Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Rti" — 919 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1052
Esta semana
RSS
M Crítico vulnerabilidad
14/09/2026
Inyección de comandos OS en D-Link DWR-M921 1.1.52 permite ejecución remota
Se ha identificado una vulnerabilidad crítica (CVSS 9.1) en el router D-Link DWR-M921 versión 1.1.52 que permite inyección de comandos del sistema operativo a través de la función /boafrm/formDiskFormat. Un atacante remoto puede manipular el parámetro 'partition' para ejecutar comandos arbitrarios sin autenticación. El exploit está publicado y activamente en uso.
M Crítico vulnerabilidad
14/09/2026
Inyección de comandos OS en D-Link DWR-M921 versión 1.1.52 (CVE-2026-90703)
Se ha identificado una vulnerabilidad crítica (CVSS 9.1) en el router D-Link DWR-M921 1.1.52 que permite inyección de comandos del sistema operativo a través del parámetro folderpath en la función de creación de comparticiones de disco. El ataque es remotamente exploitable y el exploit público ya circula en la comunidad de seguridad. Esta vulnerabilidad afecta principalmente a PyMES y empresas en LATAM que utilizan estos equipos como gateways de red.
M Alto vulnerabilidad
14/09/2026
[CVE-2023-32803] The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not pr…
The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly remove certain TrustCor root certificates from the root store. NOTE: this issue exists because of an incorrect fix for CVE-2022-23491.
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90651] Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify u…
Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certificates by default. When the api_ssl_verify and upstream_ssl_verify configuration keys are omitted from socket.yml, the generated configuration sets SOCKET_API_SSL_VERIFY='false' and UPSTREAM_SSL_VERIFY='false', and the OpenResty/Lua HTTP client used for outbound requests accepts an…
M Alto vulnerabilidad
12/09/2026
[CVE-2026-90647] ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper ce…
ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in the IEC 60870-5-104 TLS client (Task Mode). This allows a network-positioned attacker to bypass certificate validation via a certificate with multiple simultaneous faults, enabling a Man-in-the-Middle attack on protected communications.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad de condición de carrera en Hoverfly anteriores a v1.12.8
Hoverfly, herramienta de código abierto para simulación de APIs, presenta una vulnerabilidad de race condition en modo Diff que afecta escrituras concurrentes sin sincronización. Cuando múltiples solicitudes proxy se procesan simultáneamente, la función AddDiff() accede sin mutex al mapa compartido responsesDiff, causando fallos fatales en sistemas que dependen de esta herramienta para testing y desarrollo. Empresas en LATAM que usan Hoverfly en entornos de CI/CD o ambientes de validación de APIs están expuestas a interrupciones operacionales.
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-84390] A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.…
A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through 7.2.2 may allow attacker to improper access control via

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
11/09/2026
[CVE-2026-78130] strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certifi…
strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-78132] strongSwan 5.1.3 through 6.0.7 has an infinite loop in the x509 plugin's attribute certificate parse…
strongSwan 5.1.3 through 6.0.7 has an infinite loop in the x509 plugin's attribute certificate parser for ietfAttrSyntax.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-45770] Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M…
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, a Lua rule that registers too many flow variables can corrupt Lua detection state and may bypass Suricata's restricted Lua sandbox. This requires an affected Lua script/rule to be loaded. Excessive flow variables being registere…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-45768] Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M…
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, LDAP transaction state could store an unbounded number of responses. Because LDAP can be processed over UDP, crafted traffic may cause Suricata to consume excessive memory, potentially resulting in denial of service. Version 8.0…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-89011] isomorphic-git before 1.42.0 contains a prototype pollution vulnerability in the getRemoteInfo funct…
isomorphic-git before 1.42.0 contains a prototype pollution vulnerability in the getRemoteInfo function that allows a malicious Git server operator to pollute Object.prototype by advertising crafted ref names containing '__proto__' path segments during ref negotiation. Attackers controlling a Git server can advertise a specially crafted ref such as '__proto__/corsProxy' to reroute all subsequent n…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88021] Consul and Consul Enterprise are vulnerable to an authorization bypass in the Connect service mesh t…
Consul and Consul Enterprise are vulnerable to an authorization bypass in the Connect service mesh that may allow a service to reach a destination it is not authorized to access. When building Envoy RBAC rules to enforce Connect intentions, Consul did not correctly escape certain characters in service names, namespaces, and partitions, causing the generated authorization rules to match more broadl…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-89043] passport-saml-encrypted through 0.1.13 contains an XML signature wrapping vulnerability where signat…
passport-saml-encrypted through 0.1.13 contains an XML signature wrapping vulnerability where signature verification and assertion extraction use independent XPath lookups with no cross-validation. Attackers holding any validly signed SAML message can prepend a forged unsigned assertion that gets accepted as the verified identity while the genuine signature validates against the original assertion…
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-89042] passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional …
passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can post forged SAML responses with arbitrary NameID and attributes to the assertion consumer service endpoint to receive authenticated profiles without valid signatures.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
10/09/2026
[CVE-2026-45747] Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M…
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.16, the Lua TLS certificate information helper could dereference NULL certificate fields when a Lua script requested certificate information for TLS traffic where some certificate fields were absent. Crafted TLS traffic processed by a deployment using affected …
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88889] Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that…
Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that allows attackers to execute arbitrary commands by specifying a malicious distributionType parameter in maven-wrapper.properties. Attackers can inject shell commands through unescaped distributionType values to achieve remote code execution when Renovate processes Maven Wrapper updates in binarySour…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88891] OpenPanel fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing …
OpenPanel fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data. Attackers with explicit read-only access can delete reports and dashboards, schedule entire projects for deletion, publish private analytics to public share links, and modify alerting rules by exploiting missing access level validation …
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88886] Renovate is a dependency update automation tool. In versions before 44.14.7 (and in Mend Renovate CE…
Renovate is a dependency update automation tool. In versions before 44.14.7 (and in Mend Renovate CE/EE distributions before 15.4.0, and the mend-renovate-enterprise-edition Helm chart before 10.4.0), the manager/gradle-wrapper module does not escape the distributionUrl value read from a repository's gradle/wrapper/gradle-wrapper.properties file before invoking the Gradle Wrapper CLI. In self-host…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-75584] ION-DTN before 4.2.1-a.1 contains a denial of service vulnerability that allows unauthenticated remo…
ION-DTN before 4.2.1-a.1 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash the ION process by sending a BPv7 bundle with a zero-length payload. The canonicalizePayloadBlock() function in bpsec_util.c passes bundle->payload.length to zco_clone() without validating it against zero, causing a failed CHKZERO assertion that triggers sm_Abort() and terminat…