Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,598
Total alertas
3086
Críticas
10240
Altas
8
Ransomware
1806
Esta semana
RSS
M Alto vulnerabilidad
04/08/2026
[CVE-2026-69100] LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execu…
LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database template fields without compilation restrictions or whitelisting. Attackers can write or influence the script field via message template endpoints to execute arbitrary Groovy code and OS commands on the backend …
M Crítico vulnerabilidad
04/08/2026
[CVE-2026-69110] OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthentic…
OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by directly accessing the GET /api/tmp/:tmpFile and GET /api/music/:fileName endpoints. Attackers can retrieve intermediate audio, video artifacts, and subtitles belonging to other users' jobs, and additionall…
M Alto vulnerabilidad
04/08/2026
[CVE-2026-25292] Memory Corruption when processing untrusted user input in the fastboot command handler for audio fra…
Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.
M Alto vulnerabilidad
04/08/2026
[CVE-2026-24083] Memory Corruption while processing IOCTL device driver requests with invalid arguments.
Memory Corruption while processing IOCTL device driver requests with invalid arguments.
M Alto vulnerabilidad
04/08/2026
[CVE-2026-24084] Weak configuration when UE does not verify the consistency of its additional security capabilities w…
Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.
M Alto vulnerabilidad
04/08/2026
[CVE-2026-25288] Transient DOS when processing a short target wake time channel usage response frame with insufficien…
Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.
M Crítico vulnerabilidad
04/08/2026
[CVE-2026-25289] Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Disco…
Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
04/08/2026
[CVE-2026-24079] Cryptographic Issue while processing registration requests with malformed or missing authentication …
Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.
M Alto vulnerabilidad
04/08/2026
[CVE-2026-24080] Memory Corruption when handling malformed request parameters in the fingerprint TA.
Memory Corruption when handling malformed request parameters in the fingerprint TA.
M Alto vulnerabilidad
04/08/2026
[CVE-2026-21366] Memory corruption while processing a packet with a size close to the maximum allowed value.
Memory corruption while processing a packet with a size close to the maximum allowed value.
M Alto vulnerabilidad
04/08/2026
[CVE-2026-67195] Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attacke…
Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary operating system commands by submitting crafted expression strings to the PolarsVirtualServer backend, which passes client-supplied input directly to Python's eval() with only __builtins__={} cleared. Attackers can exploit Python object attribute traversal through the interpr…
M Alto vulnerabilidad
04/08/2026
[CVE-2026-67198] Perspective 5.0.0 contains a denial-of-service vulnerability in the VirtualServer protocol dispatche…
Perspective 5.0.0 contains a denial-of-service vulnerability in the VirtualServer protocol dispatcher that allows unauthenticated remote attackers to crash the server process by sending malformed or incomplete protobuf messages. Attackers can send well-formed requests such as ViewToArrowReq with no viewport set or MakeTableReq with no data field to trigger unwrap() calls on None values at nine dis…
M Alto vulnerabilidad
04/08/2026
[CVE-2026-67200] Perspective 5.0.0 contains a path traversal vulnerability that allows unauthenticated remote attacke…
Perspective 5.0.0 contains a path traversal vulnerability that allows unauthenticated remote attackers to read arbitrary files from the server filesystem by including literal ../ segments in HTTP request URL paths. Attackers can bypass the insufficient query-string-stripping sanitization to traverse outside the configured asset root directory and retrieve sensitive files such as system credentials…
M Crítico vulnerabilidad
04/08/2026
[CVE-2026-61514] Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability t…
Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthenticated attackers to access device functions by sending protocol-conforming packets over TCP port 23456 without credentials. Attackers can exploit the unvalidated Session field in the proprietary control protocol header to access live video streams, control pan and tilt motors, ac…
M Crítico vulnerabilidad
04/08/2026
[CVE-2026-61515] Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vul…
Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by sending a crafted JSON payload to the DebugShell interface exposed on TCP port 34567. Attackers can exploit the lack of authentication and input sanitization in the binary protocol service to pass arbitrary com…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
04/08/2026
[CVE-2026-18770] A vulnerability has been found in vibesurf-ai VibeSurf up to cd6e519d507cdd4d63061300bf60fb176e1f57e…
A vulnerability has been found in vibesurf-ai VibeSurf up to cd6e519d507cdd4d63061300bf60fb176e1f57e0. Impacted is an unknown function of the file /code of the component Python Validation Handler. The manipulation leads to code injection. Remote exploitation of the attack is possible. This product follows a rolling release approach for continuous delivery, so version details for affected or update…
M Alto vulnerabilidad
04/08/2026
[CVE-2026-18650] Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Privilege Escalation. This is…
Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Privilege Escalation. This issue affects Liman MYS: from 2.2.3 before 2.3.1.
M Alto vulnerabilidad
04/08/2026
[CVE-2026-11368] The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer w…
The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning channel via the static tx_meta_data_storage[] array (data->att_chan = chan). When a buffer's last reference is dropped, its net-buf destroy callback defers the completion handling to the system workqueue (att_tx_destroy -> att_tx_destroy_work_handler -> att_on_sent_cb -> bt_att_sent),…
M Alto vulnerabilidad
04/08/2026
[CVE-2026-17070] Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Pr…
Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Liman MYS: from 2.2.3 before 2.3.1.
M Alto vulnerabilidad
04/08/2026
[CVE-2026-18806] External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research…
External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-image-writer allows Removing Important Client Functionality. This issue affects pardus-image-writer: before 1.0.4.