Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,394
Total alertas
4758
Críticas
17006
Altas
8
Ransomware
1258
Esta semana
RSS
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-85508] ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc…
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c (cmc-ipv6-info subcommand to dell get-system-info).
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-85509] FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-f…
FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-11613] The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up t…
The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensit…
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-85148] SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Un…
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed password to remotely access user hosts.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-85146] SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Un…
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account credentials and passwords for the SmartIT Agent directly from the application source code.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85437] MOOS-IvP through 24.8.1 contains multiple buffer overflow vulnerabilities in IvP function string dec…
MOOS-IvP through 24.8.1 contains multiple buffer overflow vulnerabilities in IvP function string decoders that trust attacker-controlled length fields without validation. Attackers can craft malicious encoded strings with mismatched declared and actual field lengths to overflow heap and stack buffers, potentially achieving remote code execution through MOOS variables or alog files.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85438] MOOS-IvP through 24.8.1 contains a buffer overflow vulnerability in StringToIvPFunction() where dime…
MOOS-IvP through 24.8.1 contains a buffer overflow vulnerability in StringToIvPFunction() where dimension, piece, and degree counts from encoded BHV_IPF payloads are used as allocation sizes and loop bounds without validation. Attackers can supply crafted payloads with mismatched dimension values to write attacker-controlled doubles past the end of the IvPBox weight array, causing memory corruptio…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85440] MOOS core-moos through 10.4.0 contains a pre-authentication heap overflow vulnerability in MOOSCommP…
MOOS core-moos through 10.4.0 contains a pre-authentication heap overflow vulnerability in MOOSCommPkt packet handling that allows remote attackers to write arbitrary data by declaring a negative packet length. Attackers can exploit the signed integer check in InflateTo() and negative size conversion in recv() to overflow a four-byte heap buffer during the HandShake phase before authentication.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85430] MOOS essential-moos through 10.0.1 contains an authentication bypass vulnerability in pShare that ac…
MOOS essential-moos through 10.0.1 contains an authentication bypass vulnerability in pShare that accepts UDP datagrams from any source and republishes them with the attacker-claimed identity intact. Attackers can send crafted UDP datagrams to pShare input routes to inject messages into the local MOOS community under spoofed identities, or send malformed datagrams to crash the pShare process.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85433] MOOS essential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD messages, allowing …
MOOS essential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD messages, allowing any publisher to reconfigure network routes and listeners at runtime. Attackers can send crafted PSHARE_CMD messages with cmd=output or cmd=input parameters to open new listeners on arbitrary addresses and redirect or duplicate bus traffic to attacker-controlled destinations.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85434] MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbo…
MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbound bridge routes. Attackers can publish NODE_BROKER_PING messages with crafted HostRecord data to redirect bridged variables to attacker-controlled addresses.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85435] MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the source of TRY_SHORE_HOST messages on th…
MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the source of TRY_SHORE_HOST messages on the vehicle bus, allowing any publisher to enroll attacker-controlled shore routes. Attackers can publish malicious shore route messages to receive bridged vehicle traffic including sensor data and control information.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85424] MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated cl…
MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to connect with full publish, subscribe, and database clear privileges. Attackers can bypass the compile-time protocol string check and connect with arbitrary client names to execute privileged operations including DB_CLEAR which resets all variables and clears client mail queues.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85425] MOOS-IvP iSay through 24.8.1 contains a remote code execution vulnerability in the SAY_MOOS variable…
MOOS-IvP iSay through 24.8.1 contains a remote code execution vulnerability in the SAY_MOOS variable handler that passes unsanitized text to a shell command. Attackers can publish SAY_MOOS messages containing backticks or command substitution syntax to execute arbitrary commands as the iSay process user.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85426] MOOS-IvP uMemWatch through 24.8.1 constructs shell commands from attacker-chosen MOOS client names w…
MOOS-IvP uMemWatch through 24.8.1 constructs shell commands from attacker-chosen MOOS client names without sanitization. Attackers can inject shell metacharacters into client names to execute arbitrary commands as the uMemWatch process user through unquoted redirection targets in system calls.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85428] MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB…
MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server that allows unauthenticated clients to write variables. Attackers can send HTTP requests with variable names and values to the MOOSDB HTTP server port to modify MOOS variables including actuator and override commands without authentication.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-70352] Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to…
Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-80098] Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker t…
Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-83711] Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an u…
Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-62916] Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorize…
Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.