Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ui" — 3507 resultados ✕ Limpiar búsqueda
22,331
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1201
Esta semana
RSS
U Alto vulnerabilidad
02/07/2026
[CVE-2026-55119] A malicious actor with access to the network and low privileges could exploit an Improper Access Con…
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Talk Application to escalate privileges within the UniFi Talk Application.
U Alto vulnerabilidad
02/07/2026
[CVE-2026-54404] A malicious actor with access to the network and low privileges could exploit a series of authentica…
A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi OS to escalate privileges within such UniFi OS devices or instances.
U Alto vulnerabilidad
02/07/2026
[CVE-2026-54405] A malicious actor with access to the network could exploit an Improper Input Validation vulnerabilit…
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Network Application to execute a Denial of Service (DoS) attack on the application.
U Alto vulnerabilidad
02/07/2026
[CVE-2026-54406] A malicious actor with access to the network and high privileges could exploit a Path Traversal vuln…
A malicious actor with access to the network and high privileges could exploit a Path Traversal vulnerability found in self-hosted instances of UniFi Network Application to escalate write permission on the host device.
U Alto vulnerabilidad
02/07/2026
[CVE-2026-54407] A malicious actor with access to the network could exploit an Improper Access Control vulnerability …
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication in certain UniFi Protect Application API endpoints.
U Alto vulnerabilidad
02/07/2026
[CVE-2026-54408] A malicious actor with access to the network could exploit an Improper Access Control vulnerability …
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication for data streaming.
U Alto vulnerabilidad
02/07/2026
[CVE-2026-54409] A malicious actor with access to the network and under certain conditions could exploit an Improper …
A malicious actor with access to the network and under certain conditions could exploit an Improper Initialization vulnerability found in UniFi Protect Application to bypass authentication in UniFi Protect Cameras.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
U Alto vulnerabilidad
02/07/2026
[CVE-2026-55110] A malicious actor who lures an authenticated user to a malicious page could exploit a Cross-Origin R…
A malicious actor who lures an authenticated user to a malicious page could exploit a Cross-Origin Resource Sharing (CORS) misconfiguration found in UniFi OS to trigger actions in UniFi OS using that user's session.
U Alto vulnerabilidad
02/07/2026
[CVE-2026-55111] A malicious actor with access to the network could exploit a Path Traversal vulnerability found in U…
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Protect Floodlight devices to access files on the UniFi Protect Floodlight.
L Alto vulnerabilidad
02/07/2026
[CVE-2026-53358] In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: use chan time…
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() l2cap_chan_close() removes the channel from conn->chan_l, which must be done under conn->lock. cleanup_listen() runs under the parent sk_lock, so acquiring conn->lock would invert the established conn->lock -> chan->lock -> sk_lock order. Instead of calling…
U Crítico vulnerabilidad
02/07/2026
[CVE-2026-54400] A malicious actor with access to the network and high privileges could exploit an Improper Access Co…
A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device.
U Alto vulnerabilidad
02/07/2026
[CVE-2026-54401] A malicious actor with access to the network and low privileges could exploit a Server-Side Request …
A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) to escalate privileges within such UniFi OS devices or instances.
U Crítico vulnerabilidad
02/07/2026
[CVE-2026-54402] A malicious actor with access to the network and low privileges could exploit an Improper Input Vali…
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device.
U Alto vulnerabilidad
02/07/2026
[CVE-2026-54403] A malicious actor with access to the network could exploit a Path Traversal vulnerability found in c…
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to bypass authentication of such UniFi OS devices or instances.
U Crítico vulnerabilidad
02/07/2026
[CVE-2026-50746] A malicious actor with access to the network could exploit an Improper Access Control vulnerability …
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
U Crítico vulnerabilidad
02/07/2026
[CVE-2026-50747] A malicious actor with access to the network and low privileges could exploit a series of authentica…
A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi Talk Application to escalate privileges on the host device.
U Crítico vulnerabilidad
02/07/2026
[CVE-2026-50748] A malicious actor with access to the network and low privileges could exploit an Improper Input Vali…
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.
M Alto vulnerabilidad
02/07/2026
[CVE-2026-58652] luci-app-travelmate (and the travelmate package) contain a privilege-escalation flaw: a LuCI/rpcd se…
luci-app-travelmate (and the travelmate package) contain a privilege-escalation flaw: a LuCI/rpcd session holding the luci-app-travelmate write ACL is granted config-wide UCI write access to the travelmate configuration. While the LuCI UI restricts the auto-login script picker to /etc/travelmate/*.login, this is only a frontend restriction. The backend travelmate service (running as root) reads th…
M Crítico vulnerabilidad
02/07/2026
[CVE-2026-5524] The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote …
The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in all versions up to and including 5.1.8. This is due to insufficient file extension validation in the do_image_upload() function where user-supplied input from the acceptFileTypes POST parameter is directly interpolated into a regular expression used to validate uploaded files. Atta…
M Alto vulnerabilidad
02/07/2026
[CVE-2026-11946] An unauthenticated remote attacker can exhaust server memory via the GetEndpoints Discovery Service …
An unauthenticated remote attacker can exhaust server memory via the GetEndpoints Discovery Service in open62541. The endpointUrl field of GetEndpointsRequest is not validated for length. An attacker can declare an arbitrarily large string (up to ~4.09 GB via the UInt32 length field) delivered across intermediate chunks without ever sending the final chunk. The server buffers all chunks in RAM ind…