Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 min
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1012
Esta semana
RSS
M Crítico vulnerabilidad Nuevo
Hace 4 horas
[CVE-2026-100730] A service console interface on openPDC and openHistorian deserializes a client-supplied data structu…
A service console interface on openPDC and openHistorian deserializes a client-supplied data structure. On systems using Windows Authentication, an attacker must already be authenticated to reach this function; on systems without Windows Authentication, this is reachable by an unauthenticated network attacker. This allows an attacker to trigger deserialization of an arbitrary object graph, which c…
M Crítico vulnerabilidad Nuevo
Hace 19 horas
[CVE-2026-88131] Deserialization of untrusted data in Microsoft Dataverse allows an unauthorized attacker to execute …
Deserialization of untrusted data in Microsoft Dataverse allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad Nuevo
Hace 21 horas
[CVE-2026-78401] IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 …
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
M Crítico vulnerabilidad Nuevo
Hace 21 horas
[CVE-2026-78406] IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 …
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-93034] SGLang contains an arbitrary code execution vulnerability caused by the ZMQ message decoder uncondit…
SGLang contains an arbitrary code execution vulnerability caused by the ZMQ message decoder unconditionally deserializing PickleWrapper payloads via pickle.loads() in _maybe_unwrap_pickle without type allowlisting or authentication; this vulnerability persists via the msgpack path even when SGLANG_USE_PICKLE_IPC is disabled, and becomes remotely exploitable if data-parallel attention is enabled wi…
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-95606] Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP The Events Calendar allows…
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP The Events Calendar allows Object Injection. This issue affects The Events Calendar: from n/a through 6.17.4.
M Crítico vulnerabilidad
Hace 2 días
Vulnerabilidad crítica en LMCache: ejecución remota de código en modo distribuido
LMCache en modo distribuido expone un socket ZeroMQ ROUTER sin autenticación que permite a atacantes remotos ejecutar código arbitrario mediante deserialización insegura con pickle. La vulnerabilidad afecta infraestructuras de procesamiento de caché distribuido en centros de datos y servicios en la nube utilizados por empresas en LATAM. Un atacante no autenticado puede registrar procesos maliciosos y comprometer toda la arquitectura de caché compartida.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-39797] Unauthenticated PHP Object Injection in GDPR Framework By Data443 <= 2.5.0 versions.
Unauthenticated PHP Object Injection in GDPR Framework By Data443
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-97283] Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP Advanced Post Manager adva…
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP Advanced Post Manager advanced-post-manager allows Object Injection.This issue affects Advanced Post Manager: from n/a through 4.5.5.
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-55083] DHIS2 is a flexible information system for data capture, management, validation, analytics and visua…
DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. From versions 2.42.0 to before 2.42.5.1, and from versions 2.43.0 to before 2.43.0.1, DHIS2 is vulnerable to remote code execution (RCE) via unsafe Java deserialization. This issue has been patched in versions 2.42.5.1, 2.43.0.1, and 2.44.
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-100512] Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions.
Contributor PHP Object Injection in Nested Pages
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-103395] LightLLM through 1.2.0 visual_only deployments expose an unauthenticated RPyC service with allow_pic…
LightLLM through 1.2.0 visual_only deployments expose an unauthenticated RPyC service with allow_pickle enabled that deserializes attacker-supplied arguments in the remote_infer_images method. Attackers can reach the visual RPyC port and pass objects with __reduce__ methods to execute arbitrary code with service account privileges.
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-97248] Unauthenticated PHP Object Injection in Booking Activities <= 1.18.7.1 versions.
Unauthenticated PHP Object Injection in Booking Activities
M Crítico vulnerabilidad
30/09/2026
Vulnerabilidad crítica de deserialización insegura en EasyFlow .NET de Digiwin (CVE-2026-102455)
EasyFlow .NET contiene una vulnerabilidad de deserialización insegura que permite a atacantes no autenticados ejecutar código arbitrario en servidores. El riesgo es crítico (CVSS 9.8) para empresas manufactureras y de logística en LATAM que usan esta plataforma de automatización de flujos. Los atacantes pueden comprometer completamente infraestructuras empresariales sin requerir credenciales.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-103040] LightLLM through 1.2.0 contains a remote code execution vulnerability in the router profiler service…
LightLLM through 1.2.0 contains a remote code execution vulnerability in the router profiler service when started with --enable_profiling flag. The service exposes an unauthenticated RPyC server with pickle deserialization enabled, allowing attackers to execute arbitrary code by sending crafted serialized objects to the profiler command queue.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-103041] LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pick…
LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Attackers can send crafted serialized objects to exposed cache methods to execute arbitrary code with service privileges.
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-82384] Deserialization of Untrusted Data in Apache Roller 6.1.5 allows an unauthenticated remote attacker t…
Deserialization of Untrusted Data in Apache Roller 6.1.5 allows an unauthenticated remote attacker to cause deserialization of attacker-controlled bytes, because the XML-RPC endpoint accepts vendor extension types that are deserialized during request parsing, before authentication. The servlet is mapped unconditionally, so parsing occurs even when the global XML-RPC feature is set to disabled; no …
M Crítico vulnerabilidad
23/09/2026
[CVE-2026-96560] LightLLM through 1.2.0 contains a remote code execution vulnerability in the KV-transfer worker when…
LightLLM through 1.2.0 contains a remote code execution vulnerability in the KV-transfer worker when started with --pd_trans_mode nccl, which exposes an unauthenticated RPyC control channel that deserializes attacker-supplied data. Attackers can send malicious pickled objects to the exposed RPyC ThreadedServer to execute arbitrary code with the privileges of the LightLLM service account.
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-18163] IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execut…
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper deserialization of untrusted data.
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-93088] SGLang's multimodal generation runtime is vulnerable to unauthenticated arbitrary code execution bec…
SGLang's multimodal generation runtime is vulnerable to unauthenticated arbitrary code execution because the disaggregated-diffusion orchestrator's DiffusionServer binds an unauthenticated ZeroMQ ROUTER socket to a network interface and passes the final frame of received multipart messages directly to pickle.loads() before any validation occurs.