Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
Buscando: "Progress" — 16 resultados ✕ Limpiar búsqueda
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1002
Esta semana
RSS
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-91140] An OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Prog…
An OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 allows an attacker who supplies a crafted Swagger/OpenAPI document to execute arbitrary commands on a developer's machine when a user invokes the generator.
M Crítico vulnerabilidad
27/09/2026
Inyección Eval crítica en hMailServer 6.0.0-6.3.3 permite ejecución remota de código
Una vulnerabilidad crítica (CVSS 9.8) en el despachador de scripts JScript de hMailServer permite a atacantes no autenticados ejecutar código arbitrario con privilegios de servicio. La falla se activa mediante contraseñas manipuladas con secuencias de escape en autenticación SMTP, POP3 e IMAP. Afecta principalmente a servidores de correo en Windows en organizaciones de México y LATAM que usen versiones 6.0.0 a 6.3.3.
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-80519] In the Linux kernel, the following vulnerability has been resolved: ovpn: finish crypto callback cl…
In the Linux kernel, the following vulnerability has been resolved: ovpn: finish crypto callback cleanup before peer release Crypto completion callbacks hold both key-slot and peer references. The peer reference pins the netdev, and dropping the last peer reference can let netdev unregistration and module removal make progress. Do not release that peer reference before the callback has finished…
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-9192] An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11…
An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, including administrators.
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-9193] An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Serve…
An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations against the Security database.
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-9195] A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6…
A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a crafted URL to execute arbitrary JavaScript in the administrator's browser session, capture credentials, and perform privileged actions on the administrator's behalf.
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-7329] An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces o…
An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges to administrator. This enables execution of privileged operations and unauthorized data access.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-7557] An improper verification of cryptographic signature vulnerability in the SAML authentication module …
An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled.
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-8709] An improper privilege management vulnerability in the REST API document patch operation of Progress …
An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges and execute privileged operations against the Security database.
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-9190] An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 1…
An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication and authorization checks, hijack a legitimate user's session, or capture credentials. The vulnerability occurs when a crafted HTTP request containing both Content-Length and Transfer-Encoding headers causes a reverse proxy and MarkLo…
M Crítico vulnerabilidad
16/07/2026
[CVE-2026-45336] HireFlow is a web-based interview management system for managing candidates, scheduling interviews, …
HireFlow is a web-based interview management system for managing candidates, scheduling interviews, and tracking hiring progress. In 1.2 and earlier, app.py assigns a hard-coded Flask secret_key used to sign session cookies, allowing unauthenticated attackers who know the public source value to forge cookies containing role=admin and user_id values and bypass authentication. The advisory lists ver…
L Crítico vulnerabilidad
24/06/2026
[CVE-2026-53046] In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free from …
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free from async crypto on Qualcomm crypto engine ksmbd_crypt_message() sets a NULL completion callback on AEAD requests and does not handle the -EINPROGRESS return code from async hardware crypto engines like the Qualcomm Crypto Engine (QCE). When QCE returns -EINPROGRESS, ksmbd treats it as an error and imm…
M Crítico vulnerabilidad
11/06/2026
[CVE-2026-45060] ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #129, the actions/p…
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #129, the actions/progress_video.php endpoint is vulnerable to blind SQL injection. Any unauthenticated user can exploit the ids parameter to execute SQL queries and exfiltrate sensitive data. This issue has been patched in version 5.5.3 - #129.
P Crítico vulnerabilidad
04/06/2026
[CVE-2026-8037] OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an u…
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints
P Crítico vulnerabilidad
02/06/2026
[CVE-2026-7198] CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 a…
CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unauthenticated attacker to access content that should be restricted, resulting in full compromise of confidentiality, integrity, and availability of affected installations.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
P Crítico vulnerabilidad
02/06/2026
[CVE-2026-7312] CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14…
CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14.0.7700 to 14.4.8152, and 15.0.8200 to 15.0.8234, and 15.1.8300 to 15.1.8335, 15.2.8400 to 15.2.8441, 15.3.8500 to 15.3.8531, and 15.4.8600 to 15.4.8630 allows a remote unauthenticated attacker to obtain plain-text credentials used connect to Sitefinity Insight service. Successful exploitation requi…