Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Multiple Vendors" — 3587 resultados ✕ Limpiar búsqueda
22,395
Total alertas
4758
Críticas
17006
Altas
8
Ransomware
1254
Esta semana
RSS
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-75604] Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and…
Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without Cache Components on Windows-hosted servers do not consistently escape backslashes in route segments before constructing incremental-cache paths. In packages/next/src/shared/lib/router/utils/escape-path-delimiters.ts and packages/…
M Crítico vulnerabilidad
01/09/2026
[CVE-2023-54391] Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in …
Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login endpoint. Attackers can send a POST request to the access ticket API endpoint with a…
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-73749] Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malfo…
Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service. Successful exploitation could result in remote code execution with elevated privileges.
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-76658] A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could a…
A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system leading to complete system compromise.
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-76657] Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potenti…
Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the HPE Networking Fabric Composer host.
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-73700] A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow …
A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-73701] An unauthenticated remote code execution vulnerability exists in the underlying operating system of …
An unauthenticated remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer and could be exploited if certain preconditions outside of the attacker's control are met. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to execute arbitrary code as a privileged user on the underlying operating system, le…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-19766] An authentication bypass vulnerability exists in the underlying operating system of HPE Networking F…
An authentication bypass vulnerability exists in the underlying operating system of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated adjacent attacker to execute arbitrary code as a privileged user on the underlying operating system, leading to complete compromise of the AFC host.
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-79687] Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unau…
Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access.
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-18931] Use of Hard-coded Credentials vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Ind…
Use of Hard-coded Credentials vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Retrieve Embedded Sensitive Data. This issue affects Talassoft Industrial Management Software: from V.4 before V.16.
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-78012] An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-messa…
An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-message request to exceed the application-side receive buffer without generating an error or warning. The result could be memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed.
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-18808] Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical Electr…
Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical Electronics Inc. KIO (Klemsan Internet Objects) allows Code Injection. This issue affects KIO (Klemsan Internet Objects): before v1.9.
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-18210] Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i…
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Products's Store allows SQL Injection. This issue affects Products's Store: before 030631b2.
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-84119] Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed …
Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2.
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-84121] Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in…
Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-51743] Incorrect access control in the guest_wifi_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows…
Incorrect access control in the guest_wifi_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to disable guest virtual AP interfaces via sending a crafted MQTT message to the cs_broker component.
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-18765] Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i…
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Teracity Software Technologies Inc. E-OSB allows SQL Injection. This issue affects E-OSB: before V02.26.07.08.01.
M Crítico vulnerabilidad
01/09/2026
Falla crítica en manejo de excepciones de Kyverno v1.9.0-v1.12.7 permite eludir políticas de seguridad
Kyverno versiones 1.9.0 a 1.12.7 contienen una vulnerabilidad en el procesamiento de excepciones de políticas que permite a atacantes eludir controles de seguridad. Cuando una política en modo enforce se combina con dos PolicyExceptions, la excepción menos restrictiva toma precedencia, permitiendo contravenir restricciones críticas mediante nombres de recursos diseñados. Esto afecta directamente a organizaciones en LATAM que dependen de Kyverno para governanza de Kubernetes en producción.
M Crítico vulnerabilidad
01/09/2026
Escalada de privilegios crítica en tema WordPress Nokri - Validación insuficiente de tokens
El tema WordPress Nokri Job Board contiene una vulnerabilidad de escalada de privilegios en versiones hasta 1.6.6 que permite a atacantes no autenticados tomar control de cuentas de usuario. La falla radica en validación deficiente de tokens de reinicio de contraseña en la función `nokri_reset_password()`, que acepta tokens vacíos coincidiendo con valores de metadata desconfigurados. Esto afecta directamente a empresas de LATAM que operan portales de empleo en WordPress, exponiendo bases de datos de candidatos y datos administrativos.
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-83772] A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satellite Router up to 20260704. Thi…
A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satellite Router up to 20260704. This issue affects the function c_set_reports_decode of the file mail-report.sh of the component JSON Parsing. The manipulation of the argument sender/recipients results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contact…