Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Quest" — 2120 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Alto vulnerabilidad
17/09/2026
[CVE-2026-93014] RosarioSIS versions before 12.9 fail to validate the filename request parameter in Users and Student…
RosarioSIS versions before 12.9 fail to validate the filename request parameter in Users and Students modules, allowing authenticated users to unlink allow-listed files via path traversal. Attackers can use parent-directory sequences to escape upload directories and delete CSS, XML, JSON resources and other users' documents throughout the installation.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-86864] pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job/<sid>/obj…
pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job//object request to the pg_dump argument vector as a bare trailing positional argument, without validation. Because pg_dump parses its options with getopt_long, which permutes arguments, a value beginning with a dash was interpreted as an option rather than as a database name. A value such as --file=/abs…
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-86863] pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web se…
pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or reverse proxy in front of pgAdmin, delivered through the WSGI/CGI environment. WebserverAuthentication.get_user() read config.WEBSERVER_REMOTE_USER from request.environ and, when that returned nothing, fell back to reading the same name directly from the inbound HTTP request headers via requ…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-85719] The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and async…
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 2.16.1 and 3.0.12, requests using an authenticated SOCKS proxy can expose the proxy's credentials to the origin because NettyRequestFactory and NettyRequestSender attach Proxy-Authorization without confirming that the request is being sent to an HTT…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-85721] The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and async…
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, automatic response decompression on the HTTP/1.1 path uses ChannelManager.newHttpContentDecompressor() to install Http1ContentDecompressor without a cumulative output-size limit. A hostile or compromised server, or an attacker who…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-76834] b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901 where the s…
b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901 where the serialized-array object check in param_check_serialized_array() fails to reject payloads with negative integer array keys. Unauthenticated attackers can submit crafted serialized PHP objects via POST requests to htsrv/call_plugin.php that bypass validation and reach unserialize(), instantiating arbit…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-92983] InternLM LMDeploy through 0.17.0 in DistServe prefill/decode disaggregation mode fails to release sc…
InternLM LMDeploy through 0.17.0 in DistServe prefill/decode disaggregation mode fails to release scheduler sessions because the proxy uses user-facing session IDs instead of internal scheduler keys. Unauthenticated attackers can send completion requests to the proxy endpoint that accumulate unreleased scheduler metadata and memory until the prefill worker is out-of-memory killed.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
17/09/2026
[CVE-2026-92984] HUBzero CMS through 2.2.32 accepts session identifiers from query strings and request variables inst…
HUBzero CMS through 2.2.32 accepts session identifiers from query strings and request variables instead of cookies alone, allowing unauthenticated attackers to fixate victim sessions. Attackers can obtain a valid session identifier, send victims a crafted link containing it, and replay the identifier after the victim authenticates to hijack their account and access.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-81446] Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request For…
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-92971] InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistServe decod…
InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistServe decode migration loop that allows unauthenticated attackers to terminate the inference engine. Attackers can submit a migration_request with an empty remote_block_ids list to trigger an AssertionError that crashes the engine loop and causes subsequent inference requests to fail.
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-92938] vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to code running in NodeV…
vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to code running in NodeVM when that builtin is permitted, either explicitly or through builtin: ['*']. The module is wrapped with vm.readonly(), which prevents property assignment but leaves host-authority callables reachable; in addition, the resolver treats any request starting with 'node:' as a core-module request and t…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-78295] Unauthenticated Cross Site Request Forgery (CSRF) in Xagio SEO <= 7.1.0.43 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Xagio SEO
M Alto vulnerabilidad
17/09/2026
[CVE-2026-66571] Unauthenticated Cross Site Request Forgery (CSRF) in Asset CleanUp: Page Speed Booster <= 1.4.0.5 ve…
Unauthenticated Cross Site Request Forgery (CSRF) in Asset CleanUp: Page Speed Booster
M Alto vulnerabilidad
17/09/2026
Vulnerabilidad alta de bypass de autenticación en AVideo LoginControl (CVE-2026-92914)
AVideo LoginControl contiene una vulnerabilidad de bypass de autenticación en la verificación del segundo factor PGP que compara respuestas usando igualdad débil contra variables de sesión no inicializadas. Un atacante con la contraseña de la víctima puede eludir el segundo factor enviando una solicitud GET sin parámetros a verifyChallenge.json.php, lo que evalúa null == null y marca la autenticación como completada. Esto afecta principalmente a plataformas de video y gestión de contenido en empresas medianas de México y Latinoamérica que utilizan AVideo para portales internos o servicios al cliente.
M Alto vulnerabilidad
17/09/2026
Vulnerabilidad de autenticación en Grav CMS expone endpoint de depuración
Grav (versiones 1.7.0-1.7.53.2 y 2.0.0-2.0.21) expone el endpoint de profiler Clockwork sin autenticación cuando el depurador está habilitado. Un atacante remoto puede acceder a información sensible del sistema sin credenciales. Afecta principalmente a empresas con sitios en Grav que dejaron debugging activo en producción.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
17/09/2026
Vulnerabilidad crítica en FatPipe MPVPN, WARP e IPVPN: desbordamiento de búfer remoto (CVE-2026-90823)
Los equipos FatPipe MPVPN, WARP e IPVPN con firmware 10.1.2r60p100 (fin de vida) contienen un desbordamiento de búfer en la interfaz de autenticación que permite ejecución remota de código sin credenciales. Un atacante puede enviar una solicitud manipulada contra la interfaz de gestión para comprometer completamente el dispositivo, poniendo en riesgo la conectividad WAN y acceso a datos corporativos en LATAM.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-87963] The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username reques…
The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username request parameter before using it in a SQL query, and reads it before WordPress applies its request escaping, allowing unauthenticated attackers to perform SQL injection and read arbitrary database contents including administrator password hashes.
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-88795] The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4 does not generate its API authenticat…
The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4 does not generate its API authentication token securely, deriving it from data the requester controls and creating it as a side effect of the check that is supposed to validate it, allowing unauthenticated attackers to predict the token and use the access it grants to write arbitrary files, leading to remote code execution.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-88904] The PuppyFW WordPress plugin through 0.4.4 does not have proper authorisation on one of its REST rou…
The PuppyFW WordPress plugin through 0.4.4 does not have proper authorisation on one of its REST routes, which tests the caller against a capability taken from the request itself, allowing any authenticated user, including subscribers, to add, modify and delete arbitrary blog options and thereby escalate their privileges.
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-86707] The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate …
The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate a feed request is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, including administrators.