Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Quest" — 585 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1045
Esta semana
RSS
M Alto vulnerabilidad
27/09/2026
[CVE-2026-100870] Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 build administrator password-res…
Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 build administrator password-reset links using the request Host header without validation, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains. Attackers can request password resets for known administrator email addresses with forged Host headers to intercept valid reset tokens and take over …
M Alto vulnerabilidad
27/09/2026
Vulnerabilidad alta en AzuraCast anterior a 0.23.8: SSRF y lectura de archivos locales
AzuraCast antes de la versión 0.23.8 contiene vulnerabilidades de Server-Side Request Forgery (SSRF) y lectura de archivos locales en el módulo AutoDJ de obtención de playlists remotas. Un usuario con permisos de Media en la estación puede crear playlists con URLs remotas que apunten a rutas file:// o direcciones internas (loopback/link-local), exponiendo información sensible del servidor. Afecta principalmente a emisoras de radio online y plataformas de streaming en LATAM que utilizan este software para automatizar contenido.
M Alto vulnerabilidad
27/09/2026
[CVE-2026-100838] Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.19.1, the Kata age…
Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.19.1, the Kata agent policies generated by the Contrast CLI contained a flaw in the CopyFile verification that allowed arbitrary writes to the guest root filesystem. A malicious process on the untrusted host able to connect to the Kata agent VSOCK could issue a series of CopyFile requests to overwrite security-critic…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100705] Kyverno before 1.19.1 is vulnerable to server-side request forgery. The default egress blocklist (16…
Kyverno before 1.19.1 is vulnerable to server-side request forgery. The default egress blocklist (169.254.169.254, 169.254.169.253, metadata.google.internal, 127.0.0.0/8, ::1/128) and the scoped-token control were wired only into the new CEL http.Get/Post library and were never applied to the legacy apiCall service executor (pkg/engine/apicall/executor.go) or to the GlobalContextEntry external-API…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100697] Adminer 6.0.0 through 6.0.1, when the official ClickHouse driver plugin (plugins/drivers/clickhouse.…
Adminer 6.0.0 through 6.0.1, when the official ClickHouse driver plugin (plugins/drivers/clickhouse.php, rewritten in 6.0.0) is loaded, is vulnerable to pre-authentication server-side request forgery. An unauthenticated attacker can submit auth[driver]=clickhouse with auth[server] set to an arbitrary URL (for example http://127.0.0.1:18089), causing the Adminer server to issue an HTTP POST contain…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100671] Grav is a flat-file CMS. In versions 2.0.19 through 2.0.24 — and in 2.0.0 through 2.0.18 and 1.7.x o…
Grav is a flat-file CMS. In versions 2.0.19 through 2.0.24 — and in 2.0.0 through 2.0.18 and 1.7.x only where content Twig has been explicitly enabled — page content authored by a user holding only page-write permission is rendered through a Twig sandbox that allowlists get_cookie(), which returns any cookie sent with the current request, including the visitor's session cookie. Because the read oc…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100663] Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.2.Final through 4.2.17.Final does not spe…
Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.2.Final through 4.2.17.Final does not special-case HTTP/1 CONNECT authority-form request-targets when converting HTTP/1 messages to HTTP/3 in HttpConversionUtil.toHttp3Headers. The authority-form target (e.g., "CONNECT trusted.example:443") is parsed as a URI, so its host is emitted as :scheme, :path is set to "/", and the HTTP/1 Host head…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100664] Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.2.Final through 4.2.17.Final builds t…
Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.2.Final through 4.2.17.Final builds the HTTP/3 :authority pseudo-header from the HTTP/1 Host header before considering the authority of an absolute-form HTTP/1 request-target. In HttpConversionUtil.toHttp3Headers(HttpMessage, boolean) — reached via Http3FrameToHttpObjectCodec(false) — a non-empty Host header takes precedence over the r…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100666] Netty's HttpServerCodec (io.netty:netty-codec-http) in versions 4.2.0.Final through 4.2.16.Final and…
Netty's HttpServerCodec (io.netty:netty-codec-http) in versions 4.2.0.Final through 4.2.16.Final and in versions up to and including 4.1.136.Final pairs each outbound response with an inbound request by calling pollMethod() once per response, including for 1xx informational responses. If a client pipelines an HTTP/1.1 GET carrying an Expect: 100-continue header followed by a HEAD request, the 100 …
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100656] Netty (io.netty:netty-codec-http) contains an unbounded per-connection queue growth flaw in HttpServ…
Netty (io.netty:netty-codec-http) contains an unbounded per-connection queue growth flaw in HttpServerCodec. The codec tracks the HTTP method of each still-unanswered pipelined request; the first 32 entries are bit-packed into a single long, but every additional entry is appended to methodOverflowQueue, an ArrayDeque with no size limit and no rejection path. A remote, unauthenticated attacker who …
