Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Python" — 286 resultados ✕ Limpiar búsqueda
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1019
Esta semana
RSS
M Alto vulnerabilidad
28/09/2026
[CVE-2026-102266] PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorith…
PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.from_jwk is affected because PyJWK verification path used the decoded key without applying prepare_key validation. This occurs when a trusted JWK Set contains an oct entry with an empty k value. As a result, an attacker signs an HMAC token with the same zero-length key accepted by PyJWT. Consequen…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-102267] PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT PyJWKClient is …
PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT PyJWKClient is affected because redirect destinations are not revalidated against the JWKS trust boundary. This occurs when a configured trusted JWKS endpoint returns an attacker-influenced redirect. As a result, PyJWKClient follows the redirect and consumes the redirected response as key material. Consequently, f…
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-102268] PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, is_pem_format in jwt/…
PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, is_pem_format in jwt/utils.py is affected because is_pem_format does not recognize every PEM representation accepted by the cryptography loader. This occurs when an application mixes HMAC and asymmetric algorithms and supplies a mutated public-key PEM as raw key bytes. As a result, HMACAlgorithm.prepare_key treats the u…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-93348] Unsloth Zoo versions 2025.9.9 before 2026.8.14, as implemented in Unsloth 2025.9.9 through 2026.8.19…
Unsloth Zoo versions 2025.9.9 before 2026.8.14, as implemented in Unsloth 2025.9.9 through 2026.8.19, contains a code injection vulnerability in the model-loading compile path where the get_transformers_model_type() function in hf_utils.py collects model_type values from nested model configurations without enforcing a character allowlist, allowing newlines and arbitrary Python source to survive no…
M Alto vulnerabilidad
27/09/2026
[CVE-2026-101060] python-utcp versions before 1.1.4 contain a server-side request forgery vulnerability in HttpCommuni…
python-utcp versions before 1.1.4 contain a server-side request forgery vulnerability in HttpCommunicationProtocol.call_tool that validates the initial tool URL but follows HTTP redirects without re-validating the target. Attackers controlling a tool endpoint can return a 302 redirect to internal services, allowing the UTCP client to reach cloud metadata endpoints or internal HTTP services and ret…
M Alto vulnerabilidad
27/09/2026
Vulnerabilidad alta de escape de sandbox en heym anterior a 0.0.91
heym versiones anteriores a 0.0.91 contienen una vulnerabilidad de escape de sandbox en el motor de expresiones que permite a usuarios autenticados ejecutar código Python arbitrario. Los atacantes pueden manipular expresiones de flujo de trabajo para acceder a funciones del sistema operativo y ejecutar comandos con los permisos del proceso backend, comprometiendo completamente servidores y sistemas de automatización en entornos empresariales.
M Alto vulnerabilidad
27/09/2026
Vulnerabilidades altas en Heym anterior a 0.0.53 permiten ejecución arbitraria de código
Heym versiones anteriores a 0.0.53 contienen múltiples vulnerabilidades altas (CVSS 8.8). La más grave permite ejecución arbitraria de código Python mediante eval() sin sandbox en nodos de condición de flujos de trabajo. Cualquier usuario con permisos de edición de flujos o importación de plantillas maliciosas puede ejecutar código con privilegios del proceso backend. Afecta significativamente a empresas en LATAM que utilizan esta herramienta en automatización de procesos altas.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
27/09/2026
Vulnerabilidad alta de ejecución remota de código en MONAI hasta versión 1.6.0
MONAI versiones 1.6.0 y anteriores contienen una vulnerabilidad de ejecución remota de código (RCE) en el motor de configuración de bundles que permite a atacantes ejecutar código arbitrario sin validación de lista permitida. Los agresores pueden distribuir bundles maliciosos con configuraciones manipuladas que se ejecutan cuando usuarios cargan bundles mediante monai.bundle.load(), afectando laboratorios de investigación médica y centros de datos en LATAM que implementan pipelines de procesamiento de imágenes médicas.
