Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1002
Esta semana
RSS
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-102268] PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, is_pem_format in jwt/…
PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, is_pem_format in jwt/utils.py is affected because is_pem_format does not recognize every PEM representation accepted by the cryptography loader. This occurs when an application mixes HMAC and asymmetric algorithms and supplies a mutated public-key PEM as raw key bytes. As a result, HMACAlgorithm.prepare_key treats the u…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-97731] MinIO through 7aac2a2 does not verify that every x-amz-* header present on a request also appears in…
MinIO through 7aac2a2 does not verify that every x-amz-* header present on a request also appears in the client-supplied X-Amz-SignedHeaders list. extractSignedHeaders() in cmd/signature-v4-utils.go iterates only the claimed list and never enumerates the headers that actually arrived, and thus a header that arrives unsigned is neither hashed into the canonical request nor rejected. Because cmd/api…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-57178] Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the `v…
Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the `vk-app` backend accepted VK application callback data without verifying the callback signature when the `auth_key` parameter was omitted. Applications using this backend could treat unsigned attacker-controlled data as a verified VK identity. An attacker could choose callback fields such as `viewer_i…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-18152] IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to forge …
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to forge validly-signed messages due to improper verification of cryptographic signatures.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-85995] Notepad++ is a free and open-source source code editor. From 8.9.7 until 8.9.8, the Notepad++ update…
Notepad++ is a free and open-source source code editor. From 8.9.7 until 8.9.8, the Notepad++ updater and signature verification path can accept a modified GUP.exe file whose embedded certificate metadata remains present even though its Authenticode digest is invalid. An attacker who can replace or plant the updater-related file can cause Notepad++ to launch attacker-modified code when a user trig…
M Alto vulnerabilidad
21/09/2026
[CVE-2026-75939] A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy) rel…
A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy) release image signatures by checking for signature errors before the entire signed body is processed, leading to a bypass of the signature verification. A remote attacker, by intercepting or manipulating network traffic to the signature endpoint, could exploit this to craft a PGP message with a valid R…
M Alto vulnerabilidad
21/09/2026
Vulnerabilidad en verificación de firma de NooBaa-Core permite bypass de autenticación S3
Se identificó un defecto en la lógica de validación de firmas de noobaa-core que afecta la puerta de enlace multicloud de NooBaa. El servicio no rechaza correctamente solicitudes S3 con presigned URLs que contienen headers x-amz- sin firmar, permitiendo a atacantes eludir mecanismos de autenticación Signature Version 4 (SigV4). Empresas en LATAM que usan NooBaa para gestión de almacenamiento multicloud están en riesgo de acceso no autorizado a datos sensibles.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-59163] Mnemosyne is a memory layer for artificial intelligence agents. Prior to v3.10.1, the auth check in …
Mnemosyne is a memory layer for artificial intelligence agents. Prior to v3.10.1, the auth check in mnemosyne/core/sync_server.py parsed the JWT's header and payload using base64 decoding, then passed the token to a jwt library call with options that effectively disabled signature verification. The server accepted any well-formed token regardless of the signature, including tokens with alg: none a…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93657] hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Reso…
hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successful results. Attackers controlling the answering zone or positioned on the network path can have forged DNS records accepted as validated, bypassing DNSSEC authentication checks.
M Alto vulnerabilidad
18/09/2026
Vulnerabilidad alta en NetBackup Flex permite escalada a root sin autenticación adicional
Un usuario autenticado con privilegios bajos puede eludir la verificación criptográfica de comandos administrativos en NetBackup Flex OS proporcionando credenciales malformadas, obteniendo acceso root irrestricto. Esta vulnerabilidad afecta directamente a empresas en LATAM que dependen de NetBackup para respaldos y recuperación de datos altas, comprometiendo la integridad de toda la infraestructura de backup y los contenedores alojados.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-86038] libp2p is a JavaScript implementation of the libp2p networking stack. From 15.0.0 until 16.0.5, @lib…
libp2p is a JavaScript implementation of the libp2p networking stack. From 15.0.0 until 16.0.5, @libp2p/gossipsub uses the default StrictSign policy in packages/gossipsub/src/utils/buildRawMessage.ts, where validateToRawMessage verifies a signature with attacker-controlled msg.key but skips binding that key to msg.from when the claimed author is an RSA peer ID that does not inline a public key. An…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92718] Nuclei versions before 3.11.1 cache template signature verification based only on file modification …
Nuclei versions before 3.11.1 cache template signature verification based only on file modification time without content checksums. Attackers can replace verified templates with unsigned malicious content and restore the original modification time to bypass signature checks and execute arbitrary operating system commands.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-42784] A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates…
A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags subpacket is missing, leading to a discrepancy in how key capabilities are viewed. This key flag confusion allows an attacker to bypass the back-signature check. Consequently, an attacker can illegitimately bind an arbitrary subkey to their own certificate and forge signatures, com…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-58200] Payload Plugins is a collection of plugins designed to enhance Payload CMS. From 0.3.0 until 0.4.0, …
Payload Plugins is a collection of plugins designed to enhance Payload CMS. From 0.3.0 until 0.4.0, @jhb.software/payload-cloudinary-plugin deployments with clientUploads enabled expose POST /api/cloudinary-generate-signature, whose handler in cloudinary/src/getGenerateSignature.ts passes attacker-controlled body.paramsToSign directly to cloudinary.utils.api_sign_request without a key allowlist, c…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-54155] node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the UserNameIde…
node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the UserNameIdentityToken authentication handler in packages/node-opcua-server/source/opcua_server.ts decrypts an RSA-OAEP password blob but does not verify that the trailing bytes match the current session serverNonce. An unauthenticated remote attacker can obtain the server public key through GetEndpoints and fo…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
14/09/2026
[CVE-2026-57122] PraisonAI is a multi-agent teams system. Prior to 4.6.59, the WhatsApp and Linear bot webhook handle…
PraisonAI is a multi-agent teams system. Prior to 4.6.59, the WhatsApp and Linear bot webhook handlers verify HMAC signatures only when WHATSAPP_APP_SECRET or LINEAR_WEBHOOK_SECRET is configured and otherwise parse and dispatch unsigned request bodies. A remote unauthenticated client that reaches the webhook route can forge messages, comments, or agent-session events, impersonate platform users, i…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-87802] Improper verification of cryptographic signature vulnerability in Apache Syncope. When SRA is con…
Improper verification of cryptographic signature vulnerability in Apache Syncope. When SRA is configured for OAuth 2.0 without JWKS set URI assigned, an attacker can forge arbitrary JWTs to impersonate any user identity and permissions, gaining full access to services proxied by SRA. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 thr…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-80469] Ejecución arbitraria de código mediante carga de controladores maliciosos
Una vulnerabilidad alta permite a atacantes ejecutar código arbitrario en sistemas objetivo cargando paquetes de controladores maliciosos que eluden mecanismos de verificación. El impacto afecta principalmente a infraestructuras empresariales en LATAM que utilizan dispositivos de hardware con controladores sin validación adecuada. Requiere interacción del usuario para su explotación.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-73784] A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML respons…
A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML response, allowing an attacker to impersonate another user.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-89086] In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm…
In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key.