Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,337
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1207
Esta semana
RSS
M Alto vulnerabilidad
15/09/2026
[CVE-2026-89022] BookStack before 26.05.5 contains an authentication bypass vulnerability in its social login impleme…
BookStack before 26.05.5 contains an authentication bypass vulnerability in its social login implementation that allows unauthenticated attackers to sign in as arbitrary users by authenticating through a different social provider sharing the same driver_id namespace. Attackers can authenticate at one enabled social provider using a user ID that matches an account linked to a different social provi…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-58200] Payload Plugins is a collection of plugins designed to enhance Payload CMS. From 0.3.0 until 0.4.0, …
Payload Plugins is a collection of plugins designed to enhance Payload CMS. From 0.3.0 until 0.4.0, @jhb.software/payload-cloudinary-plugin deployments with clientUploads enabled expose POST /api/cloudinary-generate-signature, whose handler in cloudinary/src/getGenerateSignature.ts passes attacker-controlled body.paramsToSign directly to cloudinary.utils.api_sign_request without a key allowlist, c…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-59160] Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-gra…
Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-graph package starts its embedded Next.js server from packages/turbo-graph/src/index.ts on all interfaces, including 0.0.0.0:29312 by default, while the GET handler for /api/run in packages/turbo-graph-ui/app/api/run/route.ts has no authentication, authorization, CSRF protection, or task allowlist. The…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-63443] Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29…
Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29.19, 2.32.9, 2.33.10, and 2.34.4, agentConn.apiClient() follows redirects while its custom transport accepts the host from the redirected request URL when the port is the workspace agent HTTP API port 4. An authenticated user who controls a modified workspace agent and knows another online agent's U…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-55690] The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and variou…
The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, EmbedServiceFactory::newFromName in includes/EmbedService/EmbedServiceFactory.php interpolates an attacker-controlled unknown service name into exception text, and includes/EmbedVideo.php returns that text a…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-55691] The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and variou…
The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, EmbedHtmlFormatter::toHtml in includes/EmbedService/EmbedHtmlFormatter.php passes the user-supplied class value directly to sprintf while constructing a figure element. A quote in the class value can termina…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-55692] The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and variou…
The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, with the default $wgEmbedVideoRequireConsent configuration enabled, includes/EmbedService/EmbedHtmlFormatter.php places JSON returned through includes/EmbedService/AbstractEmbedService.php into the data-mw-i…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
15/09/2026
[CVE-2026-55149] Vouch Proxy is an SSO and OAuth/OIDC login solution for Nginx using the auth_request module. Prior t…
Vouch Proxy is an SSO and OAuth/OIDC login solution for Nginx using the auth_request module. Prior to 0.48.0, Cookie in pkg/cookie/cookie.go parses the total part count from an attacker-controlled multipart cookie name and passes the value to make([]string, numParts) without checking that the value is positive or reasonably bounded. Requests to /validate and /_external-auth-:id reach JWTCacheHandl…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-19780] Koha Eval Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attac…
Koha Eval Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Koha. Authentication is required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 8081 by default. The issue results from the lack of proper validation of a user-supplied string befo…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91989] atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP serve…
atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remote attackers to read arbitrary files by supplying directory traversal sequences in request paths. Attackers can bypass path containment checks by including '../' segments in requests to the DashboardHandler.do_GET endpoint to access files outside the intended agents_root directory.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91990] Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that…
Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limit. Attackers can send crafted multipart requests with many parts to create large transient lists, exhausting server memory and causing denial of service.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91985] Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share …
Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, allowing read-only members to obtain the share's secret credential. Attackers can exchange the disclosed hash for a link-share JWT at the share's permission level to escalate privileges and perform unauthorized writes or administrative actions.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91988] atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry back…
atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowing network man-in-the-middle attackers to rewrite catalog responses. Attackers can inject arbitrary command and argument values that are spawned as local subprocesses by MCPClientPool to achieve code execution on the agent host.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91972] Vikunja versions before 2.6.0 fail to apply rate limiting to /api/v2 public authentication endpoints…
Vikunja versions before 2.6.0 fail to apply rate limiting to /api/v2 public authentication endpoints including login, register, password-reset, and OAuth token routes. Remote unauthenticated attackers can perform unbounded credential guessing, account enumeration, and password-reset flooding attacks without throttling restrictions.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91973] Vikunja before 2.6.0 contains an authentication bypass vulnerability in CalDAV BasicAuth endpoints t…
Vikunja before 2.6.0 contains an authentication bypass vulnerability in CalDAV BasicAuth endpoints that lack rate limiting protection. Remote unauthenticated attackers can issue unbounded credential-guessing requests against /dav, /.well-known, and /feeds routes to bypass the instance's anti-brute-force controls and compromise password-only accounts.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91964] FreeRDP versions before 3.31.0 contain a heap-based buffer overflow in nego_send_negotiation_request…
FreeRDP versions before 3.31.0 contain a heap-based buffer overflow in nego_send_negotiation_request when processing Server Redirection PDU messages with attacker-controlled LoadBalanceInfo fields. A malicious RDP server can trigger the overflow by sending an arbitrary-length field that gets written to a fixed 512-byte buffer without validation, causing client crashes or potential code execution w…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91965] WWBN AVideo through 29.0 fails to enforce user-group restrictions in the plugin/Live/stats.json.php …
WWBN AVideo through 29.0 fails to enforce user-group restrictions in the plugin/Live/stats.json.php and plugin/Live/calendar.json.php endpoints. Unauthenticated attackers can retrieve restricted live transmission details including stream keys, titles, descriptions, owner information, and direct HLS playback URLs by accessing these endpoints.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91955] FreeRDP before 3.31.0 fails to validate client-supplied DesktopWidth and DesktopHeight values during…
FreeRDP before 3.31.0 fails to validate client-supplied DesktopWidth and DesktopHeight values during GCC negotiation, allowing remote attackers to crash the server. Attackers can send crafted RDP packets with zero or oversized dimensions to trigger division-by-zero or assertion failures in multifragment update capability calculations, terminating the server process.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91947] FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser t…
FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a channel pointer after releasing the synchronization lock. Authenticated clients can race AUDIN channel closure messages against DRDYNVC data parsing to trigger heap-use-after-free when accessing freed channel objects.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91948] FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static vi…
FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handling when CHANNEL_OPTION_SHOW_PROTOCOL is enabled. Authenticated clients can queue oversized channel messages that cause buffer underflow and corrupt heap memory including live pointers, potentially enabling code execution.