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100570] OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 allow an untrusted workspace …
OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 allow an untrusted workspace .env file to set the CLOUDSDK_PYTHON_ARGS environment variable. When an operator starts OpenClaw in attacker-controlled workspace content and then runs the Gmail setup flow, that value is inherited when gcloud is launched, and the gcloud launcher passes it as arguments to the trusted Python interpre…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-96795] Horilla is an HR and CRM software. Prior to 2.0.0, HorillaListView.export_data in horilla_views/gene…
Horilla is an HR and CRM software. Prior to 2.0.0, HorillaListView.export_data in horilla_views/generic/cbv/views.py accepts an authenticated user's columns POST parameter, takes field_tuple[1], interpolates it into dynamic_fn_str as Python source, and passes the generated function definition to exec(). A crafted string that remains valid under ast.literal_eval can inject Python syntax into a defa…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-96749] An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled n…
An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may occur when a single document is built from an unusually large amount of caller-supplied data. Size arithmetic is performed in a signed 32-bit type, and the guard meant to catch the overflow is written in a form whose behavior is not defined by the C language standard. A party wit…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-57178] Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the `v…
Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the `vk-app` backend accepted VK application callback data without verifying the callback signature when the `auth_key` parameter was omitted. Applications using this backend could treat unsigned attacker-controlled data as a verified VK identity. An attacker could choose callback fields such as `viewer_i…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-90959] A path traversal vulnerability was found in pulpcore. The content upload API accepts a 'file_url' pa…
A path traversal vulnerability was found in pulpcore. The content upload API accepts a 'file_url' parameter that allows users with file repository privileges to specify a local file URL for Pulp to download and store. A URL scheme validation check uses a string prefix comparison that only rejects URLs beginning with 'file://', but Python's URL parser recognizes the 'file:' scheme without double sl…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-84691] A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The setting that f…
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The setting that formats the log message emitted for API 4XX errors is an administrator-controlled Python format-string template that is rendered with a live user object as an argument. Because Python string formatting permits attribute and item traversal on its arguments, an administrator can craft a template that w…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-84706] A flaw was found in Ansible Automation Platform's automation-controller. The custom Credential Type …
A flaw was found in Ansible Automation Platform's automation-controller. The custom Credential Type environment-variable injector validates variable names against a deny-list (an ANSIBLE_* prefix check plus a fixed ENV_BLOCKLIST) that omits process-hijacking loader variables such as BASH_ENV, ENV, LD_PRELOAD, LD_LIBRARY_PATH, PYTHONSTARTUP and GIT_SSH_COMMAND. Combined with the credential file inj…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
23/09/2026
[CVE-2026-82331] Improper link resolution before file access ('link following') vulnerability in the `tar` source plu…
Improper link resolution before file access ('link following') vulnerability in the `tar` source plugin of Apache BuildStream running on Python < 3.12 allows malicious source tarballs to write files on the host, with the privileges of the user running BuildStream, via symlinks as part of source fetching. The impact of this issue is mitigated by: * BuildStream projects should only use trusted sour…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-59991] psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to 1.17.4, PSDImage.…
psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to 1.17.4, PSDImage.composite() and PSDImage.numpy() allocated output buffers from attacker-controlled PSD header geometry, including width, height, channels, depth, and per-layer rectangles, before validating those values against the available file data. A tiny crafted PSD could therefore cause multi-gigabyte memory a…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-95831] Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Pyth…
Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL. The generate_certificate runs a Python script saved as a certificate file. The pyhton script attempts to retrieve code from a hardcoded http URL that is obfuscated with base64 encoding and run the response body directly. The impact is that arbitrary code can be inv…
M Alto vulnerabilidad
21/09/2026
[CVE-2026-53940] Conda is a system-level binary package and environment manager that runs on major operating systems …
Conda is a system-level binary package and environment manager that runs on major operating systems and platforms. Prior to 26.5.2, parse_entry_point_def in conda/common/path/python.py accepted an unvalidated entry-point command from a noarch:python package's info/link.json metadata. CreatePythonEntryPointAction in conda/core/path_actions.py interpolated that command into target_short_path, and Pr…
M Alto vulnerabilidad
21/09/2026
[CVE-2026-55071] MCP-for-Stata is a MCP server for integrating Stata into agent loops with a safety-first design. Pri…
MCP-for-Stata is a MCP server for integrating Stata into agent loops with a safety-first design. Prior to version 1.19.0, the ado_package_install MCP tool in stata-mcp concatenates user-controlled input directly into a Stata command string without any validation or sanitization. An attacker who can invoke the MCP tool or the equivalent Python API can embed newline characters in the package argumen…