Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "X" — 2977 resultados ✕ Limpiar búsqueda
13,598
Total alertas
3086
Críticas
10240
Altas
8
Ransomware
1809
Esta semana
RSS
M Crítico vulnerabilidad
11/08/2026
Inyección SQL crítica en e107 2.4.0 permite acceso no autenticado a bases de datos
Una vulnerabilidad de inyección SQL en e107 2.4.0 permite a atacantes no autenticados ejecutar comandos SQL arbitrarios a través del parámetro de ID de noticia, comprometiendo completamente la integridad de la base de datos. Los atacantes pueden leer, modificar o eliminar todos los contenidos, incluidas credenciales de administrador. Esta falla afecta directamente a portales de contenidos, sitios informativos y plataformas comunitarias desplegadas en LATAM sin parches aplicados.
M Alto vulnerabilidad
11/08/2026
Vulnerabilidad alta de control de acceso en Peppermint Lab Peppermint (CVE-2026-72555)
Peppermint Lab Peppermint presenta una vulnerabilidad de control de acceso roto en instalaciones por defecto, donde el flag Config.roles_active está deshabilitado, permitiendo que todos los usuarios autenticados eludan controles de propiedad y acceso administrativo. Un atacante con cualquier cuenta de usuario puede leer, modificar o eliminar tickets, datos de clientes e información de otros usuarios. Afecta altas sistemas de gestión de tickets en empresas mexicanas y latinoamericanas que usan esta solución.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72556] A remote code execution vulnerability in ZoneMinder 1.39.17 allows any authenticated user to execute…
A remote code execution vulnerability in ZoneMinder 1.39.17 allows any authenticated user to execute OS commands by exploiting a broken permission check in the Filter class. The canEdit() and canDelete() methods invoke nonexistent methods on the ZM\User class, causing PHP __call() to return a truthy value that bypasses the permission check for all users. Any authenticated user can trigger filter-b…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72557] An unrestricted file upload vulnerability in Cockpit CMS 2.6.0 allows authenticated users to upload …
An unrestricted file upload vulnerability in Cockpit CMS 2.6.0 allows authenticated users to upload files of any extension including PHP scripts via the asset upload endpoint. The allowed_uploads configuration defaults to wildcard (*) and uploaded files are stored in a web-accessible directory. An attacker with any authenticated account can upload a PHP webshell and execute arbitrary OS commands o…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72558] An SQL injection vulnerability in CiviCRM through 6.18.alpha1 allows authenticated staff to read the…
An SQL injection vulnerability in CiviCRM through 6.18.alpha1 allows authenticated staff to read the entire database via the contact search RLIKE clause. The clause concatenates a user-supplied value into the SQL query without sanitization. An attacker with staff-level access can exfiltrate all database contents including donor and member records.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-72550] An SQL injection vulnerability in Friendica through the 2026.08-dev branch allows unauthenticated re…
An SQL injection vulnerability in Friendica through the 2026.08-dev branch allows unauthenticated remote attackers to execute arbitrary SQL statements via the photo-view order parameter. The parameter is concatenated unescaped into a SHOW COLUMNS query via a bare PDO::query() call, enabling stacked statement injection. An unauthenticated attacker can read, modify, or delete the entire database.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72551] A remote code execution vulnerability in Apioo Fusio 8.8.3 allows authenticated users with the Devel…
A remote code execution vulnerability in Apioo Fusio 8.8.3 allows authenticated users with the Developer role to execute arbitrary OS commands by exploiting a PHP-Sandbox allow-list bypass. The sandbox allow-list permits functions that transitively invoke system(), enabling a developer to escape the sandbox and gain OS command execution on the server. An attacker with a Developer-role account can …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72552] A server-side request forgery vulnerability in Dub as of 2026-07-10 allows unauthenticated remote at…
A server-side request forgery vulnerability in Dub as of 2026-07-10 allows unauthenticated remote attackers to make the server issue HTTP requests to arbitrary internal or external hosts via the metatags edge endpoint. The endpoint fetches any caller-supplied URL without applying a denylist or requiring authentication. An attacker can use this to scan internal services or exfiltrate data from clou…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72538] An argument injection vulnerability in PrefectHQ Prefect through 3.8.2 allows authenticated users to…
An argument injection vulnerability in PrefectHQ Prefect through 3.8.2 allows authenticated users to achieve remote code execution via the git_clone pull step branch field. The branch parameter is passed directly to git pull without sanitization, enabling injection of arbitrary git arguments. This represents a distinct code path from the incomplete fix applied for CVE-2026-5366 and allows command …
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72543] An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows una…
An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to retrieve any contact record via the getcontact Parse cloud function. The function executes with useMasterKey and performs no authentication or authorization checks before returning the requested contact object. An attacker can enumerate and read all contact records i…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-50237] A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog …
A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant can plant a ProjectHelmChartRepository with an arbitrary URL that the console pod fetches server-side, bypassing tenant egress restrictions. Combined with catalog metadata poisoning and admin-mediated chart installation, this enables privilege escalation.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72533] An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privi…
An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypass Docker proxy authorization checks via non-canonical URL normalization, defeating all authorization middleware. The proxy endpoint fails to normalize request paths before applying access controls, allowing crafted requests to be interpreted differently by the proxy and the autho…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72534] A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an atta…
A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token to gain superuser privileges by provisioning a SCIM group that matches an existing administrator group by name. The SCIM group ingest function adopts any existing group by name and replaces its membership without validating the source scope against t…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72536] A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remo…
A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to manipulate any tenant Stripe subscription via the stripeCreateIntent GraphQL mutation. The mutation lacks authentication and authorization checks, exposing Stripe payment intent creation to unauthenticated callers. An attacker can create payment intents and alter billing for any tena…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72537] A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an atta…
A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token to take over any user account including superusers by provisioning a SCIM user that matches an existing local user by username. The SCIM user ingest function adopts pre-existing local accounts by username without validating scope boundaries. An attac…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-58231] SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and s…
SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-71217] A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted cont…
A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len`, which are not properly validated by the server. This improper input validation can lead to excessive stream and thread creation, as well as large buffer allocations, causing resource exhaustion. Consequently, this can …
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72693] `openvt -u` is intended to identify the owner of the current VT and then execute `login` as that use…
`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the documented `kbrequest`/init usage, the ownership test in `authenticate_user()` relies on `stat("/proc//fd/0")`. `stat()` on `/proc//fd/0` follows the symlink to the underlying TTY device node. As a result, `buf.st_uid` reflects the owner of the TTY node …
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72694] A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops priv…
A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low-privileged attacker can exploit a symbolic link (symlink) following vulnerability. By influencing or pre-placing a symlink in the process ID (PID) file path, the attacker can trick the root process into changing the ownership of an arbitrary existing file to the daemon user. Thi…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-15554] the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any sh…
the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication. This enables an unauthenticated attacker with direct TCP access to port 8009 to bypass CLIENT-CERT authentication by injecting a forged X.509 certificate via the AJP protocol.