Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1012
Esta semana
RSS
M Alto vulnerabilidad
16/09/2026
[CVE-2026-61591] djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered pe…
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, for views that opt into state snapshots, the snapshot `state_json` embedded in the client page was restored on reconnect as trusted view state with no integrity check. A client could edit the unsigned `state_json` in their page and return it in the reconnect mount …
M Alto vulnerabilidad
16/09/2026
[CVE-2026-63127] RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's OAuth …
RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's OAuth implementation in crates/rmcp/src/transport/auth.rs omits the RFC 9728 resource field from ResourceServerMetadata and allows discover_oauth_server_via_resource_metadata to use protected-resource metadata without confirming that the returned resource identifier exactly matches the configured MCP serv…
M Alto vulnerabilidad
16/09/2026
Vulnerabilidad alta en Arista EOS con OSPFv2 permite denegación de servicio en redes
Arista EOS es vulnerable a packets OSPFv2 especialmente diseñados que pueden ser enviados por atacantes no autenticados en el mismo segmento de broadcast. La vulnerabilidad provoca inestabilidad en adyacencias OSPF y pérdida de paquetes, disrumpiendo el enrutamiento en dominios OSPF amplios. En infraestructuras altas de LATAM (telecomunicaciones, finanzas, energía) esto compromete la disponibilidad de servicios de red.
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-73437] On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay confi…
On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay configured, an unauthenticated attacker with network access could send a crafted DHCP reply packet from an IP address that is not configured as a helper address, and the relay agent would forward it to clients without validating the source. This could allow the attacker to supply clients with malicious n…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-54167] Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositor…
Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, the GitHub App provider accepts X-GitHub-Enterprise-Host as the API host while processing webhook events containing an installation.id, before webhook signature validation or confirmation that the host matches the repository URL in the signed payload…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-57122] PraisonAI is a multi-agent teams system. Prior to 4.6.59, the WhatsApp and Linear bot webhook handle…
PraisonAI is a multi-agent teams system. Prior to 4.6.59, the WhatsApp and Linear bot webhook handlers verify HMAC signatures only when WHATSAPP_APP_SECRET or LINEAR_WEBHOOK_SECRET is configured and otherwise parse and dispatch unsigned request bodies. A remote unauthenticated client that reaches the webhook route can forge messages, comments, or agent-session events, impersonate platform users, i…
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad en Melange y Apko permite instalar paquetes APK maliciosos sin validación
Melange versiones anteriores a 0.50.4 y Apko anteriores a 1.2.9 no verifican la integridad de los archivos de datos en paquetes APK durante la instalación, solo validan metadatos. Un atacante que controle un espejo, envenenene un caché o realice ataques MITM puede distribuir paquetes comprometidos que se instalarán sin detección. Afecta infraestructuras que utilizan estos gestores de compilación en entornos Linux containerizados.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
09/09/2026
Vulnerabilidad crítica en Dell SCG 5.0 permite acceso no autorizado sin autenticación
Dell SCG 5.0 (versiones Appliance anteriores a 5.36.00.16 y Application anteriores a 5.36.00.00) contiene una falla de verificación de autenticidad de datos que permite a atacantes remotos no autenticados reutilizar solicitudes capturadas para obtener acceso no autorizado. Con CVSS 9.8, afecta directamente infraestructuras críticas en sector financiero, gubernamental y retail en México y Latinoamérica que ejecuten estas versiones.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-73316] XenForo before 2.3.13 contains a payment replay vulnerability in the PayPal REST payment provider th…
XenForo before 2.3.13 contains a payment replay vulnerability in the PayPal REST payment provider that allows attackers to process the same webhook payload multiple times by exploiting a missing duplicate transaction ID check. Attackers can replay a valid webhook payload to trigger duplicate payment events, resulting in repeated subscription activations and unauthorized account upgrades.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85430] MOOS essential-moos through 10.0.1 contains an authentication bypass vulnerability in pShare that ac…
