Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
Buscando: "Perl" — 486 resultados ✕ Limpiar búsqueda
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1002
Esta semana
RSS
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102143] An unauthenticated attacker could cause a file with attacker-controlled content to be written to the…
An unauthenticated attacker could cause a file with attacker-controlled content to be written to the appliance filesystem through an administrative upload handler that did not properly authenticate the request. This did not by itself result in code execution, which would require a separate vulnerability to place the file in an executable location.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-47600] NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer wh…
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an error-handling path could operate on an improperly initialized resource. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-103398] OpenSave through 2.4.0 fails to properly validate save paths supplied by paired peers in the manifes…
OpenSave through 2.4.0 fails to properly validate save paths supplied by paired peers in the manifest request handler. Attackers can specify arbitrary directories outside configured save locations to read and write files through manifest and sync routes.
M Alto vulnerabilidad
30/09/2026
Vulnerabilidad de sincronización en funcionalidad de monitoreo permite denegación de servicio (CVE-2026-79625)
Múltiples productos presentan fallo en la sincronización de acceso a funcionalidad de monitoreo. Solicitudes concurrentes de clientes pueden causar lecturas/escrituras incorrectas o corrupción de estructuras de memoria internas. Un atacante autenticado con acceso de monitoreo puede explotar esto para procesamiento de datos incorrecto o denegación de servicio (CVSS 8.1).
M Alto vulnerabilidad
29/09/2026
[CVE-2026-96274] In Baicells Nova 430H, an unauthenticated device within radio range can send a malformed uplink mess…
In Baicells Nova 430H, an unauthenticated device within radio range can send a malformed uplink message during connection setup that contains an invalid NAS payload. Because the eNodeB does not properly validate this payload, it forwards the message to the core network, which can trigger a shutdown of the signaling association for the cell. This results in a temporary service disruption until the …
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102697] Ollama versions 0.14.0 before 0.31.2 contain an incorrect authorization vulnerability in the experim…
Ollama versions 0.14.0 before 0.31.2 contain an incorrect authorization vulnerability in the experimental agent mode Bash tool approval mechanism that fails to properly parse shell syntax. Attackers who can influence model output through prompt injection can execute additional shell commands by appending control operators like semicolons or logical operators to approved commands, bypassing the ses…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-86450] Insertion of sensitive information into sent data vulnerability in Parla Auto Automotive Trading Lim…
Insertion of sensitive information into sent data vulnerability in Parla Auto Automotive Trading Limited Company DetaWix Mobile Web Portal allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects DetaWix Mobile Web Portal: before v1.0.19.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
28/09/2026
[CVE-2026-101091] SiYuan versions before v3.8.4 fail to properly validate SQL statements in block query embed blocks e…
SiYuan versions before v3.8.4 fail to properly validate SQL statements in block query embed blocks executed against siyuan.db. Attackers can craft malicious .sy documents with non-read-only SQL statements that execute automatically during background indexing, rendering, or export operations without authentication.
M Alto vulnerabilidad
28/09/2026
Vulnerabilidad alta en productos Wi-Fi BUFFALO permite ejecución remota de comandos
BUFFALO Wi-Fi products procesa incorrectamente entradas en formularios web para construir cadenas de comandos del sistema operativo, permitiendo a usuarios administrativos ejecutar comandos OS arbitrarios mediante solicitudes HTTP maliciosamente elaboradas. Afecta principalmente a infraestructuras de conectividad en pequeñas y medianas empresas (PYMES) de México y Latinoamérica que utilizan equipos BUFFALO para redes corporativas.
M Alto vulnerabilidad
27/09/2026
[CVE-2026-101032] navi through 2.24.0 fails to properly escape cheatsheet variable values when substituting them into …
navi through 2.24.0 fails to properly escape cheatsheet variable values when substituting them into shell commands. Attackers can inject shell metacharacters through crafted file names in suggestion command directories to execute arbitrary commands with victim privileges.
