Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Rti" — 919 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Alto vulnerabilidad
10/09/2026
[CVE-2026-64837] ICEcoder through 8.1 passes an unescaped filesystem path into a shell command in lib/properties.php,…
ICEcoder through 8.1 passes an unescaped filesystem path into a shell command in lib/properties.php, allowing authenticated users to inject OS commands through directory names. Attackers can create directories with shell metacharacters in their names and access the Properties function to execute arbitrary commands as the web-server user via popen().
M Alto vulnerabilidad
10/09/2026
Vulnerabilidad de denegación de servicio en t-digest 3.1-3.3 (CVE-2026-87962)
t-digest versiones 3.1 a 3.3 contienen una vulnerabilidad de denegación de servicio en MergingDigest.fromBytes que no valida campos de longitud y capacidad en datos serializados. Atacantes pueden enviar digests serializados manipulados para provocar excepciones ArrayIndexOutOfBoundsException o NegativeArraySizeException, abortando el hilo de procesamiento. Afecta aplicaciones que usan t-digest para compresión de datos o análisis de distribuciones en sistemas altas.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-19583] Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the…
Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. However, no such check was implemented for client monitoring artifacts. Additionally there was no requirement that client monitoring artifacts carry the CLIENT_EVENTS …
M Alto vulnerabilidad
09/09/2026
[CVE-2026-22591] eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG…
eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.6.12, 2.14.6, 3.2.4, and 3.4.3, Fast DDS’s implementation of SQL‑based content filtering (DDSSQLFilter) allows any participant in a DDS domain to remotely crash other Fast DDS participants by sending a single crafted SEDP `DATA` submessage whose `PID_C…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87822] t-digest versions 3.1 through 3.3 fail to validate centroid means during deserialization in MergingD…
t-digest versions 3.1 through 3.3 fail to validate centroid means during deserialization in MergingDigest.fromBytes, allowing attackers to inject NaN values that bypass validation checks. Attackers can craft malicious serialized digests containing NaN centroids that degrade sorting performance from O(n log n) to O(n squared), causing severe processing delays during merge operations.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-86201] PocketMine-MP before 5.41.1 contains a denial of service vulnerability in LoginPacket processing whe…
PocketMine-MP before 5.41.1 contains a denial of service vulnerability in LoginPacket processing where large or complex structures in unknown clientData JWT properties cause excessive logging without sanitization. Attackers can send crafted LoginPackets with deeply nested or massive object structures to trigger out-of-memory conditions and crash the server.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-86199] PocketMine-MP versions before 5.43.1 fail to properly validate the Certificate field during offline …
PocketMine-MP versions before 5.43.1 fail to properly validate the Certificate field during offline login authentication. Unauthenticated players can trigger an uninitialized property access error that crashes the server.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
09/09/2026
[CVE-2024-58381] PocketMine-MP before 5.11.1 contains a denial of service vulnerability in LoginPacket JSON processin…
PocketMine-MP before 5.11.1 contains a denial of service vulnerability in LoginPacket JSON processing that allows remote attackers to crash the server by sending malformed JSON data. Attackers can exploit improper object initialization from scalar JSON types to trigger unset required properties, causing the application to crash.
M Crítico vulnerabilidad
09/09/2026
[CVE-2026-85102] Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway…
Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
M Crítico vulnerabilidad
09/09/2026
[CVE-2026-85103] A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote a…
A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.
M Alto vulnerabilidad
09/09/2026
Vulnerabilidad XSS almacenado en SiYuan anterior a v3.8.2 afecta búsqueda de activos
SiYuan versiones anteriores a v3.8.2 contienen una vulnerabilidad de cross-site scripting (XSS) almacenado en la función de búsqueda de activos. Atacantes autenticados pueden inyectar código malicioso en nombres de archivos que se ejecuta en el navegador de usuarios legítimos, permitiendo manipulación de estado de aplicación y ejecución de solicitudes API no autorizadas. El riesgo es moderado-alto en entornos colaborativos donde múltiples usuarios acceden a repositorios compartidos.
M Alto vulnerabilidad
09/09/2026
Vulnerabilidad XSS almacenado alta en SiYuan anterior a v3.8.2 afecta vista previa de activos
SiYuan antes de la versión 3.8.2 contiene una vulnerabilidad de cross-site scripting (XSS) almacenado en la función de vista previa de activos de búsqueda. Los atacantes pueden insertar contenido malicioso en activos de texto dentro de espacios de trabajo para ejecutar código JavaScript con privilegios autenticados. Esto permite acceso no autorizado a APIs internas y manipulación de datos en la instancia SiYuan, representando riesgo significativo para organizaciones que almacenan información sensible en esta plataforma de gestión de conocimiento.
M Alto vulnerabilidad
09/09/2026
Vulnerabilidad alta en PasswordPusher: condición de carrera permite eludir límites de visualización
PasswordPusher anterior a versión 2.11.1 contiene una vulnerabilidad de time-of-check-to-time-of-use que permite a atacantes no autenticados acceder múltiples veces a secretos de un solo uso enviando solicitudes concurrentes al endpoint de visualización, antes de que se incremente el contador de vistas y expire el contenido. Afecta sistemas de gestión de credenciales en empresas de México y LATAM que dependen de esta herramienta para compartir contraseñas temporales.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-78492] Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5…
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-79637] Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5…
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
09/09/2026
[CVE-2026-80122] Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5…
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-78491] Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5…
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-78494] Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5…
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-79636] Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5…
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Validation of Certificate with Host Mismatch vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86819] Waves Central for macOS contains a local privilege escalation in the privileged helper service. The …
Waves Central for macOS contains a local privilege escalation in the privileged helper service. The helper authorizes connecting XPC clients by comparing the caller's code-signing certificate chain for equality with its own, rather than validating the caller against a pinned code requirement (application identifier and Team ID). A local, authenticated user can execute code within the vendor-signed…