Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "X" — 3569 resultados ✕ Limpiar búsqueda
22,394
Total alertas
4758
Críticas
17006
Altas
8
Ransomware
1258
Esta semana
RSS
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-81939] A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and arc…
A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outside the intended destination directory using a specially crafted archive.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-78327] An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner…
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated attacker with SuperAdmin privileges to inject arbitrary commands that are executed on the underlying host, resulting in remote code execution.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-75430] PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP…
PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without authentication on the default transport port. This allows a remote attacker to execute arbitrary code.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-31020] In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to d…
In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to define prompt content used during chatbot interactions. This functionality renders user-supplied prompt data using Jinja templates without input sanitization or sandboxing. An unauthenticated attacker can inject malicious template expressions, leading to a server-side template injection (SSTI) vulner…
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-75431] PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT signing key for HS256-base…
PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT signing key for HS256-based authentication. This allows a remote attacker to execute arbitrary code.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-75160] An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via th…
An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via the endpoints /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-44402] Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in …
Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary commands as root by uploading a crafted tar archive without valid credentials. Attackers can supply a malicious tar archive containing arbitrary executable files that are extracted to a privileged directory and…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-18658] IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.…
IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements and leverage database functionality to write a web shell to the application web root, resulting in remote code execution.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-85696] SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded …
SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without proper escaping. Attackers can upload audio files with shell metacharacters in the filename to break out of quoted arguments and execute arbitrary system commands when video generation occurs.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-85684] marker through 2.0.0 contains a path traversal vulnerability in the FastAPI /marker/upload handler t…
marker through 2.0.0 contains a path traversal vulnerability in the FastAPI /marker/upload handler that fails to sanitize the file.filename parameter. Unauthenticated attackers can supply filenames containing directory traversal sequences to write arbitrary files to any location or delete existing files on the system.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-85688] TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the …
TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints. Attackers can submit POST and PUT requests to the /api/designer/v1/file-content endpoints to read arbitrary files or write malicious content to system paths, enabling code execution through authorized_keys, cron files, or executable graph files.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-85672] zerox 1.1.20 contains an OS command injection vulnerability in the file download mechanism where the…
zerox 1.1.20 contains an OS command injection vulnerability in the file download mechanism where the temporary file extension derived from document URLs is interpolated unsanitized into shell commands executed by poppler utilities. Attackers can craft document URLs with malicious file extensions containing command substitution syntax to execute arbitrary OS commands before document processing occu…
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-85667] xiaobei through 5.5.2 fails to implement authentication or signature validation on webhook endpoints…
xiaobei through 5.5.2 fails to implement authentication or signature validation on webhook endpoints, allowing unauthenticated attackers to inject arbitrary messages into the agent pipeline. Attackers can publish malicious messages via the /webhook_worktool handler and exploit unvalidated media URL fetching to perform server-side request forgery against internal services.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-85661] excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unse…
excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files. Attackers can supply unchecked file paths to read and write tools to access any file accessible to the process.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-85663] Aim 3.29.1 remote tracking server fails to authenticate requests and dispatches arbitrary methods th…
Aim 3.29.1 remote tracking server fails to authenticate requests and dispatches arbitrary methods through getattr without allowlist validation. Unauthenticated attackers can register clients, instantiate Repo resources, and invoke arbitrary methods to read experiments or delete runs.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-85085] The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView…
The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with Canva using the user’s session.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-62928] XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS command may be injec…
XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS command may be injected.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-69657] XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyone with the knowledge of the cr…
XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyone with the knowledge of the credential may log in to the affected device.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-70403] XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Anyone with the knowledge of the …
XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Anyone with the knowledge of the credential may log in to the affected device.
? Crítico alerta
04/09/2026
CISA Adds One Known Exploited Vulnerability to Catalog
CISA emite alerta de seguridad: CISA Adds One Known Exploited Vulnerability to Catalog. CVEs relacionados: CVE-2026-85046.