Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
Buscando: "Rti" — 183 resultados ✕ Limpiar búsqueda
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1002
Esta semana
RSS
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-96207] Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to eleva…
Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-95210] Improper certificate validation in gnutls v3.8.13 causes the application to accept certificates cont…
Improper certificate validation in gnutls v3.8.13 causes the application to accept certificates containing invalid extensions.
M Crítico vulnerabilidad
Hace 1 día
Vulnerabilidad crítica en AKINSOFT WOLVOX permite extracción de datos sensibles del sistema
Se ha identificado una vulnerabilidad de inserción de información sensible en el Panel de Control de AKINSOFT WOLVOX (versiones 26.02.25 anteriores a 26.02.26) que permite a atacantes extraer datos de recursos del sistema. Esta falla afecta principalmente a empresas de importación-exportación en México y Latinoamérica que utilizan esta solución para gestión operativa. El score CVSS de 9.1 indica severidad crítica.
M Crítico vulnerabilidad
Hace 2 días
Vulnerabilidad crítica en LMCache: ejecución remota de código en modo distribuido
LMCache en modo distribuido expone un socket ZeroMQ ROUTER sin autenticación que permite a atacantes remotos ejecutar código arbitrario mediante deserialización insegura con pickle. La vulnerabilidad afecta infraestructuras de procesamiento de caché distribuido en centros de datos y servicios en la nube utilizados por empresas en LATAM. Un atacante no autenticado puede registrar procesos maliciosos y comprometer toda la arquitectura de caché compartida.
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-104286] An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in F…
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-102149] Kiteworks Email Protection Gateway did not sufficiently restrict which account a certificate could b…
Kiteworks Email Protection Gateway did not sufficiently restrict which account a certificate could be assigned to. This could allow an attacker to associate a certificate with another user's account, affecting the confidentiality and integrity of that account's encrypted mail and, where certificate-based login is enabled, potentially permitting unauthorized access to the account.
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-88920] An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote…
An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML sender-vouches assertion containing an attacker-controlled key. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-84436] IBM Guardium Data Protection 12.2 is vulnerable to command injection in the certificate export CLI f…
IBM Guardium Data Protection 12.2 is vulnerable to command injection in the certificate export CLI functionality, allowing a privileged authenticated CLI user to execute arbitrary commands with root privileges.
M Crítico vulnerabilidad
28/09/2026
Vulnerabilidad crítica de desbordamiento de búfer en FAST FAC1200R 5.0
Se ha identificado un desbordamiento de búfer basado en pila (stack-based buffer overflow) en la función parse_advertisement_frame del servicio devdiscover del dispositivo FAST FAC1200R versión 5.0_20201119_1.0.2, con puntuación CVSS 9.9. La vulnerabilidad puede ser explotada remotamente sin autenticación, permitiendo ejecución de código arbitrario en routers empresariales y de pequeños negocios ampliamente desplegados en México y Latinoamérica. El exploit es público y el fabricante no ha respondido a solicitudes de parche.
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-93291] Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-m…
Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code.
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-19072] Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the …
Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each endpoint in the hunt. Although the field "compiled_collector_args" is an internal field, Velociraptor allowed the field to be set from a user API call. This allows another user who can schedule a hunt (minimal role of "investigator" ) to set the compiled VQL statements for the hun…
M Crítico vulnerabilidad
23/09/2026
[CVE-2026-82843] The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0 does not bind the OpenID …
The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0 does not bind the OpenID Connect identity assertion it issues to the authorization grant being exchanged, returning instead the assertion belonging to whichever user authenticated most recently, which allows users with the Subscriber role and above to obtain a validly signed identity assertion for another user, including an…
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-57149] plone.app.portlets.portlets provides a Plone-specific user interface for plone.portlets, as well as …
plone.app.portlets.portlets provides a Plone-specific user interface for plone.portlets, as well as a standard set of portlets that ship with Plone. Starting in version 5.0.0 and prior to versions 5.0.8, 6.0.4, and 7.0.2, the Classic portlet (plone.app.portlets.portlets.classic) used its user-supplied template/macro fields to build a TALES path expression that was then evaluated by the TAL path() …
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-84388] A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Ext…
A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4 all versions may allow attacker to information disclosure via remote unauthenticated attack
M Crítico vulnerabilidad
21/09/2026
[CVE-2026-94301] The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypa…
The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committed to the  2.2.X branch only. The 2.0.X and 2.1.X maintenance branches never received the resolveProxyClass() override, so the 2.0.29 and 2.1.13 artifacts listed a…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-75885] A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/d…
A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Request Forgery (SSRF), where the console pod makes requests to internal services and reflects partial responses to the attacker. Additionally, by sending repeated large requests withou…
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-80442] IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerabili…
IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the exportCertificate functionality. Successful exploitation could allow an attacker to execute unauthorized commands and impact the confidentiality, integrity, and availability of the affected system.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-61781] pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, …
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, create_partition_time() reads the writable part_config.time_encoder text value and interpolates it without identifier quoting into a dynamically executed SELECT statement. A role with the documented partman_user INSERT and UPDATE privileges can store SQL rather than a function name. When pg_partman_…
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-61550] Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate…
Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JSON-RPC message handling does not validate that the sender is a trusted endpoint. An unauthenticated network attacker able to connect to TCP port 5665 can replace the node certificate and trusted CA certificate, impersonate a trusted node, and take control of the node. This issue is fixed i…
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-59163] Mnemosyne is a memory layer for artificial intelligence agents. Prior to v3.10.1, the auth check in …
Mnemosyne is a memory layer for artificial intelligence agents. Prior to v3.10.1, the auth check in mnemosyne/core/sync_server.py parsed the JWT's header and payload using base64 decoding, then passed the token to a jwt library call with options that effectively disabled signature verification. The server accepted any well-formed token regardless of the signature, including tokens with alg: none a…