Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1003
Esta semana
RSS
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-75156] Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of A…
Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login. Deployments are affected only when the FAB auth manager is configured with Azure AD as an OAuth provider. Because the signing keys are fetched from Microsoft's **multi-tenant** JWKS endpoint, an `id_token` minted in *any* Azure tenant — including one the attac…
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85152] undici 8.10.0 omits the destination origin from the cache and request-deduplication keys when the ca…
undici 8.10.0 omits the destination origin from the cache and request-deduplication keys when the cache or deduplicate interceptor is composed directly onto a Client or Pool. Because the internal cache key falls back to an empty origin string, a cacheable or in-flight response from one upstream origin is returned for a request to a different, trusted origin whenever the method, path, and relevant …
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84482] WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_d…
WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_domain() and isSameDomain() functions that fail to properly validate referer origins. Attackers can forge requests from sibling subdomains or unparseable long-gTLD origins to perform administrative ObjectYPT writes including live server configuration changes.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-55532] PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, MCP HTTP Stream _validate_origin…
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, MCP HTTP Stream _validate_origin uses request_origin.startswith(allowed), allowing the attacker-controlled localhost.attacker.com HTTP origin to satisfy the localhost allowlist. A webpage can send Content-Type: text/plain requests without preflight and invoke tools/call without an API key, including file writes that persist agent …
M Alto vulnerabilidad
21/08/2026
[CVE-2026-62316] Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior t…
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, ufo/client/mcp/http_servers/linux_mcp_server.py binds a FastMCP streamable HTTP server to localhost:8010 but does not validate the Host, Origin, or Sec-Fetch-Site headers. An attacker-controlled web page can use DNS rebinding to reach the local /mcp endpoint, enumerate tool schemas through …
M Alto vulnerabilidad
17/08/2026
[CVE-2026-74802] SiYuan versions before 3.7.4 contain a cross-site WebSocket hijacking vulnerability in the admin-onl…
SiYuan versions before 3.7.4 contain a cross-site WebSocket hijacking vulnerability in the admin-only /ws/network/proxy endpoint that explicitly disables origin validation by setting CheckOrigin to unconditionally return true. Attackers can craft malicious webpages that establish WebSocket connections to this endpoint and direct the SiYuan kernel process to proxy arbitrary network traffic to attac…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-18847] IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to harvest credentials du…
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to harvest credentials due to spoofing of Navigator for i.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
12/08/2026
[CVE-2026-18098] IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive informa…
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and compromise system integrity due to an XML injection flaw.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-56179] Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker…
Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.
M Crítico vulnerabilidad
07/08/2026
Vulnerabilidad crítica en OpenYak permite ejecución de código remoto desde navegadores web
OpenYak, un runtime local para modelos de IA con herramientas integradas, presenta una vulnerabilidad crítica (CVSS 9.6) en versiones anteriores a 1.1.3. El backend del escritorio expone una API HTTP sin validación de origen, autenticación de loopback ni enforcement de Content-Type, con política CORS abierta. Cualquier página web visitada mientras OpenYak se ejecuta puede ejecutar comandos arbitrarios en el sistema local, comprometiendo completamente la máquina del usuario.
M Alto vulnerabilidad
05/08/2026
[CVE-2026-16442] A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federati…
A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a provider is restricted to account linking only. This allows an attacker with control over a linked upstream identity to bypass login restrictions and gain full access to a local user ac…
M Alto vulnerabilidad
04/08/2026
Falla de validación de origen en Microsoft Edge permite divulgación de información
Se ha identificado una vulnerabilidad alta (CVSS 8.1) en Microsoft Edge basado en Chromium que permite a atacantes no autorizados eludir validaciones de origen y acceder a información sensible a través de la red. Esta falla afecta principalmente a empresas en México y LATAM que dependen de Edge como navegador corporativo, exponiendo datos de sesiones, credenciales y comunicaciones internas.
M Alto vulnerabilidad
04/08/2026
[CVE-2026-66322] Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perfor…
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-66420] MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that al…
MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated remote attackers to hijack authenticated administrator sessions by exploiting an unconditional early return in the CheckWebServerOriginName() function within webserver.js when self-signed certificates are in use. Attackers can open cross-origin WebSocket connections to any of th…
M Alto vulnerabilidad
30/07/2026
[CVE-2026-17916] Insufficient policy enforcement in Settings in Google Chrome prior to 151.0.7922.72 allowed a remote…
Insufficient policy enforcement in Settings in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
29/07/2026
[CVE-2026-6102] MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulnerability. This vulner…
MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MSI Center. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the NTIOLib_X64.sys driver. The issue …
M Alto vulnerabilidad
28/07/2026
[CVE-2026-54605] OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.…
OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parses the raw Location header of a 300 to 399 redirect returned by the OAuth server and follows the redirect recursively, which can mutate the consumer's configuration and expose signed OAuth request metadata, including the Authorization header, to a cros…
M Alto vulnerabilidad
26/07/2026
[CVE-2026-57989] Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclo…
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
M Alto vulnerabilidad
23/07/2026
[CVE-2026-16745] A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to…
A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the Kubernetes API, potentially leading to arbitrary code execution, privilege escalation…
M Alto vulnerabilidad
22/07/2026
[CVE-2026-13321] The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outs…
The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.