Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ui" — 3500 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1055
Esta semana
RSS
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100686] Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/group…
Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/groups/:groupId/apps endpoint, allowing builders to assign application roles across workspace boundaries. A builder of a single workspace can exploit missing per-app authorization checks to grant themselves admin roles in other workspaces by modifying user group role mappings.
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100692] Hugo is a static site generator. In versions after v0.123.0 and before v0.166.0, Hugo's symlink conf…
Hugo is a static site generator. In versions after v0.123.0 and before v0.166.0, Hugo's symlink confinement checks stopped at the mount root itself, so a theme or module checked into themes/ (or a vendored module) could contain a symlink at a mount root (for example themes/mytheme/assets -> /some/dir/outside). Files behind such a symlink were readable during a site build through resources.Get, res…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100680] Budibase versions before 3.45.0 fail to disable external JSON reference resolution in the OpenAPI/Sw…
Budibase versions before 3.45.0 fail to disable external JSON reference resolution in the OpenAPI/Swagger import validator, allowing authenticated builders to read arbitrary local files. Attackers with builder access can embed file:// references in OpenAPI specifications submitted to the import endpoint to exfiltrate sensitive files including environment variables containing JWT secrets, API keys,…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100682] Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in the PWA icon upload …
Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in the PWA icon upload endpoint that extracts user-supplied ZIP archives without proper symlink validation. Attackers with BUILDER role can craft a malicious ZIP with leaf symlink entries followed by duplicate file entries to write arbitrary files as root, enabling remote code execution.
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100683] Budibase (@budibase/server) before 3.45.0 builds MySQL and MSSQL column-rename DDL in packages/backe…
Budibase (@budibase/server) before 3.45.0 builds MySQL and MSSQL column-rename DDL in packages/backend-core/src/sql/sqlTable.ts by interpolating identifiers directly into a raw query string (backtick-quoted for MySQL, a single-quoted sp_rename literal for MSSQL) without applying the project's quoteMySqlIdentifier / quoteSqlServerIdentifier helpers. An attacker with DDL rights on a connected MySQL/…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100685] Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint by workspace, allowi…
Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint by workspace, allowing builders to enumerate chat identity link records across all workspaces in a tenant. Attackers with builder access to a single workspace can retrieve sensitive chat identity linking data including user IDs and external chat service identifiers from other workspaces they have no permission to acces…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100664] Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.2.Final through 4.2.17.Final builds t…
Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.2.Final through 4.2.17.Final builds the HTTP/3 :authority pseudo-header from the HTTP/1 Host header before considering the authority of an absolute-form HTTP/1 request-target. In HttpConversionUtil.toHttp3Headers(HttpMessage, boolean) — reached via Http3FrameToHttpObjectCodec(false) — a non-empty Host header takes precedence over the r…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100665] Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostname verification fix…
Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostname verification fix in the QUIC certificate verification path when using a plain X509TrustManager. The BoringSSLCertificateVerifyCallback discards the SSLEngine for plain trust managers, preventing endpoint identification from running even when HTTPS verification is configured. Attackers on the network path can presen…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100660] Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.0.Final through 4.2.17.Final retains unbo…
Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.0.Final through 4.2.17.Final retains unbounded per-stream QPACK encoder state. QpackEncoder stores a queue and a dynamic-table index tracker for every encoded field section that references the QPACK dynamic table, keyed by the peer-controlled QUIC stream ID, and these entries are released only when the remote decoder sends a Section Acknow…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100631] Parse Server is an open source backend server. In versions prior to 8.6.90 and in versions from 9.0.…
Parse Server is an open source backend server. In versions prior to 8.6.90 and in versions from 9.0.0 prior to 9.10.1-alpha.9, the device token deduplication logic for installation records does not validate the type of client-supplied installation fields before using them to build database queries. An unauthenticated remote attacker who knows only the public application ID can submit non-string va…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100623] Capgo (capgo.app) exposes the legacy membership table public.org_users directly through Supabase Pos…
Capgo (capgo.app) exposes the legacy membership table public.org_users directly through Supabase PostgREST. The table's row-level security policies "Allow org admin to insert" and "Allow org admin to update" only verify that the caller has admin rights in the target organization (public.check_min_rights('admin', ...)); they do not require a pending invitation in tmp_users, acceptance of an invite …
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100625] Capgo (capgo.app) exposes a native build TUS upload proxy (supabase/functions/_backend/public/build/…
Capgo (capgo.app) exposes a native build TUS upload proxy (supabase/functions/_backend/public/build/upload.ts) that authorizes a caller against a single build job identified by the supplied builder_job_id and validates only that job's stored upload_path, but then forwards the user-controlled TUS resource suffix taken from /build/upload/:jobId/* to the builder service while injecting Capgo's privil…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100617] Cap-go capgo.app fails to validate that principals in channel_permission_overrides belong to the org…
Cap-go capgo.app fails to validate that principals in channel_permission_overrides belong to the organization, allowing authenticated app/org admins to grant channel permissions to non-member users. Attackers with admin privileges can insert override rows with arbitrary external user UUIDs to grant channel-scoped permissions such as channel.promote_bundle to users outside the organization.
