Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ui" — 871 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1055
Esta semana
RSS
M Alto vulnerabilidad
29/09/2026
[CVE-2026-100831] Use-after-free in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Fir…
Use-after-free in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102496] Apache XmlSchema doesn't limit how deeply schema structures can be nested when it builds its schema …
Apache XmlSchema doesn't limit how deeply schema structures can be nested when it builds its schema model, so a malicious schema can make parsing recurse until the stack overflows. This causes a denial of service. Users are recommended to upgrade to version 2.3.3, which fixes this issue.
M Alto vulnerabilidad
29/09/2026
Falta de autenticación en Progress Fiddler Everywhere 8.0.2 permite acceso no autorizado a tokens OAuth
Progress Software Fiddler Everywhere 8.0.2 presenta una vulnerabilidad alta (CVSS 7.7) que permite a un atacante local sin credenciales acceder al backend .NET (Fiddler.WebUi) a través de canales HTTP y SignalR no autenticados. Esto posibilita la generación de tokens OAuth fraudulentos y la lectura del certificado raíz man-in-the-middle. Afecta principalmente a desarrolladores y equipos de testing que utilizan esta herramienta en México y Latinoamérica para análisis de tráfico HTTPS.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102248] A vulnerability was identified in Rebuild up to 4.4.7/4.5.0-beta5. This affects an unknown part of t…
A vulnerability was identified in Rebuild up to 4.4.7/4.5.0-beta5. This affects an unknown part of the file /user/login of the component Login Endpoint. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Alto vulnerabilidad
29/09/2026
Vulnerabilidad de autorización en REBUILD hasta v4.4.11 permite acceso no autorizado remoto
Se ha identificado una falla de seguridad en REBUILD versiones hasta 4.4.11 que afecta el módulo /commons/file-editor-save, permitiendo omitir controles de autorización mediante manipulación de parámetros (url/fileKey). Esta vulnerabilidad de severidad alta (CVSS 7.3) puede ser explotada remotamente y su código de ataque ya es público. Empresas en LATAM que usan REBUILD para gestión de contenidos están expuestas a acceso no autorizado a archivos sensibles.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-96326] The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to S…
The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Rich Text Editor Field in all versions up to, and including, 2.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses …
M Alto vulnerabilidad
29/09/2026
[CVE-2026-101860] A vulnerability was found in RaspAP raspap-webgui up to 3.5.5. Affected by this issue is the functio…
A vulnerability was found in RaspAP raspap-webgui up to 3.5.5. Affected by this issue is the function PluginInstaller::addSudoers of the file src/RaspAP/Plugins/PluginInstaller.php of the component sudo Configuration. Performing a manipulation results in improper privilege management. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
28/09/2026
[CVE-2026-102281] Nest is a framework for building scalable Node.js server-side applications. Prior to 11.2.4 and 12.0…
Nest is a framework for building scalable Node.js server-side applications. Prior to 11.2.4 and 12.0.2, a single message with a deeply nested object in its pattern can terminate a NestJS microservice using the TCP or RabbitMQ transport. ServerTCP#handleMessage and ServerRMQ#handleMessage pass a client-controlled non-string pattern to JSON.stringify to derive the handler lookup key; sufficiently de…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-18413] The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small…
The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small: the buffer_size field of struct adc_sequence in include/zephyr/drivers/adc.h documents that "the driver must ensure that samples are not written beyond the limit and it must return an error if the buffer turns out to be not large enough". The NXP MCUX LPADC driver did not honour that contract. mcu…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-18414] The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small…
The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small: the buffer_size field of struct adc_sequence in include/zephyr/drivers/adc.h documents that "the driver must ensure that samples are not written beyond the limit and it must return an error if the buffer turns out to be not large enough". The ADI MAX32 driver did not honour that contract. start_re…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-16513] The userspace verifier z_vrfy_rtio_sqe_copy_in_get_handles() in subsys/rtio/rtio_syscalls.c (subsys/…
The userspace verifier z_vrfy_rtio_sqe_copy_in_get_handles() in subsys/rtio/rtio_syscalls.c (subsys/rtio/rtio_handlers.c before v4.3.0) validated the RTIO object handle and the sqes input array, but not the handle out-parameter. On the first loop iteration it executed *handle = sqe, storing the kernel address of the newly acquired submission-queue entry through a pointer taken verbatim from user m…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-101916] @grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. P…
@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.6 and 1.14.5, getAuthContext does not distinguish authorized from unauthorized peer certificates when server credentials set requireClientCertificate to false. When applications use the returned authentication context, they can treat an unauthorized certificate as authorized, causing im…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-87114] A flaw was found in kube-compare. When processing a 'container://' reference path, the tool incorrec…
A flaw was found in kube-compare. When processing a 'container://' reference path, the tool incorrectly executes an untrusted container image's entrypoint instead of merely extracting data from a stopped container. This allows a remote attacker to achieve arbitrary code execution on the operator's workstation. If the Docker daemon requires elevated privileges, the untrusted code may execute with r…
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-88804] An unauthenticated update of public UI settings could be used by remote attackers to execute a store…
An unauthenticated update of public UI settings could be used by remote attackers to execute a stored cross-site scripting attack in the Rancher UI, in SUSE Rancher 2.15 before 2.15.2, 2.14 before 2.14.6, 2.13 before 2.13.10, 2.12 before 2.12.14 and 2.11 before 2.11.18.
