Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Rti" — 222 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
15/09/2026
[CVE-2026-73955] Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Char…
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Charting). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker. Successful at…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-88765] GitLab has remediated an issue in GitLab EE affecting all versions from 12.3 to 19.1.8, 19.2 before …
GitLab has remediated an issue in GitLab EE affecting all versions from 12.3 to 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 under certain conditions could allow an authenticated user to achieve remote code execution by importing a specially crafted Git project export to overflow the Unicode conversion buffer used in Advanced Search indexing.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-61668] DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0…
DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, WorkloadManagementSystem/Utilities/PilotWrapper.py pilotWrapperScript uses ssl._create_unverified_context to download the second-stage pilot.tar archive without TLS certificate verification and downloads the reference checksum through the same unvalidated channel. An attacke…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-12150] IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3…
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote attacker with a trusted TLS client certificate to cause a denial of service and potentially affect memory contents due to improper validation of deeply nested certificate data during …
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-89026] The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf cont…
The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens. Attackers can use the forged token to call the manager originate endpoint with the System application parameter, c…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91955] FreeRDP before 3.31.0 fails to validate client-supplied DesktopWidth and DesktopHeight values during…
FreeRDP before 3.31.0 fails to validate client-supplied DesktopWidth and DesktopHeight values during GCC negotiation, allowing remote attackers to crash the server. Attackers can send crafted RDP packets with zero or oversized dimensions to trigger division-by-zero or assertion failures in multifragment update capability calculations, terminating the server process.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91848] A vulnerability was identified in WuzhiCMS up to 4.1.0. Affected by this issue is the function artic…
A vulnerability was identified in WuzhiCMS up to 4.1.0. Affected by this issue is the function article::getDataOfJson of the file /index.php?m=content&f=article&v=getDataOfJson. The manipulation of the argument title/master_table leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92047] Privilege escalation in the Crash Reporting component. This vulnerability was fixed in Firefox 156 a…
Privilege escalation in the Crash Reporting component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
M Alto vulnerabilidad
15/09/2026
Vulnerabilidad de acceso anónimo en lamp-cloud permite lectura de propiedades del sistema JVM
lamp-cloud en versiones hasta 5.10.0 expone un patrón de ruta /*/anno/** accesible sin autenticación, permitiendo a atacantes remotos recuperar propiedades altas del JVM como rutas del sistema de archivos, classpath, detalles del SO y secretos de inicio mediante solicitudes POST a /defGenProject/anno/getProperties. Esta exposición de metadatos del servidor facilita reconocimiento para ataques posteriores contra infraestructura en México y LATAM.
M Crítico vulnerabilidad
15/09/2026
Vulnerabilidad crítica en PraisonAI permite ejecución remota de código malicioso
PraisonAI versiones 1.4.0 a 1.7.2 contienen una vulnerabilidad de ejecución de código no autorizado (CVSS 9.9) en el módulo code-mode.ts. Un atacante puede eludir el sandbox de JavaScript utilizando técnicas de prototipado para recuperar el constructor Function real y acceder a process, comprometiendo completamente sistemas que ejecuten agentes multi-IA. Este riesgo afecta directamente a empresas en LATAM que implementan automatización con PraisonAI en entornos productivos.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-13107] IBM Business Automation Workflow containers and traditional may use programming model artifacts that…
IBM Business Automation Workflow containers and traditional may use programming model artifacts that are vulnerable to XML Entity Injection attacks by default.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-19624] A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection proper…
A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection properties (vpn.data and vpn.secrets values) unescaped into a generated ipsec.conf file that pluto loads as root. A local unprivileged user can create and activate their own L2TP VPN profile containing a newline-injected leftupdown directive; pluto executes that command as root when the IKE security assoc…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-90942] Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /…
Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it. Attackers can use the exposed private key to forge JWT tokens for any user in any organization, including global administrators.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-57132] PraisonAI is a multi-agent teams system. Prior to 4.6.62, setting PRAISONAI_CALL_AUTH to disabled ma…
PraisonAI is a multi-agent teams system. Prior to 4.6.62, setting PRAISONAI_CALL_AUTH to disabled makes verify_token accept requests to /api/v1/agents/{id}/invoke without CALL_SERVER_TOKEN authentication. Deployments that use the application's advertised opt-out can expose registered agents and their connected tools or private context to unauthenticated invocation. The vulnerability is fixed in 4.…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-82428] Description Dependency artifacts uploaded with `storm jar --artifacts` were stored under a blob key…
Description Dependency artifacts uploaded with `storm jar --artifacts` were stored under a blob key derived only from the Maven coordinate, for example `dep---.jar`. The key was therefore identical for every user of the cluster and predictable in advance. When the blob already existed, the uploader caught `KeyAlreadyExistsException` and silently reused it, with no check that the existing blob's c…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-82441] Description A submitted topology carries two lists of blobstore keys, `dependency_jars` and `depend…
Description A submitted topology carries two lists of blobstore keys, `dependency_jars` and `dependency_artifacts`, which the client fills in after uploading the corresponding blobs. Nimbus performed no validation of their contents on the submission path, yet acts on them in two places. During cleanup of a finished topology, Nimbus deletes the keys named in those lists, and the deletion is perfo…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-78336] Insertion of sensitive information into sent data vulnerability in Apache Syncope. Any authentica…
Insertion of sensitive information into sent data vulnerability in Apache Syncope. Any authenticated user can query for the list of available OIDC providers configured for SSO with Console and Enduser. The returned payload contains all configuration settings, including client secrets, regardless of the entitlements owned by the caller. This issue affects Apache Syncope: from 3.0.0-M0 through…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-73668] Incorrect Authorization vulnerability in Apache Syncope. An administrator with adequate entitle…
Incorrect Authorization vulnerability in Apache Syncope. An administrator with adequate entitlements in a given Realm may be able to read via REST the full Connector configuration, confidential properties included, scoped in another Realm and thus be able to effectively duplicate such Connector instance into the Realm they have administration rights for. This issue affects Apache Syncope: fr…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-87779] Insertion of sensitive information into log file vulnerability in Apache Syncope. When AES key of…
Insertion of sensitive information into log file vulnerability in Apache Syncope. When AES key of non-standard length (not 16/24/32 bytes) is configured, Syncope will pad the provided value with random characters. The resulting key value is logged. This issue affects Apache Syncope: from 3.0.15 through 3.0.16, from 4.0.3 through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to…
M Alto vulnerabilidad
14/09/2026
Vulnerabilidad alta en Parallels Desktop: escalada de privilegios local vía socket mundial
Parallels Desktop ejecuta el servicio prl_disp_service con permisos root a través de un socket accesible mundialmente (/var/run/prl_disp_service.socket), permitiendo a usuarios locales ejecutar comandos arbitrarios sin validación de firma ni pertenencia a grupos administrativos. La vulnerabilidad afecta principalmente a empresas en México y LATAM que usan Parallels Desktop en infraestructuras de desarrollo, testing y virtualización en macOS, exponiendo sistemas con múltiples usuarios o acceso compartido.