Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1778
Esta semana
RSS
M Crítico vulnerabilidad Nuevo
Hace 16 horas
[CVE-2026-7808] justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dange…
justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive sanitization, potentially leading to cross-site scripting. The issues primarily affect advanced usage rather than the default JustHTML(..., sanitize=True) path for ordinary parsed HTML: mutating or reusing sanitization policy objects (including exporte…
M Crítico vulnerabilidad Nuevo
Hace 16 horas
[CVE-2026-5388] justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_valu…
justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Markdown passthrough (html_passthrough=True), and several custom sanitization-policy edge cases. Depending on configuration, an attacker can bypass sanitization to inject active HTML and JavaScript — for example via encoded javascript: URLs, backslash-b…
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-48755] Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation…
Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads to an arbitrary file write on the host, possibly leading to arbitrary command execution. Version 7.1.0 patches the issue.
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-48769] Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file w…
Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead to arbitrary command execution as root on the server. Version 7.2.0 patches the issue.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-66785] A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect ne…
A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect network traffic from other connected clusters (peer clusters) by publishing a specially crafted network endpoint. The system fails to properly validate the network subnets provided by the malicious cluster, enabling it to declare arbitrary network ranges. Consequently, all network traffic intended for…
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-20318] As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Wo…
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20318 are related to improper input validation issues that ar…
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-49827] WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1…
WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote Code Execution. Combined with open registration (no invite required) and broken role middleware (CheckUserRole silently swallows RouteNotFoundException), this chai…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-48056] Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions p…
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 improperly validate executable paths supplied to the  run-download  IPC handler, allowing a compromised renderer process to execute arbitrary local binaries with the application’s privileges. Version 2.5.0 contains a patch.
M Crítico vulnerabilidad
10/08/2026
[CVE-2026-72867] Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, the incomp…
Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, the incomplete fix for CVE-2026-45628 leaves packages/server/src/db/schema/compose.ts branch fields without server-side validation, allowing a direct compose.update request to store a malicious customGitBranch, branch, gitlabBranch, bitbucketBranch, or giteaBranch. A low-privileged authenticated user can trig…
M Crítico vulnerabilidad
07/08/2026
Vulnerabilidad crítica en Kata Containers permite ejecución de código en el host
Kata Containers anterior a versión 4.0.0 es vulnerable a ejecución de código en el host mediante anotaciones de configuración sin validar. Un atacante puede especificar una ruta TOML arbitraria a través de la anotación io.katacontainers.config_path para cargar archivos maliciosos del host. Esta vulnerabilidad afecta infraestructuras containerizadas en datacenters y plataformas cloud de empresas LATAM que ejecuten orquestación con Kubernetes.
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-57817] The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter …
The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache CXF RP is integrated with a non-compliant or misconfigured Identity Provider (IdP) that omits the `c_hash`, the RP becomes vulnerable to Authorization Code Substitution/Injection attacks. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3…
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-20303] As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst …
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20303 are related to improper input validation issues that are g…
M Crítico vulnerabilidad
01/08/2026
Vulnerabilidad crítica de bypass de autorización en @better-auth/scim (CVE-2026-67330)
El plugin @better-auth/scim para better-auth en versiones 1.4.0-beta.27 a 1.6.21 y 1.7.0-beta.0 a 1.7.0-beta.9 contiene una falla de autorización que permite a atacantes reutilizar identificadores de proveedores SSO/SAML/OIDC existentes en la emisión de tokens SCIM, comprometiendo la identidad de usuarios y cuentas corporativas. Afecta principalmente sistemas de gestión de identidades y acceso (IAM) en empresas que implementan provisionamiento automático de usuarios.
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-18002] Insufficient validation of untrusted input in Google Lens in Google Chrome prior to 151.0.7922.72 al…
Insufficient validation of untrusted input in Google Lens in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17987] Insufficient validation of untrusted input in Notifications in Google Chrome prior to 151.0.7922.72 …
Insufficient validation of untrusted input in Notifications in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted PDF file. (Chromium security severity: Low)

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17990] Insufficient validation of untrusted input in WebAuthn in Google Chrome prior to 151.0.7922.72 allow…
Insufficient validation of untrusted input in WebAuthn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted PDF file. (Chromium security severity: Low)
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17991] Insufficient validation of untrusted input in AI in Google Chrome prior to 151.0.7922.72 allowed a r…
Insufficient validation of untrusted input in AI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17940] Insufficient validation of untrusted input in Picture-in-Picture in Google Chrome on Android prior t…
Insufficient validation of untrusted input in Picture-in-Picture in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17847] Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed …
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17848] Integer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to pote…
Integer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium)