attacker-controlled nomeClasse and metodo values without a complete controller and method allowlist, exempts sensitive ContribuicaoLogController operations from authentication, and constructs a controller include path without canonical dire…
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-54627] SAIL is a cross-platform library for loading and saving images with support for animation, metadata,…
SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, psd_private_sail_pixel_format() in src/sail-codecs/psd/helpers.c resolves a one-channel PSD in Bitmap color mode to SAIL_PIXEL_FORMAT_BPP1_INDEXED without requiring the file depth to be one, so the pixel buffer uses one-bit rows while sail_codec_load_frame_v…
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-47252] Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, authenticated users with INS…
Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, authenticated users with INSERT or UPDATE access to affected macOS virtual tables can execute operating-system commands because the Chrome plugin and equivalent Brave, Edge, and Safari variants interpolate a SQL-controlled URL into AppleScript or JXA source passed to osascript. In plugins/chrome/tabs.go, tabsTable.Insert() pas…
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-54053] Many Notes is a Markdown note-taking web application designed for simplicity. Prior to 0.16.0, the Z…
Many Notes is a Markdown note-taking web application designed for simplicity. Prior to 0.16.0, the ZIP vault import implemented in app/Actions/ProcessImportedVault.php accepts archive filenames containing parent-directory traversal segments. An authenticated user can write arbitrary files outside the importing user's vault and into other users' vaults, including overwriting existing files. Disguis…
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-63472] Vendure is an open-source headless commerce platform. Prior to 3.7.0, ExternalAuthenticationService.…
Vendure is an open-source headless commerce platform. Prior to 3.7.0, ExternalAuthenticationService.createCustomerAndUser in packages/core/src/service/helpers/external-authentication/external-authentication.service.ts selects an existing customer user by emailAddress and attaches a newly presented ExternalAuthenticationMethod without requiring verified to be true. In deployments with a custom exte…