Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
Buscando: "Ni" — 2114 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88895] CyberPanel before 3.0.5 fails to enforce two-factor authentication on API endpoints, allowing attack…
CyberPanel before 3.0.5 fails to enforce two-factor authentication on API endpoints, allowing attackers to bypass TOTP requirements using password-derived tokens. Attackers who obtain an administrator's password can derive API tokens and perform administrative operations or create authenticated sessions without the second factor.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88888] Renovate before 44.14.7 contains a command injection vulnerability in the Mix manager when processin…
Renovate before 44.14.7 contains a command injection vulnerability in the Mix manager when processing private dependencies with unescaped organization parameters. Attackers can inject shell metacharacters through malicious package names to execute arbitrary commands as the Renovate user in binarySource=docker mode.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88883] Renovate is an automated dependency update tool. In versions before 44.14.4 (and Mend Renovate CE/EE…
Renovate is an automated dependency update tool. In versions before 44.14.4 (and Mend Renovate CE/EE images before 15.4.0 and the mend-renovate-enterprise-edition Helm chart before 10.4.0), log sanitisation for TLS private keys used for Mutual TLS was incomplete. While the value of hostRules[].httpsPrivateKey was redacted in the field itself, the same private key value was not redacted if it also …
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88872] AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery…
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in the setPassword.json.php endpoint that allows unauthenticated attackers to modify any user's channel password by sending a GET request. Attackers can craft a malicious webpage that, when visited by an authenticated administrator, sets or clears any user's channel password without C…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88873] WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request fo…
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in view/logArchive.json.php that allows unauthenticated attackers to archive application logs by making GET requests without CSRF token validation. Attackers can craft malicious pages that trigger administrators' browsers to request the endpoint, copying sensitive application log…
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-88869] AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scriptin…
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the AD_Server plugin's log.php endpoint that fails to escape the label parameter before storage. An unauthenticated attacker can inject malicious HTML through the label parameter, which is later rendered unsanitized in the admin Ad Types report using jQuery .html(), allowing execu…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88868] AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scriptin…
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LiveLinks plugin where title and description fields are stored without sanitization. A user with canStream permission can inject malicious scripts that execute in the browser of every visitor viewing the live-link page, including administrators, within the site origin.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-88864] Capgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed th…
Capgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed through Supabase PostgREST. A holder of an ordinary Capgo full API key can insert a row with status='active' and enforce_sso=true, bypassing the intended backend SSO provisioning route (supabase/functions/_backend/private/sso/providers.ts) and its controls: the Enterprise plan requirement, SSO provide…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88866] WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scr…
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to encode the User-Agent header before storing it in login history. Attackers with any valid login account can inject malicious scripts in the User-Agent header that execute in administrator browsers when viewing the Login History page, allo…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88867] WWBN AVideo, in versions up to and including commit c3edcc274c389816d434acadac07ee78eaf330c1, contai…
WWBN AVideo, in versions up to and including commit c3edcc274c389816d434acadac07ee78eaf330c1, contains a stored cross-site scripting vulnerability. objects/categoryAddNew.json.php passes the POST parameters `name` and `iconClass` to Category::setName() and Category::setIconClass(), which store the values without sanitization (setName only truncates to 45 characters). The category name is later ech…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-75584] ION-DTN before 4.2.1-a.1 contains a denial of service vulnerability that allows unauthenticated remo…
ION-DTN before 4.2.1-a.1 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash the ION process by sending a BPv7 bundle with a zero-length payload. The canonicalizePayloadBlock() function in bpsec_util.c passes bundle->payload.length to zco_clone() without validating it against zero, causing a failed CHKZERO assertion that triggers sm_Abort() and terminat…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-6285] Weak Password Recovery Mechanism for Forgotten Password vulnerability in Ankaref Innovation and Tech…
Weak Password Recovery Mechanism for Forgotten Password vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Password Recovery Exploitation. This issue affects LIBRID/LIBREF: from 2.01.0.2183 through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
M Alto vulnerabilidad
10/09/2026
Vulnerabilidad alta en ESP32-audioI2S 3.4.4-4.0.0: lectura fuera de límites en procesamiento ID3
ESP32-audioI2S versiones 3.4.4 a 4.0.0 contienen una vulnerabilidad de lectura fuera de límites en la función read_ID3_Header durante procesamiento de etiquetas ID3 sincronizadas. Atacantes pueden crear archivos MP3 maliciosos o flujos de audio HTTP con declaraciones de tamaño de fotograma exageradas, causando caídas del dispositivo o exposición de memoria adyacente. Afecta principalmente a sistemas IoT, dispositivos embebidos y aplicaciones de streaming de audio en infraestructuras empresariales LATAM.
M Alto vulnerabilidad
10/09/2026
Vulnerabilidad de denegación de servicio en t-digest 3.1-3.3 (CVE-2026-87962)
t-digest versiones 3.1 a 3.3 contienen una vulnerabilidad de denegación de servicio en MergingDigest.fromBytes que no valida campos de longitud y capacidad en datos serializados. Atacantes pueden enviar digests serializados manipulados para provocar excepciones ArrayIndexOutOfBoundsException o NegativeArraySizeException, abortando el hilo de procesamiento. Afecta aplicaciones que usan t-digest para compresión de datos o análisis de distribuciones en sistemas altas.