Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1771
Esta semana
RSS
M Crítico vulnerabilidad
11/06/2026
[CVE-2026-41005] Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a …
Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML signatures from the Identity Provider (authenticity) in two SAML flows: the OAuth 2.0 SAML2 bearer grant (token endpoint) and browser SSO (ACS) when wantAssertionSigned is set to false. Assertions or responses that were unsigned but contained encrypted content could still be accep…
M Crítico vulnerabilidad
11/06/2026
[CVE-2026-49973] Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that allows u…
Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that allows unauthenticated remote attackers to hijack initial setup by submitting the _set_password parameter to the settings API endpoint without any network origin restriction. Attackers on any reachable network can send a POST request to the settings endpoint during the first-run setup window to persist an a…
P Crítico vulnerabilidad
11/06/2026
[CVE-2026-45177] Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its int…
Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication components. A remote, unauthenticated attacker could exploit this by submitting a specially crafted request. Under specific circumstances, this could allow the attacker to manipulate internal validation mechanisms, potentially leading to a bypass of identity verification and the…
M Crítico vulnerabilidad
11/06/2026
[CVE-2026-49261] MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11…
MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As a workaround, anyone who cannot upgrade now should…
M Crítico vulnerabilidad
11/06/2026
[CVE-2026-9648] The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS cli…
The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS clients to accept certificates whose Subject Alternative Names fall outside the issuing CA’s permitted subtrees. This oversight enables an attacker who compromises a name-constrained sub-CA to impersonate domains beyond its intended scope.
M Crítico vulnerabilidad
11/06/2026
[CVE-2026-11839] Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies …
Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies Inc. Rotaban allows Upload a Web Shell to a Web Server. This issue affects Rotaban: from V2026.06.002 before V2026.06.003.
M Crítico vulnerabilidad
11/06/2026
[CVE-2026-38581] SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0 allows remote attacker…
SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0 allows remote attackers to execute arbitrary SQL commands via the idFormMain parameter to /substudy/ezform.php (line 14) and the id parameter (line 49). The parameters are concatenated directly into SQL queries without sanitization or parameterized statements.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
11/06/2026
[CVE-2026-7852] Unrestricted upload of file with dangerous type vulnerability in Limatek System Inc. LimRAD NAC allo…
Unrestricted upload of file with dangerous type vulnerability in Limatek System Inc. LimRAD NAC allows Remote Code Inclusion. This issue affects LimRAD NAC: before 5.5.7.3.9.
M Crítico vulnerabilidad
11/06/2026
[CVE-2026-11561] Improper neutralization of special elements used in an expression language statement ('expression la…
Improper neutralization of special elements used in an expression language statement ('expression language injection') vulnerability in Soagen Informatics Technologies Software and Consulting Inc. Apinizer allows Code Injection. This issue affects Apinizer: from 2026.04.0 before 2026.04.6.
M Crítico vulnerabilidad
10/06/2026
[CVE-2026-46695] Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and la…
Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. Prior to version 0.9.0, Boxlite does not restrict the kernel capabilities available inside the container, malicious code can remount the directory in rw mode, thereby gaining write access to that directory. This allows malicious code to perform …
M Crítico vulnerabilidad
10/06/2026
[CVE-2026-46703] Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and la…
Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. Prior to version 0.9.0, Boxlite allows users to specify the OCI image used by containers in the sandbox. However, when processing tar entries in OCI images, Boxlite does not account for the possibility that entries may be symlinks pointing to ab…
P Crítico vulnerabilidad
10/06/2026
[CVE-2026-0274] An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Corte…
An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resources.
P Crítico vulnerabilidad
10/06/2026
[CVE-2026-50638] Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injec…
Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions such as dogstatsd) allow mutiple metrics, separated by newlines, to be sent per packet. Metrics::Any::Adapter::DogStatsd which extends Metrics::Any::Adapter::Statsd, which has a similar vulnerability. In addition, the _tags function does not check tags f…
M Crítico vulnerabilidad
10/06/2026
[CVE-2026-50566] Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of …
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, a tenant with environments.fission.io create/update RBAC can run privileged / allowPrivilegeEscalation / dangerous-capability containers in the Fission function or builder namespace, scheduled under the executor's high-privilege serv…
M Crítico vulnerabilidad
10/06/2026
[CVE-2026-50545] Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of …
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, the Environment.spec.runtime.podSpec / spec.builder.podSpec passthrough lacked validation, and MergePodSpec propagated dangerous fields into the generated pods. This issue has been patched in version 1.24.0.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
10/06/2026
[CVE-2026-50563] Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of …
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, Fission's Container Executor path lets a tenant supply Function.spec.podspec directly; the executor merges it into the executor-built podspec and creates a Deployment whose pods run the user's container image. This issue has been pat…
M Crítico vulnerabilidad
10/06/2026
[CVE-2026-50564] Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of …
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, Fission's Environment CRD exposes spec.runtime.podSpec and spec.builder.podSpec, which are merged into the Kubernetes pod specs for runtime and builder pods. The merge logic propagated hostNetwork, hostPID, hostIPC, container privile…
M Crítico vulnerabilidad
10/06/2026
[CVE-2026-46614] Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of …
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.23.0, the Fission router registers an internal-style route — /fission-function/ and /fission-function// — for every Function object, independent of whether any HTTPTrigger exists for that function. The route was mounted on …
K Crítico vulnerabilidad
10/06/2026
[CVE-2026-53475] A flaw was found in assisted-migration-agent. The application hardcodes insecure Transport Layer Sec…
A flaw was found in assisted-migration-agent. The application hardcodes insecure Transport Layer Security (TLS) connections when communicating with vCenter. This vulnerability allows a Man-in-the-Middle (MITM) attacker to intercept and harvest vCenter administrator credentials. This can lead to unauthorized access to vCenter.
K Crítico vulnerabilidad
10/06/2026
[CVE-2026-53476] A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local…
A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local area network (LAN), can exploit a path traversal vulnerability. By crafting a specially designed gzipped tarball, the attacker can bypass security checks and write arbitrary files to the system. This could ultimately lead to the execution of unauthorized code on the appliance.