Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ui" — 3500 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1055
Esta semana
RSS
M Alto vulnerabilidad
28/09/2026
[CVE-2026-82375] Server-Side Request Forgery (SSRF) in Apache Roller 6.1.5 allows an authenticated user with entry-ed…
Server-Side Request Forgery (SSRF) in Apache Roller 6.1.5 allows an authenticated user with entry-editing rights on a weblog to cause outbound HTTP requests to attacker-chosen destinations through legacy outbound Trackback and entry enclosure handling. The Trackback control is hidden in the standard UI, but its action remains directly reachable; the enclosure path is relevant only when an author s…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-82376] Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a user with entr…
Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a user with entry-editing rights on a weblog to cause the server to parse an attacker-influenced trackback response with an XML parser that does not disable external entity resolution, leading to disclosure of files readable by the Roller process. The Trackback control is hidden in the standard UI, but its action r…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-82380] Cross-Site Request Forgery (CSRF) in Apache Roller 6.1.5 allows a remote attacker to cause a logged-…
Cross-Site Request Forgery (CSRF) in Apache Roller 6.1.5 allows a remote attacker to cause a logged-in user to perform state-changing actions under the victim's authority, because the CSRF validation filters accept a request that does not submit the required salt token, validating instead against a value the server itself generated for the request. No optional feature or non-default configuration …
M Alto vulnerabilidad
28/09/2026
[CVE-2026-82348] Authorization Bypass Through User-Controlled Key in Apache Roller 6.1.5 allows an authenticated user…
Authorization Bypass Through User-Controlled Key in Apache Roller 6.1.5 allows an authenticated user with authoring rights on one weblog to read, modify, or delete resources belonging to another weblog through unscoped identifier-based lookups. This affects multi-user installations where users are intended to be isolated between weblogs; no optional feature or non-default configuration is required…
M Crítico vulnerabilidad
27/09/2026
[CVE-2026-100886] A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. …
A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. The affected element is an unknown function of the component Debug Service. Such manipulation leads to improper authentication. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any wa…
M Alto vulnerabilidad
27/09/2026
[CVE-2026-96280] The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functio…
The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functions expecting gsize (32 bits on 32-bit systems), causing undersized allocations while subsequent operations use the original 64-bit size, leading to heap buffer overflows. An attacker controlling an OCI registry can craft a delta stream that triggers this during flatpak install/update, potentially ac…
M Crítico vulnerabilidad
27/09/2026
[CVE-2026-101065] Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, th…
Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart command documented in the README starts the container listening on 0.0.0.0:8080 with authentication disabled by default. When authentication is disabled, every request is mapped to a synthetic "nobody" user that holds the Owner and Admin roles, so any unauthenticated party who ca…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
27/09/2026
[CVE-2026-100870] Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 build administrator password-res…
Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 build administrator password-reset links using the request Host header without validation, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains. Attackers can request password resets for known administrator email addresses with forged Host headers to intercept valid reset tokens and take over …
M Alto vulnerabilidad
27/09/2026
Vulnerabilidades altas en Heym anterior a 0.0.53 permiten ejecución arbitraria de código
Heym versiones anteriores a 0.0.53 contienen múltiples vulnerabilidades altas (CVSS 8.8). La más grave permite ejecución arbitraria de código Python mediante eval() sin sandbox en nodos de condición de flujos de trabajo. Cualquier usuario con permisos de edición de flujos o importación de plantillas maliciosas puede ejecutar código con privilegios del proceso backend. Afecta significativamente a empresas en LATAM que utilizan esta herramienta en automatización de procesos altas.
M Alto vulnerabilidad
27/09/2026
Vulnerabilidad alta de inyección de código en AzuraCast anterior a 0.23.6
AzuraCast versiones anteriores a 0.23.6 contiene una vulnerabilidad de inyección de código en el campo de contraseña de retransmisión remota que permite a atacantes con permisos de RemoteRelays ejecutar código arbitrario en el proceso Liquidsoap. La falla resulta de una migración incompleta desde el método vulnerable cleanUpString a toRawString, exponiendo servidores de radio en línea a compromisos de integridad, divulgación de claves API internas y disrupciones operacionales.
M Alto vulnerabilidad
27/09/2026
Vulnerabilidad alta de inyección de código en AzuraCast anterior a 0.23.4
AzuraCast versiones anteriores a 0.23.4 contiene una vulnerabilidad de inyección de código en el método ConfigWriter::cleanUpString() que no desinfecta correctamente secuencias de interpolación de Liquidsoap. Usuarios autenticados con permisos de Media o Profile pueden inyectar código Liquidsoap arbitrario en configuraciones de estaciones de radio, permitiendo ejecución remota de comandos mediante expresiones #{process.run()} en URLs de listas de reproducción o campos de metadatos. Afecta principalmente a emisoras de radio web y plataformas de streaming en LATAM que usan AzuraCast para gestión de contenido.
