Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1017
Esta semana
RSS
M Alto vulnerabilidad
Hace 1 día
CVE-2026-104704: Vulnerabilidad alta en hMailServer 6.0.0-6.3.5 por falta de validación TLS en SMTP
hMailServer versiones 6.0.0 a 6.3.5 no implementa correctamente la validación DANE/TLSA para entregas SMTP salientes, permitiendo degradación a conexiones sin TLS cuando los registros DNSSEC no contienen registros DANE-EE. Esto expone las comunicaciones de correo en tránsito a empresas mexicanas y latinoamericanas que usan este servidor de correo, comprometiendo la confidencialidad de mensajes según RFC 7672.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107232] The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and async…
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 on 3.x and 2.16.1 on 2.x, the client infers that an HTTP proxy tunnel exists from the last request method rather than the CONNECT result. After a proxy rejects CONNECT, redirect or authentication handlers can write an origin request and its Authoriza…
M Alto vulnerabilidad
02/10/2026
[CVE-2026-103098] Transmission of a sensitive key in the URL over an unencrypted HTTP connection.  The request is sent…
Transmission of a sensitive key in the URL over an unencrypted HTTP connection.  The request is sent over HTTP rather than HTTPS, meaning the key is transmitted in plaintext across the network. An attacker with the ability to monitor network traffic could intercept the request and obtain the key
M Alto vulnerabilidad
01/10/2026
[CVE-2026-67105] HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could al…
HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of sensitive data and potential man-in-the-middle (MitM) attacks.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-82826] Hitachi Coding Software Suite contains a vulnerability related to the Cleartext Transmission of Sens…
Hitachi Coding Software Suite contains a vulnerability related to the Cleartext Transmission of Sensitive Information which allows an attacker to eavesdrop on with authentication credentials and sensitive data in transit. This issue affects Hitachi Coding Software Suite: through 3.3.0.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-18176] IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain…
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-18134] IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain…
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
17/09/2026
[CVE-2026-85719] The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and async…
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 2.16.1 and 3.0.12, requests using an authenticated SOCKS proxy can expose the proxy's credentials to the origin because NettyRequestFactory and NettyRequestSender attach Proxy-Authorization without confirming that the request is being sent to an HTT…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91988] atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry back…
atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowing network man-in-the-middle attackers to rewrite catalog responses. Attackers can inject arbitrary command and argument values that are spawned as local subprocesses by MCPClientPool to achieve code execution on the agent host.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-31278] An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and …
An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers to obtain Active Directory service account credentials in cleartext by supplying a crafted GET request.
M Alto vulnerabilidad
02/09/2026
Vulnerabilidad alta en HTTPX2: falla de inicio de TLS en conexiones WebSocket seguras por proxy SOCKS5
HTTPX2 (cliente HTTP de próxima generación para Python) versiones anteriores a 2.10.0 no inicia correctamente TLS al conectar a servidores WebSocket seguro (wss://) a través de proxy SOCKS5, debido a que el validador de protocolo solo reconoce https. La falla afecta aplicaciones que usan Client.websocket() y AsyncClient.websocket() desde v2.6.0, exponiendo comunicaciones que deberían estar cifradas en entornos corporativos y financieros de LATAM.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84366] Scrapy is a high-level web crawling and scraping framework for Python. Prior to 2.17.0, in scrapy/co…
Scrapy is a high-level web crawling and scraping framework for Python. Prior to 2.17.0, in scrapy/core/downloader/handlers/s3.py, Scrapy's S3DownloadHandler converts an S3-scheme bucket and key request into a plaintext HTTP request to the corresponding S3 endpoint unless request.meta["is_secure"] is explicitly enabled, then signs and sends the plaintext request with configured AWS credentials. A n…
M Alto vulnerabilidad
28/08/2026
[CVE-2026-73809] A cleartext transmission of sensitive information vulnerability exists in certain Ebyte gateway pro…
A cleartext transmission of sensitive information vulnerability exists in certain Ebyte gateway products. The web management interface does not adequately protect sensitive communications using transport-layer encryption. An attacker with access to network traffic could intercept authentication or session-related information transmitted between a user and the affected device. Successful explo…
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-69658] MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information t…
MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information to network-level attackers. This may enable unauthorized device impersonation and disruption of messaging functions.
M Alto vulnerabilidad
27/08/2026
[CVE-2026-81691] openssl_encrypt versions before 1.4.9 fail to validate server URLs in login and register_with_email …
openssl_encrypt versions before 1.4.9 fail to validate server URLs in login and register_with_email functions, accepting unencrypted http:// URLs and unconfigured hosts. Attackers on the network path can intercept cleartext credentials including client_id, passwords, and JWTs to achieve full keyserver account takeover.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
26/08/2026
[CVE-2026-29988] A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Mil…
A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device models running affected firmware versions allows an unauthenticated attacker with physical proximity to retrieve LoRaWAN ABP NwkSKey and AppSKey values and D2D keys via an NFC read operation. The exposed keys can be used to decrypt LoRaWAN traffic, forge uplink and downlink frames,…
M Crítico vulnerabilidad
19/08/2026
[CVE-2026-22306] Download of code without integrity check, inclusion of functionality from untrusted control sphere, …
Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext transmission of sensitive information vulnerability in Ozols Grupa OZOLS on Windows caused by an abandoned auto-update domain. Affected component: the automatic update channel - OzolsSQL client update path, the _update SQL Server Agent job (@subsystem = N'ActiveScripting') and se…
M Alto vulnerabilidad
20/07/2026
[CVE-2026-47255] AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to versio…
AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 had weakness related to validation and and binding of inactive-agent hour filtering; storage SQL identifier validation; metadata-backed ownership checks for raw storage SQL; blocking direct storage metadata access through raw SQL; fail-closed ou…
M Alto vulnerabilidad
29/06/2026
[CVE-2026-55844] Home Assistant is open source home automation software that puts local control and privacy first. Pr…
Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2025.5.0, The iOS companion app ignores the SSID allowlist for internal networks. The app uses SSID to detect when to use the internal URL, but whenever the app cannot find any other URL to be used, it fallbacks to the internal URL as well, which can expose user's token when connected to a no…
A Alto vulnerabilidad
26/06/2026
[CVE-2026-49486] The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but n…
The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control channel was TLS-protected the data channel was transmitted in cleartext. Any deployment using `FTPSHook` or `FTPSFileTransmitOperator` to move files over FTPS exposed file contents and credentials-in-transit to a network attacker able to observe the da…