MOOS essential-moos through 10.0.1 contains an authentication bypass vulnerability in pShare that accepts UDP datagrams from any source and republishes them with the attacker-claimed identity intact. Attackers can send crafted UDP datagrams to pShare input routes to inject messages into the local MOOS community under spoofed identities, or send malformed datagrams to crash the pShare process.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85431] MOOS essential-moos through version 10.0.1 contains an unauthenticated UDP packet injection vulnerab…
MOOS essential-moos through version 10.0.1 contains an unauthenticated UDP packet injection vulnerability in pMOOSBridge when configured with UDPListen. Attackers can send crafted UDP packets to the configured port to inject arbitrary variables into the local MOOS community with spoofed source and community identifiers.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85434] MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbo…
MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbound bridge routes. Attackers can publish NODE_BROKER_PING messages with crafted HostRecord data to redirect bridged variables to attacker-controlled addresses.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85435] MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the source of TRY_SHORE_HOST messages on th…
MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the source of TRY_SHORE_HOST messages on the vehicle bus, allowing any publisher to enroll attacker-controlled shore routes. Attackers can publish malicious shore route messages to receive bridged vehicle traffic including sensor data and control information.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85429] MOOS-IvP uFldNodeComms through 24.8.1 trusts the source node identity from the message body rather t…
MOOS-IvP uFldNodeComms through 24.8.1 trusts the source node identity from the message body rather than validating it from the connection source. Attackers can craft NODE_MESSAGE packets with spoofed source identities to impersonate other nodes and post arbitrary variable notifications without validation.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-53728] Medplum is a developer platform that enables development of healthcare apps. Prior to version 5.1.6,…
Medplum is a developer platform that enables development of healthcare apps. Prior to version 5.1.6, the external identity provider callback at GET /auth/external accepts attacker-controlled redirect URIs that only need to start with a registered client redirect URI, rather than matching exactly. After a successful external IdP login, the server appends Medplum login and code values to that attack…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
02/09/2026
Vulnerabilidad en AGESA™ permite actualización no autorizada de ROM y escalada de privilegios
Una verificación insuficiente de autenticidad en AGESA™ (firmware de procesadores AMD) permite a atacantes modificar datos de SPI ROM, comprometiendo la integridad del sistema. La vulnerabilidad afecta servidores y estaciones de trabajo en centros de datos de LATAM, con riesgo de denegación de servicio o ejecución de código con privilegios elevados.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-19219] In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog …
In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog request parameters used by the RadEditor file browser may allow an attacker who has obtained certain application encryption key material to alter the folders the file browser reads from, writes to, and uploads into, potentially resulting in remote code execution.
M Crítico vulnerabilidad
31/08/2026
Vulnerabilidad crítica en @hulumi/drift permite ejecución de planes maliciosos sin validación
Las versiones de @hulumi/drift anteriores a 1.3.2 aceptan planes de ejecución externos sin validar su procedencia, permitiendo que entrada de reconciliación no confiable sea tratada como confiable. Atacantes pueden inyectar planes maliciosos que eludan controles de seguridad para ejecutar operaciones de reconciliación no autorizadas, afectando sistemas de procesamiento de datos en empresas de México y LATAM con puntuación CVSS 9.8.
M Alto vulnerabilidad
30/08/2026
[CVE-2026-82549] A vulnerability was identified in Linux Foundation Magma 1.9.0. This affects an unknown function of …
A vulnerability was identified in Linux Foundation Magma 1.9.0. This affects an unknown function of the component SecurityModeComplete Handler. Such manipulation leads to improper validation of integrity check value. The attack may be launched remotely. The exploit is publicly available and might be used.
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad alta en IGEL OS 11 y 12: inyección de parámetros de arranque
IGEL OS versiones anteriores a 12.7.6 y 11.11.150 contienen una vulnerabilidad de inyección de parámetros de arranque (CVSS 7.6) que permite a atacantes con acceso físico ejecutar parámetros arbitrarios del cargador Linux. La falla radica en un área de configuración sin encripción ni firma que es leída por el cargador de arranque, permitiendo la inyección de comandos de kernel maliciosos con privilegios de entorno de arranque. Afecta principalmente entornos de terminales sin cliente en bancos, retail y centros de datos en LATAM.