M Crítico vulnerabilidad
26/09/2026
[CVE-2026-100706] kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Policy apiCall urlPath…
kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Policy apiCall urlPath, allowing namespace tenants to bypass the per-namespace clamp and create objects in other namespaces as the admission-controller ServiceAccount. Attackers can exploit this by using percent-encoded directory traversal sequences to create MutatingWebhookConfiguration objects cluster-wide or PolicyExc…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100685] Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint by workspace, allowi…
Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint by workspace, allowing builders to enumerate chat identity link records across all workspaces in a tenant. Attackers with builder access to a single workspace can retrieve sensitive chat identity linking data including user IDs and external chat service identifiers from other workspaces they have no permission to acces…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100676] January, the media proxy/embed service of stoatchat (stoatchat/stoatchat), before version 0.15.5 imp…
January, the media proxy/embed service of stoatchat (stoatchat/stoatchat), before version 0.15.5 improperly resolves SVG values as local filesystem paths when a fetched resource is served as image/svg+xml. An unauthenticated remote attacker who causes the service to proxy an attacker-hosted SVG (e.g. via the /proxy endpoint) can determine whether local files exist through observable r…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100643] SiYuan versions before v3.8.4 fail to properly escape four stored Attribute View values in textarea …
SiYuan versions before v3.8.4 fail to properly escape four stored Attribute View values in textarea elements, allowing authenticated attackers to inject JavaScript by modifying field descriptions, template sources, select option descriptions, or footer calculation templates. Attackers can execute stored JavaScript when other users open affected database menus, and in the Electron desktop app with …
M Alto vulnerabilidad
26/09/2026
Vulnerabilidad alta de autorización en OpenClaw anterior a 2026.7.1
OpenClaw versiones anteriores a 2026.7.1 presentan un fallo de autorización que permite a usuarios no-propietarios ejecutar cambios de configuración MCP mediante los comandos /mcp set y /mcp unset. Los atacantes pueden persistir comandos MCP arbitrarios en stdio que se ejecutan con los privilegios del proceso OpenClaw, comprometiendo la confidencialidad, integridad y disponibilidad del host. Este riesgo afecta principalmente a empresas en LATAM que utilizan OpenClaw en entornos de producción sin restricciones de acceso adecuadas.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
26/09/2026
Vulnerabilidad alta en OpenClaw Codex permite ejecución remota de código sin autorización
OpenClaw Codex anterior a versión 2026.7.1 presenta falla en validación de autorización que permite a usuarios no propietarios con acceso a comandos crear enlaces nativos y ejecutar operaciones con acceso a archivos, herramientas y procesos del sistema. Afecta principalmente a empresas que utilizan esta plataforma para orquestación de infraestructura en entornos cloud de LATAM.
M Alto vulnerabilidad
26/09/2026
Vulnerabilidad alta en OpenClaw anterior a 2026.7.1 permite ejecución de código arbitrario
OpenClaw versiones anteriores a 2026.7.1 presentan un defecto de validación de autorización en el comando de instalación Codex que permite a usuarios sin permisos instalar plugins arbitrarios y ejecutar procesos MCP con privilegios de OpenClaw. Esta vulnerabilidad compromete confidencialidad, integridad y disponibilidad de sistemas host, afectando servidores en entornos empresariales de México y Latinoamérica que utilicen esta plataforma.
M Alto vulnerabilidad
26/09/2026
Vulnerabilidad alta en OpenClaw Slack 2026.8.0 y anteriores permite bypass de políticas de remitentes
OpenClaw Slack versiones anteriores a 2026.8.1 no validan correctamente las listas de remitentes autorizados en mensajes directos grupales, permitiendo a participantes no autorizados activar agentes de Slack y acceder a herramientas y datos. Esta falla de control de acceso afecta principalmente a organizaciones en LATAM que utilizan automatización de Slack para gestionar datos sensibles, cumplimiento normativo y comunicaciones altas.
M Alto vulnerabilidad
26/09/2026
Vulnerabilidad alta en paquete npm OpenClaw permite ejecución de comandos arbitrarios
OpenClaw (paquete npm 'openclaw') versiones anteriores a 2026.7.1 presenta una falla en la validación de mayúsculas y minúsculas que permite a actores maliciosos eludir controles de seguridad y crear trabajos cron persistentes. Un agente con capacidad de herramientas puede ser manipulado para ejecutar comandos arbitrarios con los privilegios del proceso OpenClaw, comprometiendo servidores de aplicaciones altas en entornos empresariales de LATAM.
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100568] OpenClaw versions before 2026.8.1 fail to properly restrict access to operator command cron jobs, al…
OpenClaw versions before 2026.8.1 fail to properly restrict access to operator command cron jobs, allowing model-visible agent callers to read and execute ownerless command jobs. Attackers can inspect stored environment variables and force-run disabled or unscheduled command jobs to access secrets and execute operator-authored commands.