Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,395
Total alertas
4758
Críticas
17006
Altas
8
Ransomware
1254
Esta semana
RSS
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85223] A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functio…
A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Performing a manipulation of the argument callback_url/sync_interval results in os command injection. The attack can be initiated remotely. The exploit has been made public and could be used.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85224] A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part o…
A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executing a manipulation of the argument fileurl can lead to os command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85061] MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanit…
MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/dom.ts iterates elem.attributes as a live NamedNodeMap while removeAttributes() removes attributes from the same collection, shifting indexes and skipping an adjacent dangerous attribute. An attacker who controls untrusted third-party style attribution strings or user-supplied cust…
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85222] A vulnerability has been found in D-Link DNS-340L 1.01B04. Affected by this vulnerability is an unkn…
A vulnerability has been found in D-Link DNS-340L 1.01B04. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/addon_center.cgi of the component Add-On Center. Such manipulation of the argument f_name/f_url/f_flag/f_login_user leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85050] Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote …
Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85047] Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82…
Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85042] Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to exec…
Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85394] python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepti…
python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's public key can forge HS256 tokens that pass verification when algorithms are not explicitly restricted. This is an incomplete fix for CVE-2024-33663.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85391] Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows u…
Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use the published secret to mint valid tokens for arbitrary user IDs and access protected endpoints without credentials.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-82526] R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attacke…
R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL statements by manipulating the index name parameter in the vector index creation endpoint. The index name is interpolated directly into a CREATE INDEX statement via string formatting without identifier quoting or allowlist validation, enabling arbitrary DDL and DML execut…
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-58400] GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.…
GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the Saxon XSLT processor used to render formatters is configured without secure processing (`FEATURE_SECURE_PROCESSING`) and without disabling Java extension functions (`ALLOW_EXTERNAL_FUNCTIONS`). Any stylesheet loaded by GeoNetwork can therefore invoke `java.lang.Runtime.exec()` or …
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-84813] Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions.
Unauthenticated SQL Injection in GeoDirectory
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-84814] Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions.
Subscriber Privilege Escalation in Bricksforge
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-84834] Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.
Unauthenticated PHP Object Injection in JobSearch
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-84768] Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions.
Unauthenticated SQL Injection in VikAppointments Services Booking Calendar

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-84238] Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versi…
Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-84753] Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.
Unauthenticated PHP Object Injection in Mail Mint
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85181] CAT uses Java String.hashCode as the sole integrity check for session cookies without server-side ke…
CAT uses Java String.hashCode as the sole integrity check for session cookies without server-side keying, allowing attackers to forge valid checksums offline. Attackers can set the x-forwarded-for header to bypass IP binding validation and create admin sessions with full configuration access.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85183] Taipy configures its socket.io server with wildcard CORS origin and credential flag enabled, allowin…
Taipy configures its socket.io server with wildcard CORS origin and credential flag enabled, allowing any web page to establish credentialed WebSocket connections to victim applications. Attackers can open socket.io sessions from arbitrary domains and invoke state variable modifications and action callbacks without CSRF protection.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85109] A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of…
A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of the file /boaform/formLogin of the component Boa Web Server. Executing a manipulation of the argument Username can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.