Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "X" — 3569 resultados ✕ Limpiar búsqueda
22,395
Total alertas
4758
Críticas
17006
Altas
8
Ransomware
1254
Esta semana
RSS
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-50152] Ceph is an open-source distributed storage platform providing object, block, and file storage. In ve…
Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Monitor subscription handler fails to properly authorize access to the configuration-key store, allowing any CephX user with only  `mon allow r` capabilities to read the entire store by sending a single crafted MMonSubscribe message. The config-key store holds …
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-81934] Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handl…
Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands with the privileges of the Redis server. Fixed in Redis 8.2.9, 8.4.6, 8.6.6, 8.8.2, and 8.10.1.
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-81707] openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allow…
openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inject ANSI escape sequences that forge the fingerprint verification line displayed to users. Attackers can deliver a crafted identity bundle through normal contact-exchange flows or keyserver responses to manipulate terminal output and display a fraudulent fingerprint, bypassing th…
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-81700] openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.v…
openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that accepts revoked and expired keys by only checking VALIDSIG status without inspecting REVKEYSIG, EXPKEYSIG, or gpg exit codes. Attackers holding compromised-then-revoked signing keys or expired project keys can bypass signature verification to execute malicious plugins in the host…
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-81701] openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing …
openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-level plugins/ directories and unknown subdirectories to bypass signature verification. Attackers can place malicious unsigned plugins following documented installation paths to achieve arbitrary code execution in the CLI process with access to passwords and cryptographic key…
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-81098] The Telnyx MCP server exposed its HTTP transport on every interface and did not require a caller cre…
The Telnyx MCP server exposed its HTTP transport on every interface and did not require a caller credential. packages/mcp-server/src/http.ts served MCP on the root path with a listener bound to all interfaces and parsed the caller's authentication headers in a mode that did not fail when they were absent, so a request without any credential completed initialisation and dispatched tools. Dispatch f…
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-81094] The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only whe…
The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only when the operator asked for it. The serve command in apps/cli/src/commands/serve.ts defaulted its host to the all-interfaces address on a fixed port, and required a token only when the corresponding flag was supplied, so a default invocation exposed the aggregator, and every MCP server it fronted, to a…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-81096] ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that req…
ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that required no authentication. The executor behind the python_code_executor tool, in python_executor_tool.py, inspected the submitted source for a denied list of attribute names and calls but left the attribute-lookup builtins available and did not stop a dunder attribute reached through a string lookup o…
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-57499] Liman is open source server management software. Prior to 2.2.2 - 1103, an OS command injection vuln…
Liman is open source server management software. Prior to 2.2.2 - 1103, an OS command injection vulnerability in the log rotation configuration endpoint allows an authenticated administrator to execute arbitrary operating system commands on the Liman server. The `ip_address` parameter is embedded directly into a shell command without sanitization, enabling shell escape via single-quote injection. …
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-16279] An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R…
An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could allow an attacker to gain access to some user accounts.
M Crítico vulnerabilidad
27/08/2026
Inyección de objetos PHP sin autenticación en Geo Controller <= 8.9.8
Se ha identificado una vulnerabilidad crítica (CVSS 9.8) de inyección de objetos PHP sin autenticación en Geo Controller versiones 8.9.8 y anteriores. Un atacante remoto podría ejecutar código arbitrario y comprometer completamente sistemas que utilicen esta extensión, afectando potencialmente aplicaciones web en infraestructuras de empresas y gobiernos en LATAM. La gravedad se debe a la ausencia de validación de autenticación previa al procesamiento de datos en el controlador Geo.
M Crítico vulnerabilidad
27/08/2026
Inyección SQL sin autenticación en Beautiful Taxonomy Filters <= 2.4.6
Se ha identificado una vulnerabilidad crítica de inyección SQL sin autenticación en Beautiful Taxonomy Filters versión 2.4.6 y anteriores, con puntuación CVSS de 9.3. Esta falla permite a atacantes remotos ejecutar comandos SQL arbitrarios contra bases de datos de sitios WordPress afectados, comprometiendo la confidencialidad e integridad de datos. Empresas en LATAM que utilizan este plugin en sitios de comercio electrónico, portales administrativos o plataformas de contenido están expuestas a robo de información sensible y manipulación de registros.
M Crítico vulnerabilidad
27/08/2026
Inyección de objetos PHP sin autenticación en Hash Form <= 1.4.1 (CVE-2026-78292)
Vulnerabilidad crítica (CVSS 9.8) en Hash Form versión 1.4.1 y anteriores permite inyección de objetos PHP sin requerir autenticación. Un atacante remoto puede ejecutar código arbitrario comprometiendo servidores web en empresas mexicanas y latinoamericanas. El riesgo es máximo en entornos de e-commerce, plataformas de gestión y aplicaciones expuestas a internet.
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-59354] In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynami…
In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the registration endpoint performs insufficient validation of certain client metadata fields supplied by the registering client. An attacker who possesses a valid Initial Access Token can register a malicious client with crafted metadata, which, depending…
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-47890] Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Event…
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-47891] A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not corr…
A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-47884] Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has…
Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and ea…
? Crítico alerta
27/08/2026
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA emite alerta de seguridad: CISA Adds Three Known Exploited Vulnerabilities to Catalog. CVEs relacionados: CVE-2023-49105, CVE-2026-53362, CVE-2026-66384.
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-70419] Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special…
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-81032] NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. Each daemon star…
NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. Each daemon starts the web service defined in src/webservice/WebService.cpp, whose bind address defaults to all interfaces, and registers routes for reading and writing gflags alongside status and statistics. Neither the service nor its router carries any authentication, token check or address restriction. The read…