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100642] SiYuan versions from v2.1.0 before v3.8.4 contain a cross-site request forgery vulnerability in the …
SiYuan versions from v2.1.0 before v3.8.4 contain a cross-site request forgery vulnerability in the CheckAuth lock-screen pass-through branch that grants administrator access to loopback requests without validating Origin headers. Attackers can craft malicious web pages that force victims to terminate the kernel process, read workspace configuration and proxy settings, and trigger administrative a…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100646] SiYuan is a self-hosted personal knowledge management system. In versions up to and including 3.8.3,…
SiYuan is a self-hosted personal knowledge management system. In versions up to and including 3.8.3, the kernel's authentication guards (CheckAuth in kernel/model/session.go and IsSessionOriginAllowed in kernel/util/net.go) fail open when the HTTP Origin header is absent, on the incorrect assumption that any browser-initiated cross-site request carries an Origin. Because browsers omit Origin on cr…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100627] Capgo (Cap-go/capgo.app) server backend Supabase functions contain an incorrect authorization flaw i…
Capgo (Cap-go/capgo.app) server backend Supabase functions contain an incorrect authorization flaw in the API-key bundle promotion path. The PUT /bundle endpoint, available to "all" and "write" API keys, dispatches to setChannel, which authorizes with checkPermission(c, 'channel.promote_bundle', { appId: body.app_id }) and omits the request's channel_id. Because the omitted scope field is passed t…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-96524] The MCP Server for WordPress WordPress plugin before 1.8.2 does not correctly verify the WordPress …
The MCP Server for WordPress WordPress plugin before 1.8.2 does not correctly verify the WordPress REST API nonce for cookie-authenticated requests when a condition an attacker can influence is present, allowing unauthenticated attackers to perform administrator-only actions, including creating a new administrator account, by tricking a logged-in administrator into visiting a crafted page.
M Crítico vulnerabilidad
26/09/2026
Vulnerabilidad crítica de carga arbitraria de archivos en plugin Request a Quote for WooCommerce
El plugin Request a Quote for WooCommerce para WordPress es vulnerable a carga arbitraria de archivos en versiones hasta la 2.9.2 debido a validación insuficiente de extensiones y tipos MIME en la función afrfq_submit_quote_via_popup(). Un atacante puede cargar archivos maliciosos (como shells PHP) directamente al servidor sin restricción, comprometiendo completamente sitios de comercio electrónico en LATAM. Con CVSS 9.8, afecta principalmente a pequeñas y medianas empresas que usan este plugin para gestionar cotizaciones de productos.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
26/09/2026
Vulnerabilidad alta en paquete OpenClaw (npm) permite falsificación de aprobaciones
OpenClaw versiones anteriores a 2026.7.1 presenta un defecto en el enlace de reacciones de aprobación en Signal que permite que una aprobación destinada a una solicitud estructurada se adjunte incorrectamente a mensajes de texto ordinarios en la misma conversación. Esto podría resultar en que una reacción de un aprobador a un mensaje no relacionado sea interpretada como aprobación de una solicitud, comprometiendo controles de autorización en flujos de trabajo altas de empresas que utilizan esta dependencia npm.
M Alto vulnerabilidad
26/09/2026
Vulnerabilidad alta en paquete npm OpenClaw permite bypass de autorización de propietario
OpenClaw (paquete npm `openclaw`) anterior a versión 2026.7.1 no valida correctamente permisos de propietario en solicitudes de autorización de Claude Code a través del canal MCP. Un usuario autorizado sin permisos de propietario puede aprobar o denegar solicitudes de permisos destinadas al administrador de la cuenta, ejecutando acciones sin consentimiento del propietario. Afecta sistemas de automatización y desarrollo que dependan de este paquete en entornos empresariales.
M Alto vulnerabilidad
26/09/2026
Vulnerabilidad alta en OpenClaw Codex permite ejecución remota de código sin autorización
OpenClaw Codex anterior a versión 2026.7.1 presenta falla en validación de autorización que permite a usuarios no propietarios con acceso a comandos crear enlaces nativos y ejecutar operaciones con acceso a archivos, herramientas y procesos del sistema. Afecta principalmente a empresas que utilizan esta plataforma para orquestación de infraestructura en entornos cloud de LATAM.
M Alto vulnerabilidad
26/09/2026
Vulnerabilidad alta en paquete npm OpenClaw permite eludir restricciones administrativas (CVE-2026-100588)
OpenClaw versiones anteriores a 2026.7.1 no valida correctamente permisos administrativos en el método node.invoke, permitiendo a usuarios con permisos de escritura acceder a funciones de control de navegador sin autorización. En arquitecturas Gateway que validan identidad del llamante, esto expone sistemas a escalación de privilegios no autorizada.
M Alto vulnerabilidad
26/09/2026
Vulnerabilidad alta en OpenClaw (npm) permite escalación de privilegios en Gateway
OpenClaw versiones anteriores a 2026.7.1 expone herramientas administrativas restringidas (gateway y cron) a través del endpoint chat.send, permitiendo que usuarios sin permisos de propietario ejecuten operaciones privilegiadas en despliegues con autenticación. Afecta principalmente a infraestructuras en nube que utilizan este paquete npm en sistemas de orquestación y automatización.