M Alto vulnerabilidad
27/09/2026
Vulnerabilidad alta en AzuraCast anterior a 0.23.8: SSRF y lectura de archivos locales
AzuraCast antes de la versión 0.23.8 contiene vulnerabilidades de Server-Side Request Forgery (SSRF) y lectura de archivos locales en el módulo AutoDJ de obtención de playlists remotas. Un usuario con permisos de Media en la estación puede crear playlists con URLs remotas que apunten a rutas file:// o direcciones internas (loopback/link-local), exponiendo información sensible del servidor. Afecta principalmente a emisoras de radio online y plataformas de streaming en LATAM que utilizan este software para automatizar contenido.
M Alto vulnerabilidad
27/09/2026
Vulnerabilidad de inyección de comandos en AzuraCast 0.23.x afecta servidores de radio
AzuraCast versiones hasta 0.23.x contiene una vulnerabilidad de inyección de comandos en la generación de configuración de Liquidsoap para grabaciones en vivo. Usuarios autenticados con permisos de Streamers pueden insertar metacaracteres de shell en nombres de usuario y ejecutar comandos con privilegios del proceso Liquidsoap cuando finaliza la grabación. Esta vulnerabilidad afecta principalmente a emisoras de radio y plataformas de streaming que utilizan AzuraCast en infraestructura on-premise o en la nube en LATAM.
M Alto vulnerabilidad
27/09/2026
Vulnerabilidad de validación de URLs en AzuraCast anterior a 0.23.8 (CVE-2026-100849)
AzuraCast, plataforma de gestión de radio web autohospedada, contiene un fallo en la validación de URLs de webhooks que permite eludir restricciones de acceso a direcciones internas. La función AbstractConnector::getValidUrl() solo rechaza direcciones link-local, permitiendo ataques SSRF contra redes RFC1918 y loopback. Radiodifusoras y proveedores de streaming en LATAM que usen conectores Generic o Discord están expuestos.
M Alto vulnerabilidad
27/09/2026
Vulnerabilidad alta de ejecución remota de código en MONAI hasta versión 1.6.0
MONAI versiones 1.6.0 y anteriores contienen una vulnerabilidad de ejecución remota de código (RCE) en el motor de configuración de bundles que permite a atacantes ejecutar código arbitrario sin validación de lista permitida. Los agresores pueden distribuir bundles maliciosos con configuraciones manipuladas que se ejecutan cuando usuarios cargan bundles mediante monai.bundle.load(), afectando laboratorios de investigación médica y centros de datos en LATAM que implementan pipelines de procesamiento de imágenes médicas.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
27/09/2026
[CVE-2026-100842] MONAI through 1.6.0 contains an eval injection vulnerability in _get_fake_spatial_shape() in monai/b…
MONAI through 1.6.0 contains an eval injection vulnerability in _get_fake_spatial_shape() in monai/bundle/scripts.py. The function validates shape expressions with a helper that walks the AST and only collects ast.Name nodes, rejecting any name other than 'p' or 'n', before passing the string to eval(). Expressions built solely from constants and attribute, subscript, or call nodes (for example "(…
M Alto vulnerabilidad
27/09/2026
[CVE-2026-100723] vm2 before 3.12.2 does not apply its Buffer backing-store ownership invariant (byteOffset === 0 and …
vm2 before 3.12.2 does not apply its Buffer backing-store ownership invariant (byteOffset === 0 and buffer.byteLength === length) to Buffers returned from host builtin modules. When an application explicitly exposes Node's zlib module through NodeVM's builtin allowlist (require: { builtin: ['zlib'] }), zlib.deflateSync can return a Buffer backed by Node's shared small-buffer pool whose .buffer is …
M Crítico vulnerabilidad
27/09/2026
[CVE-2026-100721] vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an e…
vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an embedder configures `require.external` with a custom resolver (and `context: 'host'`), `LegacyResolver.customResolve` in lib/resolver-compat.js records the resolved module directory in `this.externals` as `new RegExp('^' + escapeRegExp(resolvedPath))`, without requiring a path separator or end-of-str…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-72668] Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana Agent Builder can lead to p…
Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana Agent Builder can lead to privilege escalation. A non-administrative user able to edit a shared agent could cause privileged operations to be carried out under the identity of a higher-privileged user who subsequently interacts with that agent. Where the same user can also author workflows, this can extend to full administrat…
M Crítico vulnerabilidad
26/09/2026
[CVE-2026-100714] Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlik…
Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlike sibling settings hardened in GHSA-33mp, the field has no string_regexp or required_otp guard, and its value is concatenated unescaped into the acme.sh command line built in lib/Froxlor/Cron/Http/LetsEncrypt/AcmeSh.php and executed by the root cron via FileDir::safe_exec. Because safe_exec only bla…