Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ui" — 666 resultados ✕ Limpiar búsqueda
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1016
Esta semana
RSS
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-90042] In the Linux kernel, the following vulnerability has been resolved: ceph: properly decrypt filename…
In the Linux kernel, the following vulnerability has been resolved: ceph: properly decrypt filenames in vmalloc() buffers The fscrypt subsystem uses the scatterlist crypto API, inheriting its requirement that any buffers are in the linear mapping region. However, the messenger client uses kvmalloc() to create buffers for messages, which will occasionally place those buffers in the vmalloc() regi…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-89914] In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Sign-extend VA for …
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Sign-extend VA for range-based TLBI invalidation When the decode_range_tlbi() helper was moved to be used for S1 TLBIs, the required sign extension was omitted. Add it. As a result, special care must be taken to not overflow PA bits when this is used for S2 invalidation.
M Crítico vulnerabilidad
16/09/2026
Vulnerabilidad crítica en Arista EOS con P4Runtime permite ejecución remota de código
Una vulnerabilidad de puntuación CVSS 10 en Arista EOS permite que clientes no autenticados ejecuten código arbitrario con privilegios administrativos en switches configurados con P4Runtime. Aunque P4Runtime está deshabilitado por defecto, equipos que lo han activado para programabilidad de red enfrentan riesgo crítico. Esta falla afecta especialmente a proveedores de servicios y operadores de centros de datos en Latinoamérica que utilizan infraestructura Arista.
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-89788] In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix tree connection use-…
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix tree connection use-after-free in smb2_tree_connect() ksmbd_tree_conn_connect() publishes a new tree connection in sess->tree_conns with a single reference and returns its pointer to smb2_tree_connect(). The handler continues to initialize the object and build the response after publication. A concurrent session logof…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-12793] The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Esc…
The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.6.2. This is due to the plugin not validating that a submitted form ID belongs to a JetFormBuilder form before parsing the referenced post's content as form schema and executing an Advanced Validation server-side callback. This makes it possible for un…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-83462] Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component:…
Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Mobile Application Server. Successful attacks of this vulnerability can result in takeover of Oracle Mob…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-83452] Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite…
Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Document Management and Collaboration. Successful attacks of this vulnerability can result …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-83327] Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Pe…
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in takeover of Oracle Applications…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-83154] Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Support…
Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Siebel CRM End User. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical da…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-83149] Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.…
Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows low privileged attacker having Test Manager for Web Apps privilege with network access via HTTP to compromise Oracle Application Testing Suite. While the vulnerability is in Oracle Application Testing Suite, attacks may significantly impact additional pr…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-83040] Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet…
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle WebCenter Portal. Successful attacks require human interaction from a person other than the attacker a…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-83042] Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Leg…
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Mana…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-83043] Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Compose…
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks require human interaction from a person other than the attacker and while…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-73957] Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet…
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks require human interaction from a person other than the attacker a…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-19773] libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerabili…
libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of libwebsockets. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parsing of HTTP/2 HPACK path header. The issue results from the lack of proper valid…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-53710] MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to …
MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the python_sandbox_server in mcp-servers/python/python_sandbox_server/src/python_sandbox_server/server_fastmcp.py exposes raw getattr through safe_builtins, omits a required _getattr_ guard, and relies on validate_code checks for literal dangerous dunder strings. An attacker can construct dun…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-55158] Conflibot warns in advance when merging a pull request will cause conflicts in other open pull reque…
Conflibot warns in advance when merging a pull request will cause conflicts in other open pull requests. Prior to 1.2.1, src/index.ts builds git checkout, git merge, and git format-patch commands by interpolating the attacker-controlled pull request head.ref value into strings passed to exec. In the documented pull_request_target configuration, an attacker can open a pull request, including from a…
M Crítico vulnerabilidad
15/09/2026
Vulnerabilidad crítica de bypass de autorización en Casdoor 4.4.0 y anteriores
Casdoor versiones hasta 4.4.0 presenta una vulnerabilidad de bypass de autorización en el endpoint /api/mcp que permite a atacantes con credenciales válidas (clientId y clientSecret) de cualquier aplicación acceder sin restricciones a la administración de usuarios en todas las organizaciones. Los atacantes pueden enumerar registros de usuarios incluyendo salts de contraseñas y direcciones de correo, crear cuentas administrativas, modificar y eliminar usuarios existentes. Este riesgo es crítico para empresas en LATAM que utilizan Casdoor en entornos de producción con múltiples organizaciones o tenants.
M Crítico vulnerabilidad
15/09/2026
Vulnerabilidad crítica de autenticación en Pig anterior a 4.1.0 permite control administrativo
Pig versiones anteriores a 4.1.0 presentan una vulnerabilidad de omisión de autenticación en el endpoint /register/password que descarta la verificación de contraseña actual, permitiendo a atacantes remotos reescribir credenciales de cualquier cuenta incluyendo administrador con CVSS 9.1. Esta falla expone sistemas de gestión de identidades en empresas LATAM a toma de control administrativo completo sin credenciales válidas.
M Crítico vulnerabilidad
15/09/2026
Vulnerabilidad crítica en PraisonAI permite ejecución remota de código malicioso
PraisonAI versiones 1.4.0 a 1.7.2 contienen una vulnerabilidad de ejecución de código no autorizado (CVSS 9.9) en el módulo code-mode.ts. Un atacante puede eludir el sandbox de JavaScript utilizando técnicas de prototipado para recuperar el constructor Function real y acceder a process, comprometiendo completamente sistemas que ejecuten agentes multi-IA. Este riesgo afecta directamente a empresas en LATAM que implementan automatización con PraisonAI en entornos productivos.