Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "X" — 3569 resultados ✕ Limpiar búsqueda
22,395
Total alertas
4758
Críticas
17006
Altas
8
Ransomware
1254
Esta semana
RSS
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-55559] Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs inserts templateArgs from PO…
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs inserts templateArgs from POST /api/instances and PATCH /api/instances/{instance} into YAML through VarStatement.append in yamcs-core/src/main/java/org/yamcs/templating/VarStatement.java without YAML-context escaping. The rendered configuration is parsed by YamcsServer.createInstance and loaded by YamcsServerInstance, allowing…
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-55248] plone.app.portlets provides portlets and a Plone-specific user interface for plone.portlets. Prior t…
plone.app.portlets provides portlets and a Plone-specific user interface for plone.portlets. Prior to 5.0.8, 6.0.4, and 7.0.2, a member who can add an RSS portlet can set its feed URL to a very large response, causing src/plone/app/portlets/portlets/rss.py to download and retain excessive data in memory and deny service. The same RSS URL handling accepts internal hosts, IP addresses, single-word d…
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-55511] Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs allows a user with SystemPri…
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs allows a user with SystemPrivilege.ControlArchiving to create a double-quoted StreamSQL column name that is interpolated into generated Java source by Expression.fillCode_InputDefVars and Expression.sanitizeName. A sum aggregate reaches yamcs-core/src/main/java/org/yamcs/yarch/streamsql/CompilableAggregateExpression.java and y…
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-54745] Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. …
Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the Kubeflow Pipelines frontend exposes an unauthenticated server-side request forgery vulnerability through the /_proxy/ route in frontend/server/proxy-middleware.ts. The _routePathWithReferer() function accepts an arbitrary attacker-controlled HTTP or HTTPS target and passes its o…
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-54755] Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty…
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty fields decoded in core/kapp/builtInFunctions/utils.go can contain values greater than core.HundredPercent, and core/kapp/kda/create.go and core/kapp/kda/trigger.go sum those values in uint32 accumulators. Crafted values such as two 0x80000000 entries wrap the validation sum to zero and pass CheckVa…
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-37751] An OS command injection vulnerability in the killSessionSync function (lib/agent-runtime.ts) of 23bl…
An OS command injection vulnerability in the killSessionSync function (lib/agent-runtime.ts) of 23blocks-OS ai-maestro v0.24.17 allows attackers to execute arbitrary commands via a crafted input.
M Crítico vulnerabilidad
28/08/2026
Vulnerabilidad crítica de ejecución remota de código en Budibase anterior a v3.41.3
Budibase versiones anteriores a 3.41.3 contienen una vulnerabilidad de ejecución remota de código (RCE) en el manejo de plugins que permite a usuarios administradores autenticados ejecutar código arbitrario mediante la carga de un tarball malicioso. El servidor ejecuta eval() en archivos JavaScript de plugins sin aislamiento en el proceso Node.js principal, habilitando la exfiltración de variables de entorno y credenciales con privilegios root. Empresas en LATAM que utilicen Budibase en entornos de producción o desarrollo enfrentan riesgo crítico de compromiso total del servidor.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-42007] An attacker that has valid credentials can use a Sieve script with the editheader extension to trigg…
An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail. This causes memory leak and opportunity to do memory corruption during mail delivery, which can crash the delivery process and may allow execution of arbitrary code in the c…
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-76581] The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions u…
The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. This is due to inconsistent and ambiguous HMAC message construction between the unauthenticated `wdpsso_step1` and `wdpsso_step2` AJAX actions, where step 1 signs and discloses an unseparated concatenation of the token, state, redirect, and domain values, while step 2 ver…
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-78032] SOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed…
SOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed by an attacker with the web server privilege.
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-40541] An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerabilit…
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, via a UI interaction, to read or write arbitrary files and conduct denial-of-service attacks in DSM.
G Crítico vulnerabilidad
28/08/2026
CVE-2026-66323 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-66323 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability. Tipo: Ejecución Remota de Código (RCE).
G Crítico vulnerabilidad
28/08/2026
CVE-2026-66798 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-66798 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability. Tipo: Ejecución Remota de Código (RCE).
G Crítico vulnerabilidad
28/08/2026
CVE-2026-70341 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-70341 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability. Tipo: Ejecución Remota de Código (RCE).
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-82082] NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remot…
NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-61800] Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints an…
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.4.0 through 4.14.6, a party holding the cluster key can write, overwrite, or delete arbitrary files under /var/ossec on worker nodes, leading to remote code execution as root. During cluster file synchronization, the non-merged branch of update_master_files_in_worker…
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-78239] Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, …
Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remote attacker to enable administrative services that should be restricted. Successful exploitation may permit unauthorized access to the device.
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-76943] Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allo…
Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to bypass intended access controls and obtain command execution capabilities. Successful exploitation could allow unauthorized interaction with privileged functionality and may lead to complete device compromise.
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-76179] An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway produ…
An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products. Authentication tokens used by the web management interface are insufficiently protected during client-side session handling, which may allow an attacker with access to exposed session information to obtain and reuse a valid token. Successful exploitation could allow an attacker to impersona…
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-69658] MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information t…
MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information to network-level attackers. This may enable unauthorized device impersonation and disruption of messaging functions.