Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 49 min
Buscando: "Multiple Vendors" — 3587 resultados ✕ Limpiar búsqueda
22,395
Total alertas
4758
Críticas
17006
Altas
8
Ransomware
1253
Esta semana
RSS
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-40541] An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerabilit…
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, via a UI interaction, to read or write arbitrary files and conduct denial-of-service attacks in DSM.
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-82082] NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remot…
NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server.
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-61800] Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints an…
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.4.0 through 4.14.6, a party holding the cluster key can write, overwrite, or delete arbitrary files under /var/ossec on worker nodes, leading to remote code execution as root. During cluster file synchronization, the non-merged branch of update_master_files_in_worker…
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-78239] Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, …
Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remote attacker to enable administrative services that should be restricted. Successful exploitation may permit unauthorized access to the device.
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-76943] Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allo…
Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to bypass intended access controls and obtain command execution capabilities. Successful exploitation could allow unauthorized interaction with privileged functionality and may lead to complete device compromise.
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-76179] An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway produ…
An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products. Authentication tokens used by the web management interface are insufficiently protected during client-side session handling, which may allow an attacker with access to exposed session information to obtain and reuse a valid token. Successful exploitation could allow an attacker to impersona…
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-75337] The static resource interface /api/static/{deployKey}/ of Yu AI Code Mother v4.3 is vulnerable to pa…
The static resource interface /api/static/{deployKey}/ of Yu AI Code Mother v4.3 is vulnerable to path traversal. The user-controlled path is concatenated to the preview root directory without any normalization, allowing anonymous attackers to read files outside the preview root.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-73125] Ebyte device web management interface does not consistently enforce authentication before granting …
Ebyte device web management interface does not consistently enforce authentication before granting access to administrative functionality. An unauthenticated remote attacker could access sensitive configuration information, modify device settings, or disrupt availability.
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-71187] The Ebyte device relies on client side authentication logic that can be reproduced by unauthenticat…
The Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An attacker may generate valid authentication requests and bypass authentication to obtain administrative access to the device.
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-69658] MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information t…
MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information to network-level attackers. This may enable unauthorized device impersonation and disruption of messaging functions.
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-50152] Ceph is an open-source distributed storage platform providing object, block, and file storage. In ve…
Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Monitor subscription handler fails to properly authorize access to the configuration-key store, allowing any CephX user with only  `mon allow r` capabilities to read the entire store by sending a single crafted MMonSubscribe message. The config-key store holds …
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-81934] Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handl…
Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands with the privileges of the Redis server. Fixed in Redis 8.2.9, 8.4.6, 8.6.6, 8.8.2, and 8.10.1.
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-19092] The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal …
The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables while rendering templates, allowing unauthenticated users to invoke arbitrary zero-argument PHP functions and receive their output.
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-81735] startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::…
startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was given, so startSseAndStreamableHttpMcpServer bound the Streamable HTTP and SSE MCP transports to every interface, and its authentication middleware was optional: middlewares are applied only when a caller supplies them. The @agent-infra/mcp-server-commands and @agent-infra/mcp-ser…
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-81707] openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allow…
openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inject ANSI escape sequences that forge the fingerprint verification line displayed to users. Attackers can deliver a crafted identity bundle through normal contact-exchange flows or keyserver responses to manipulate terminal output and display a fraudulent fingerprint, bypassing th…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-81700] openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.v…
openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that accepts revoked and expired keys by only checking VALIDSIG status without inspecting REVKEYSIG, EXPKEYSIG, or gpg exit codes. Attackers holding compromised-then-revoked signing keys or expired project keys can bypass signature verification to execute malicious plugins in the host…
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-81701] openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing …
openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-level plugins/ directories and unknown subdirectories to bypass signature verification. Attackers can place malicious unsigned plugins following documented installation paths to achieve arbitrary code execution in the CLI process with access to passwords and cryptographic key…
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-81702] openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities fr…
openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identity stores. Attackers can replace legitimate public keys with their own while maintaining the claimed fingerprint, enabling silent key substitution where encryption uses attacker keys and signature verification appears valid.
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-81098] The Telnyx MCP server exposed its HTTP transport on every interface and did not require a caller cre…
The Telnyx MCP server exposed its HTTP transport on every interface and did not require a caller credential. packages/mcp-server/src/http.ts served MCP on the root path with a listener bound to all interfaces and parsed the caller's authentication headers in a mode that did not fail when they were absent, so a request without any credential completed initialisation and dispatched tools. Dispatch f…
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-81094] The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only whe…
The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only when the operator asked for it. The serve command in apps/cli/src/commands/serve.ts defaulted its host to the all-interfaces address on a fixed port, and required a token only when the corresponding flag was supplied, so a default invocation exposed the aggregator, and every MCP server it fronted, to a…