Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,696
Total alertas
3097
Críticas
10327
Altas
8
Ransomware
1772
Esta semana
RSS
M Alto vulnerabilidad
07/08/2026
[CVE-2026-68772] ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component…
ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attackers with write access to a shared artifact store to execute arbitrary code by planting a malicious pickle file. Attackers can replace a stored artifact.pkl file with a crafted cloudpickle payload containing a malicious __reduce__ method, which executes arbitrary system commands wh…
M Alto vulnerabilidad
07/08/2026
[CVE-2026-20345] A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attac…
A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper handling of an endian conversion operation, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerab…
M Alto vulnerabilidad
07/08/2026
[CVE-2026-20346] A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attac…
A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PDF files during scanning, which may result in an out-of-bounds buffer read. An attacker could exploit …
M Alto vulnerabilidad
07/08/2026
[CVE-2026-20347] A vulnerability in the Mach-O file format parser of ClamAV could allow an unauthenticated, remote at…
A vulnerability in the Mach-O file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in Mach-O files during scanning, which may result in an out-of-bounds buffer read. An attacker could ex…
M Alto vulnerabilidad
07/08/2026
[CVE-2026-20348] A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attac…
A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in XAR files during scanning. An attacker could exploit this vulnerability by submitting a crafted file th…
M Alto vulnerabilidad
07/08/2026
[CVE-2026-19211] A vulnerability was found in SourceCodester Photo Share Website 1.0. This affects an unknown functio…
A vulnerability was found in SourceCodester Photo Share Website 1.0. This affects an unknown function of the file /social/ajax.php?action=signup. Performing a manipulation of the argument email results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
M Alto vulnerabilidad
07/08/2026
[CVE-2026-20337] A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker …
A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper boundary checks for content in zip files during scanning, which may result in an out-of-bounds write condition. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A succe…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
07/08/2026
[CVE-2026-20338] A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker …
A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in zip files during scanning. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to …
M Alto vulnerabilidad
07/08/2026
[CVE-2026-20339] A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote at…
A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PESpin files during scanning, which may result in an integer overflow. An attacker could exploit thi…
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-19264] Postiz is an open-source social media scheduling tool. The route that serves locally stored media jo…
Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto the upload directory and streams the file without normalising the path or confining it to that directory, and the route requires no authentication. Raw dot-segments are collapsed before routing, but URL-encoded separators survive route matching and are decoded onl…
M Crítico vulnerabilidad
07/08/2026
[CVE-2022-4995] Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows…
Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthenticated attacker to upload arbitrary files, including JSP webshells, by submitting a multipart/form-data POST request to /workrelate/plan/util/uploaderOperate.jsp with arbitrary secId and plandetailid field values. Successful exploitation results in remote code execution under the…
M Alto vulnerabilidad
07/08/2026
[CVE-2026-56793] Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authenticatio…
Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
M Alto vulnerabilidad
07/08/2026
Vulnerabilidad alta en dracut permite ejecución de comandos con privilegios root
Se descubrió una falla en dracut donde la función de manejo de errores die() no realiza escape adecuado de caracteres especiales en mensajes, permitiendo inyección de comandos a través de la opción DHCP ROOT_PATH. Un atacante en la red local controlando un servidor DHCP rogue puede ejecutar comandos arbitrarios con privilegios root durante el siguiente arranque del sistema, afectando servidores de infraestructura alta en data centers de LATAM.
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-71558] Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache For…
Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer deserialization, causing an object of an incompatible type to be treated as the declared base type. This may result in undefined behavior and potentially lead to den…
M Alto vulnerabilidad
07/08/2026
[CVE-2026-71559] Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an at…
Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic. This issue affects Apache Fory: from 0.16.0 before 1.5.0.  Users of other language implementations are not affected. Users are recommended to upgrade to version 1.5.0…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-71560] Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory…
Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payload may trigger an out-of-bounds heap read in the tagged integer fast-path deserializer, potentially causing information disclosure or denial of service. Users are recommended to…
M Alto vulnerabilidad
07/08/2026
Vulnerabilidad alta de secuestro de DLL en LUCID Vision Labs Arena SDK 1.0.80.49
Una vulnerabilidad de tipo DLL Search Order Hijacking (puntuación CVSS 8.8) en Arena SDK 1.0.80.49 permite a atacantes locales ejecutar código arbitrario con los privilegios de la aplicación. El riesgo es alto en entornos de visión artificial e industria 4.0 comunes en plantas manufactureras de México y Latinoamérica, donde este SDK se integra en sistemas de inspección y control de calidad.
M Alto vulnerabilidad
07/08/2026
Exposición de credenciales en firmware de dispositivos - CVE-2026-49007 (CVSS 7.5)
Vulnerabilidad que permite a atacantes acceder a credenciales iniciales de dispositivos al leer información sin encriptar en el firmware. Afecta múltiples fabricantes y expone interfaces web administrativas. En LATAM, esta falla impacta servidores, equipos de red y sistemas embebidos en infraestructuras altas.
M Alto vulnerabilidad
07/08/2026
SQL Injection alta en SourceCodester Photo Share Website 1.0
Se identificó una vulnerabilidad de inyección SQL en SourceCodester Photo Share Website 1.0 mediante la manipulación del parámetro email en /social/ajax.php?action=login. El exploit es de acceso público y permite a atacantes remotos comprometer bases de datos de aplicaciones web en empresas mexicanas y latinoamericanas que utilizan esta plataforma. Con CVSS 7.3, representa un riesgo considerable para la confidencialidad e integridad de datos de usuarios.
M Alto vulnerabilidad
07/08/2026
[CVE-2026-16041] The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership …
The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, allowing an unauthenticated attacker to create WooCommerce product reviews with an attacker-chosen reviewer name, email and star rating on stores configured to accept reviews only from verified owners.