M Alto vulnerabilidad
28/09/2026
Vulnerabilidad alta de inyección en Zohocorp ManageEngine DDI Central 6.2.0
ManageEngine DDI Central versiones 6.2.0 con build inferior a 6201 contiene una vulnerabilidad de inyección de configuración en Keepalived que permite a operadores autenticados modificar la configuración de alta disponibilidad. Un usuario con rol de operador podría ejecutar comandos con privilegios root en el servidor DDI Central, comprometiendo la integridad de infraestructuras altas de DNS y DHCP en empresas latinoamericanas.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
28/09/2026
Vulnerabilidad crítica de desbordamiento de buffer en FAST FAC1200R 5.0
Se identificó una vulnerabilidad de desbordamiento de búfer basado en pila (CVSS 9.9) en el analizador MmtAtePrase del dispositivo FAST FAC1200R versión 5.0_20201119_1.0.2, permitiendo explotación remota sin autenticación. El exploit se encuentra públicamente disponible y el fabricante no ha respondido a notificaciones previas. Esta vulnerabilidad afecta principalmente a empresas de telecomunicaciones, ISPs y proveedores de servicios en México y LATAM que utilizan equipos FAST en infraestructuras críticas.
M Alto vulnerabilidad
28/09/2026
Vulnerabilidad de desbordamiento de búfer en productos Wi-Fi BUFFALO permite denegación de servicio
Existe una vulnerabilidad de desbordamiento de búfer basado en pila en equipos Wi-Fi BUFFALO que permite a un atacante no autenticado enviar solicitudes HTTP especialmente diseñadas para provocar una denegación de servicio (DoS). Esta vulnerabilidad afecta principalmente a pequeñas y medianas empresas en LATAM que utilizan routers y puntos de acceso BUFFALO en sus infraestructuras de red corporativa e ISP.
M Alto vulnerabilidad
28/09/2026
Vulnerabilidad alta en productos Wi-Fi BUFFALO permite ejecución remota de comandos
BUFFALO Wi-Fi products procesa incorrectamente entradas en formularios web para construir cadenas de comandos del sistema operativo, permitiendo a usuarios administrativos ejecutar comandos OS arbitrarios mediante solicitudes HTTP maliciosamente elaboradas. Afecta principalmente a infraestructuras de conectividad en pequeñas y medianas empresas (PYMES) de México y Latinoamérica que utilizan equipos BUFFALO para redes corporativas.
M Alto vulnerabilidad
28/09/2026
Vulnerabilidad de validación en OpenDMARC afecta autenticación de correo en servidores hasta versión 1.4.2
Se ha identificado una falla en Trusted Domain Project OpenDMARC versiones hasta 1.4.2 que permite eludir validaciones de equivalencia en el componente Domain Handler (archivo policy.c). La vulnerabilidad puede explotarse remotamente y afecta la autenticación DMARC de correos electrónicos en servidores de correo, con riesgo de suplantación de dominios. Empresas en LATAM que usan OpenDMARC deben aplicar actualizaciones urgentes, especialmente aquellas que procesan comunicaciones altas.
M Alto vulnerabilidad
28/09/2026
[CVE-2026-82386] Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a weblog adminis…
Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a weblog administrator to read files readable by the Roller process and reach internal network addresses by importing a crafted OPML document, because the bookmark import parser does not disable external entity resolution. No non-default configuration is required; the import is reached through the administrator boo…