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100610] Flowise through 3.1.4 exposes GET /api/v1/upsert-history/:id and PATCH /api/v1/upsert-history withou…
Flowise through 3.1.4 exposes GET /api/v1/upsert-history/:id and PATCH /api/v1/upsert-history without route-level permission checks, and the backing service performs no workspace or ownership validation. getAllUpsertHistory() returns UpsertHistory rows selected solely by an attacker-supplied chatflowid, and patchDeleteUpsertHistory() deletes rows by an attacker-supplied array of record UUIDs. As a…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100605] Flowise through 3.1.4 contains missing route-level RBAC checks on chat message endpoints that allow …
Flowise through 3.1.4 contains missing route-level RBAC checks on chat message endpoints that allow low-privileged API keys to read and delete chat history. Attackers with valid but low-privileged API keys can access GET and DELETE chat message routes without required flow permissions to read chat histories, prompts, model responses, and delete messages.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
26/09/2026
Vulnerabilidad alta en paquete npm OpenClaw permite bypass de autorización de propietario
OpenClaw (paquete npm `openclaw`) anterior a versión 2026.7.1 no valida correctamente permisos de propietario en solicitudes de autorización de Claude Code a través del canal MCP. Un usuario autorizado sin permisos de propietario puede aprobar o denegar solicitudes de permisos destinadas al administrador de la cuenta, ejecutando acciones sin consentimiento del propietario. Afecta sistemas de automatización y desarrollo que dependan de este paquete en entornos empresariales.
M Alto vulnerabilidad
26/09/2026
Vulnerabilidad alta en paquete npm OpenClaw permite eludir restricciones administrativas (CVE-2026-100588)
OpenClaw versiones anteriores a 2026.7.1 no valida correctamente permisos administrativos en el método node.invoke, permitiendo a usuarios con permisos de escritura acceder a funciones de control de navegador sin autorización. En arquitecturas Gateway que validan identidad del llamante, esto expone sistemas a escalación de privilegios no autorizada.
M Alto vulnerabilidad
26/09/2026
Vulnerabilidad de suplantación de identidad en OpenClaw (npm) permite escalación de privilegios
El paquete npm 'openclaw' anterior a versión 2026.7.1 presenta una falla alta en la validación de identidad del solicitante en arquitecturas de Gateway con autenticación. Un atacante con permisos de escritura puede suplantar la identidad de otros usuarios para ejecutar acciones de canal no autorizadas. Afecta principalmente a sistemas de integración empresarial en entornos cloud y on-premise en LATAM.
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100551] OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the C…
OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the Control UI. While native connections enforced the saved Gateway fingerprint, the authenticated Terminal and session Dashboard WebViews omitted it. If a user had accepted a Gateway fingerprint, an attacker able to redirect the same host and port and present a different certificate that is accepted by …
M Alto vulnerabilidad
25/09/2026
[CVE-2026-5267] Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an eve…
Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an event-streaming API that does not properly enforce authentication. An unauthenticated attacker with network access to the affected service could access the event stream and potentially obtain sensitive information.