Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,696
Total alertas
3097
Críticas
10327
Altas
8
Ransomware
1751
Esta semana
RSS
M Alto vulnerabilidad
10/08/2026
[CVE-2026-72566] A server-side request forgery (SSRF) vulnerability in automatisch through commit 41f3c56 allows a lo…
A server-side request forgery (SSRF) vulnerability in automatisch through commit 41f3c56 allows a low-privileged authenticated user with 'manage Flow' permission to make the server fetch arbitrary URLs and retrieve the full response body via the HTTP Request app's Custom Request action.
M Crítico vulnerabilidad
10/08/2026
[CVE-2026-72567] An improper path validation vulnerability in AsyncFuncAI/deepwiki-open through commit 16f35a0 allows…
An improper path validation vulnerability in AsyncFuncAI/deepwiki-open through commit 16f35a0 allows unauthenticated remote attackers to write to or delete arbitrary files with root privileges. The api/api.py wiki-cache endpoint constructs file paths from user-controlled owner, repo, and repo_type fields without sanitization, enabling path traversal.
M Alto vulnerabilidad
10/08/2026
[CVE-2026-72568] An out-of-bounds read vulnerability in Redis through 8.8.1 allows an adjacent unauthenticated attack…
An out-of-bounds read vulnerability in Redis through 8.8.1 allows an adjacent unauthenticated attacker to cause denial of service or information disclosure by sending a specially crafted PING message to the Redis Cluster Bus port.
M Crítico vulnerabilidad
10/08/2026
[CVE-2026-72569] A path traversal vulnerability in cube-root/directory-serve through 1.3.7 allows an unauthenticated …
A path traversal vulnerability in cube-root/directory-serve through 1.3.7 allows an unauthenticated remote attacker to delete arbitrary files outside the intended served directory when the application is run with the --delete option.
M Alto vulnerabilidad
10/08/2026
[CVE-2026-72571] A path traversal vulnerability in mustafaakin/cast-localvideo (all versions) allows an unauthenticat…
A path traversal vulnerability in mustafaakin/cast-localvideo (all versions) allows an unauthenticated remote attacker to read arbitrary files from the server. The app.js handler at lines 151-153 passes the user-supplied req.body.dir parameter directly to res.sendFile() without sanitization, enabling directory traversal via absolute paths or ../ sequences to read sensitive system files.
M Alto vulnerabilidad
10/08/2026
[CVE-2026-72572] A path traversal vulnerability in o1lab/xmysql (all versions) allows an unauthenticated remote attac…
A path traversal vulnerability in o1lab/xmysql (all versions) allows an unauthenticated remote attacker to read and download arbitrary files from the server. The lib/xapi.js file at lines 338 and 424 uses the user-controlled req.query.name parameter in path.join(cwd, name) without sanitization before passing it to res.download, enabling directory traversal via ../ sequences to access sensitive sys…
M Crítico vulnerabilidad
10/08/2026
[CVE-2026-72564] An improper authorization vulnerability in fosrl/pangolin through v1.20.0 allows an authenticated re…
An improper authorization vulnerability in fosrl/pangolin through v1.20.0 allows an authenticated remote attacker to authenticate to any resource in any organization by reusing an access token issued for a different resource.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
10/08/2026
[CVE-2026-72565] A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows unauthenticated remote attacke…
A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows unauthenticated remote attackers to bypass per-table access control and read arbitrary database tables via the Map-form @having operator.
M Alto vulnerabilidad
10/08/2026
[CVE-2026-61899] Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to downlo…
Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspath assets via specially crafted URLs. Users are recommended to upgrade to version 5.9.1, which fixes this issue.
M Alto vulnerabilidad
10/08/2026
[CVE-2026-65942] TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0. Users are recomme…
TLS hostname verification issue in Apache Ranger Client Code in versions
M Alto vulnerabilidad
10/08/2026
[CVE-2026-65948] UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0.  Note:  UnixAuth is NOT a …
UnixAuth lacks brute-force protection in Apache Ranger versions
M Alto vulnerabilidad
10/08/2026
[CVE-2026-59087] A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks f…
A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader. A remote attacker could exploit this vulnerability by tricking a user into opening a specially crafted Seattle Filmworks file. This could lead to a heap overflow, allowing the attacker to write several kilobytes of controlled data beyond the intended memory buffer. Such an overflow can r…
M Alto vulnerabilidad
10/08/2026
[CVE-2026-55814] Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0. Users are recommended to…
Missing Authentication in Apache Ranger Download APIs on versions
M Alto vulnerabilidad
10/08/2026
[CVE-2026-66403] DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor ma…
DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log information stored on the affected products may be retrieved.
M Alto vulnerabilidad
10/08/2026
[CVE-2026-66405] DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be lever…
DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be leveraged to log in to the affected products.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
10/08/2026
[CVE-2026-66407] DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication. …
DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication. The WebSocket private key may be retrieved through analyzing the traffic data via a man-in-the-middle attack, and communication contents may be altered.
M Alto vulnerabilidad
10/08/2026
[CVE-2026-64940] Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a pe…
Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a permissive regular expression, which may allow an attacker who can access the affected product to log in to the management console. As a result, the attacker may perform any operations available from the management console.
M Crítico vulnerabilidad
10/08/2026
[CVE-2026-19053] The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter bef…
The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement reachable by unauthenticated visitors, leading to a blind SQL injection.
M Alto vulnerabilidad
10/08/2026
[CVE-2026-18470] The Login & Register Forms WordPress plugin before 4.0.2 does not verify that a password reset requ…
The Login & Register Forms WordPress plugin before 4.0.2 does not verify that a password reset request comes from the account's owner, and does not adequately redact the address returned in its response, allowing unauthenticated users to obtain registered users' email addresses, including administrators'.
M Alto vulnerabilidad
10/08/2026
[CVE-2026-18946] The Contact Form to Any API WordPress plugin before 3.0.7 does not use a random filename when copyin…
The Contact Form to Any API WordPress plugin before 3.0.7 does not use a random filename when copying files uploaded through contact forms into a publicly accessible directory, allowing unauthenticated attackers to enumerate and download files submitted by other users.