Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1002
Esta semana
RSS
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-82973] Improper neutralization of CRLF sequences in IMAP command construction in psyb0t/docker-mailbox befo…
Improper neutralization of CRLF sequences in IMAP command construction in psyb0t/docker-mailbox before 0.4.13 allows a remote unauthenticated attacker, when bearer-token authentication is not configured, to inject additional IMAP commands into an authenticated upstream mailbox connection via crafted folder, UID, or search values.
M Crítico vulnerabilidad
26/09/2026
[CVE-2026-100717] froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl reje…
froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return and line feed characters only in the path, query and fragment components returned by parse_url, and never inspects the userinfo (user:pass@) components. This is an incomplete fix for GHSA-c3p2. An authenticated low-privilege customer with subdomain-create rights (no admin or chan…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-90937] froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowi…
froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives. Attackers can supply URLs containing literal newlines that are written verbatim into vhost config files during cron rebuild, enabling web server configuration corruption, denial of service, or hijacking of HTTP …
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-75925] Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker…
Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted by the local service are written to a file later consumed by a privileged subprocess, without line-ending sequences being neutralized, which allows additional directives to be introduced into that file. The configuration interface…
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-84372] Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 un…
Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replication connections reparses an already serialized RESP buffer in AbstractAggregateConnection::write() by splitting it with explode("\r\n") instead of honoring RESP length prefixes. Attacker-controlled keys or values containing CRLF s…
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-82854] Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.siz…
Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter. When an application passes a custom envelope object with a size property containing CRLF characters to sendMail(), the value is concatenated into the SMTP MAIL FROM command (as SIZE=...) without sanitization, allowing injection of arbitrary SMTP commands such as RCPT TO to silently add …
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-47890] Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Event…
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-77549] A malicious actor with access to the network and under certain conditions could exploit an Improper …
A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances.
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-77550] A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequen…
A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances.
M Crítico vulnerabilidad
10/08/2026
Inyección de comandos OS en crontab-ui v0.4.2 permite ejecución remota sin autenticación
Una vulnerabilidad crítica de inyección de comandos en crontab-ui afecta todas las versiones hasta la 0.4.2, permitiendo a atacantes no autenticados inyectar trabajos cron arbitrarios mediante solicitudes GET manipuladas al parámetro env_vars. Esta exposición es de alto riesgo para empresas en LATAM que usan este componente en infraestructuras de automatización, facilitando compromiso de servidores, exfiltración de datos y movimiento lateral en redes corporativas.
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-70615] boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-…
boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permission to inject arbitrary lines into the server account's SSH authorized_keys file by supplying a percent-encoded newline character in the domain parameter of the tunnel creation endpoint. Attackers can insert an unrestricted public key entry into authorize…
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-44092] An unauthenticated remote attacker can inject malicious input into the ModbusServer application beca…
An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT. This may lead to integrity and availability loss.
M Crítico vulnerabilidad
22/06/2026
[CVE-2026-11373] Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections. Net::Statsite::Clien…
Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections. Net::Statsite::Client is a client for the statsite protocol, which is a variant of statsd. Newlines are not removed from metric names, allowing metric injections. Values are not sanitised for newlines or other protocol control characters such as colons or pipes, allowing metric injections.
P Crítico vulnerabilidad
10/06/2026
[CVE-2026-50638] Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injec…
Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions such as dogstatsd) allow mutiple metrics, separated by newlines, to be sent per packet. Metrics::Any::Adapter::DogStatsd which extends Metrics::Any::Adapter::Statsd, which has a similar vulnerability. In addition, the _tags function does not check tags f…
B Crítico vulnerabilidad
05/06/2026
[CVE-2026-11362] DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags. DataDog:…
DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags. DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from untrusted sources. The format_event method (used by the event method) does not validate the content of the tags, which may contain commas (allowing tags to be injected) or newlines, pipes and colons that allow metr…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
B Crítico vulnerabilidad
05/06/2026
[CVE-2026-9270] DataDog::DogStatsd versions through 0.07 for Perl allow metric injections. DataDog::DogStatsd does …
DataDog::DogStatsd versions through 0.07 for Perl allow metric injections. DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from untrusted sources. The send_stats method does not remove newlines from metric names ($stat variable), allowing attackers to change the metric name prefix. The send_stats method does not validate the content of the value ($delta v…