Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1003
Esta semana
RSS
M Crítico vulnerabilidad Nuevo
Hace 1 hora
[CVE-2026-108263] Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the…
Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow code-node path through /console-api/workflow/code/run and /workflow/v1/run selects LocalExecutor in core/workflow/engine/nodes/code/code_node.py when CODE_EXEC_TYPE is not explicitly changed. LocalExecutor supplies complete Python builtins to dynamic code execution without the docu…
M Alto vulnerabilidad Nuevo
Hace 7 horas
[CVE-2026-33367] SNMP can be used to perform administrative actions such as retrieving configuration files, modifying…
SNMP can be used to perform administrative actions such as retrieving configuration files, modifying user accounts or device settings, and initiating firmware or bootloader upgrades or downgrades—all without any authentication.
M Alto vulnerabilidad Nuevo
Hace 8 horas
[CVE-2026-105281] The internal data publisher on openPDC accepts network connections without authentication in its def…
The internal data publisher on openPDC accepts network connections without authentication in its default configuration. An unauthenticated network attacker can connect to this interface and retrieve the complete device and measurement topology of the system.
M Alto vulnerabilidad Nuevo
Hace 12 horas
[CVE-2026-78025] Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Missing A…
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure, Protection mechanism bypass, and Unauthorized access.
M Crítico vulnerabilidad Nuevo
Hace 23 horas
[CVE-2026-77900] Missing authentication for critical function in Azure App Service allows an unauthorized attacker to…
Missing authentication for critical function in Azure App Service allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-84249] IBM Guardium Data Protection 12.2, and 12.2.2 could allow a remote attacker to execute arbitrary man…
IBM Guardium Data Protection 12.2, and 12.2.2 could allow a remote attacker to execute arbitrary management operations due to missing authentication for critical function.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-11318] Deskin through 3.3.4.3 contains a privilege escalation vulnerability in the com.deskin.service.insta…
Deskin through 3.3.4.3 contains a privilege escalation vulnerability in the com.deskin.service.installer XPC service that allows local unprivileged attackers to execute arbitrary installer packages as root by connecting to the root-owned service without authentication. Attackers can invoke the privileged installer method to run an attacker-supplied installer, achieving full root compromise of the …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-107779] Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a missing authentica…
Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a missing authentication vulnerability in bundled xxl-job-admin JobInfoController endpoints annotated with @PermissionLimit(limit = false). Unauthenticated attackers can POST GLUE_SHELL, GLUE_PYTHON, or GLUE_POWERSHELL jobs with attacker-supplied glueSource to /jobinfo/addAndStart, executing commands on the executor ho…
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-84272] IBM Guardium Data Protection 12.1 and 12.2.2 are vulnerable to missing authentication in the edge-co…
IBM Guardium Data Protection 12.1 and 12.2.2 are vulnerable to missing authentication in the edge-controller component. An unauthenticated remote attacker could exploit this vulnerability to execute arbitrary container images and gain control of managed edge clusters.
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-104076] TVU Networks Receiver/Transceiver devices running firmware before version 7.9 contain a missing auth…
TVU Networks Receiver/Transceiver devices running firmware before version 7.9 contain a missing authentication vulnerability that allows remote unauthenticated attackers to read sensitive device information and modify device configuration via unprotected REST API endpoints on port 8288. Attackers can send unauthenticated GET requests to disclose network configuration, firmware details, and cloud s…
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-9209] mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulnerability in the Logi…
mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulnerability in the Login.aspx admin panel handlers, where the runQueryButton postback and exportSqlQuery_Server PageMethod execute caller-supplied SQL against the backing Sybase SQL Anywhere database using DBA/sysadmin privileges with no server-side authentication enforced beyond a client-side sessionStorage flag. Attacke…
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-105110] OS Command Injection in the login.xgi CGI endpoint in Iskratel Innbox GPON ONT devices allows an una…
OS Command Injection in the login.xgi CGI endpoint in Iskratel Innbox GPON ONT devices allows an unauthenticated remote attacker to execute arbitrary commands as root via the CLI parameter.
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-76268] In Splunk Enterprise versions below 10.4.3 and 10.2.7, an unauthenticated user with network access t…
In Splunk Enterprise versions below 10.4.3 and 10.2.7, an unauthenticated user with network access to the Patroni Representational State Transfer (REST) Application Programming Interface (API) on a search head cluster member could execute attacker-controlled operating-system commands. The vulnerability is possible because this interface does not require authentication for critical configuration op…
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-76480] As part of Cisco's ongoing commitment to proactive security and product quality, the engineering tea…
As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-202…
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-62253] Homer is open source telecom observability software. Prior to version 11.0.283, both JWT middleware …
Homer is open source telecom observability software. Prior to version 11.0.283, both JWT middleware functions (`JWTMiddleware` and `JWTMiddlewareV4`) immediately return `next(c)` when `jwtSecret == ""`. The JWT secret defaults to an empty string. On a default installation, all protected API endpoints under `/api/v1`, `/api/v3`, and `/api/v4` are completely unauthenticated. Version 11.0.283 patches…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-107204] LMCache through 0.5.5 contains an unauthenticated remote code execution vulnerability that allows re…
LMCache through 0.5.5 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute Python code by posting scripts to the /run_script endpoint. Attackers can recover real builtins through the injected FastAPI app object, bypassing the guarded __import__, to import os and run operating system commands as the LMCache process.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-107205] LMCache through 0.5.5 contains a missing authentication vulnerability in the multiprocess coordinato…
LMCache through 0.5.5 contains a missing authentication vulnerability in the multiprocess coordinator that allows remote unauthenticated attackers to access its HTTP fleet control API listening on all interfaces by default. Attackers can register or deregister instances via /instances, overwrite quotas via /quota endpoints, inject events via /events, and enumerate /directory/keys to disrupt cachin…
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-107206] LMCache through 0.5.5 contains a missing authentication vulnerability in the multiprocess mode HTTP …
LMCache through 0.5.5 contains a missing authentication vulnerability in the multiprocess mode HTTP server that allows remote unauthenticated attackers to access management endpoints listening on all interfaces by default. Attackers can read environment credentials via GET /env and configuration via GET /config, clear caches, delete cache objects, and modify tenant quotas to evict other tenants' c…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-107207] LMCache through 0.5.5 contains a server-side request forgery vulnerability in its frontend monitorin…
LMCache through 0.5.5 contains a server-side request forgery vulnerability in its frontend monitoring service that allows unauthenticated attackers to bypass the proxy allowlist by registering arbitrary hosts. Attackers can add entries via POST /api/proxies and then use /proxy or /proxy2 to reach internal hosts, read responses, and tamper with nodes or stop the heartbeat.
M Crítico vulnerabilidad
Hace 2 días
[CVE-2025-70516] The websocket handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce proper authenticati…
The websocket handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce proper authentication restrictions against sessionless users. The lack of restrictions grants anyone the ability to view any device resources such as operational logs or perform diagnostic requests.