Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 3 horas
14,928
Total alertas
3375
Críticas
11165
Altas
8
Ransomware
865
Esta semana
RSS
M Alto vulnerabilidad
Hace 5 días
Vulnerabilidad alta en MongoDB Connector for BI ODBC: desbordamiento de búfer por inyección SQL
Un atacante puede enviar consultas SQL malformadas a través del controlador ODBC de MongoDB Connector for BI, especificando nombres de cursor que exceden los límites internos del búfer. Esto provoca sobrescritura de memoria adyacente, potencialmente causando denial of service (DoS) o ejecución de código arbitrario en aplicaciones que integren este conector. Afecta directamente a plataformas de análisis y Business Intelligence que dependan de este driver en entornos LATAM.
M Alto vulnerabilidad
Hace 5 días
Vulnerabilidad de memoria en MongoDB BI Connector ODBC Driver (CVE-2026-81533)
El controlador ODBC de MongoDB BI Connector presenta un fallo de seguridad de memoria (CVSS 7.1) cuando procesa sentencias SQL con secuencias de dígitos inusualmente largas en cláusulas LIMIT, afectando solo conexiones con la opción de prefetch habilitada. La vulnerabilidad se origina por copia insegura de datos a un búfer interno de tamaño fijo sin validación de límites. Empresas en LATAM que utilizan este driver para consultas analíticas en MongoDB deben revisar inmediatamente su configuración de prefetch y aplicar los parches disponibles del fabricante.
M Alto vulnerabilidad
Hace 5 días
Vulnerabilidad en multer 2.2.0: descriptor de archivo no cerrado en cargas abortadas
multer, middleware de Node.js para procesar multipart/form-data, presenta una vulnerabilidad en la versión 2.2.0 donde las cargas abortadas o truncadas no cierran correctamente los descriptores de archivo, dejándolos abiertos en el sistema. Esto permite a atacantes remotos consumir recursos del servidor y potencialmente acceder a información sensible. El riesgo es alta en aplicaciones web que manejan uploads de usuarios sin autenticación robusta.
M Alto vulnerabilidad
Hace 5 días
Vulnerabilidad alta en multer permite denegación de servicio en aplicaciones Node.js
multer, middleware estándar para procesar datos multipart/form-data en Node.js, contiene una vulnerabilidad que causa RangeError no controlado al recibir solicitudes especialmente crafteadas con nombres de campos numéricos malformados. Un atacante puede terminar abruptamente el proceso Node.js, afectando disponibilidad de plataformas digitales en empresas mexicanas y latinoamericanas que usan este componente en APIs de carga de archivos.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-18899] IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to read arbitrary files due to p…
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to read arbitrary files due to path traversal.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-18904] IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information …
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information and inject unauthorized messages due to a namespace collision between user identifiers.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-16821] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileg…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a format string vulnerability.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-17203] IBM Administration Runtime Expert for i 1R1M0 could allow a remote authenticated attacker to obtain …
IBM Administration Runtime Expert for i 1R1M0 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-18729] IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitra…
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-18891] IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and a…
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and access sensitive information due to improper authentication.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-82286] gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the POST /crawl endpoint…
gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the POST /crawl endpoint, allowing unauthenticated attackers to write arbitrary files to any filesystem path. Attackers can supply absolute paths or parent-directory segments to overwrite existing files with content sourced from attacker-controlled URLs.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-82287] Rybbit before 2.7.0 contains a CORS misconfiguration vulnerability that allows attackers to bypass o…
Rybbit before 2.7.0 contains a CORS misconfiguration vulnerability that allows attackers to bypass origin restrictions by reflecting any request origin in Access-Control-Allow-Origin responses while credentials are enabled. Attackers can issue credentialed cross-origin requests from any website to read analytics data, account information, and perform authenticated state-changing operations as the …
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-82288] Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerability in the /sdapi/v…
Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerability in the /sdapi/v1/cmd-flags endpoint that returns parsed command-line arguments including gradio_auth and api_auth values in cleartext. Unauthenticated attackers can access this endpoint to retrieve configured usernames and passwords, then use them to authenticate to the interface and access the application.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-82289] Gitingest through 0.3.1 fails to properly validate hostnames in _validate_host, accepting any host w…
Gitingest through 0.3.1 fails to properly validate hostnames in _validate_host, accepting any host with a git., gitlab., or github. prefix regardless of known-hosts list membership. Attackers can submit URLs with attacker-controlled hostnames to trigger outbound connections to arbitrary hosts and disclose GitHub personal access tokens via HTTP basic credentials.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-82291] HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS responses while allowing creden…
HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS responses while allowing credentials, enabling cross-origin requests with authentication. Attackers can execute authenticated GraphQL queries from malicious pages visited by logged-in users to access workspaces, projects, forms, submissions, and respondent data, or modify account settings.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-82279] HyperDX through 1.10.1 fails to enforce role-based access controls in team management endpoints, all…
HyperDX through 1.10.1 fails to enforce role-based access controls in team management endpoints, allowing any team member to perform administrative actions. Attackers can delete team members including owners, rotate API keys, and rename teams by sending requests to PATCH /team/apiKey, PATCH /team/name, and DELETE /team/member endpoints.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-82280] Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users …
Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users to modify any prompt by identifier. Attackers with read-only access to shared brains can read exposed prompt identifiers and overwrite system prompts affecting all brain users.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-82281] Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_con…
Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_conv, rename_conv, and on_set_public_conversation functions in control.py. Attackers can read other users' chat histories, delete conversations, or rename conversations by supplying arbitrary conversation identifiers without proper authorization checks.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-82282] Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing unauthenticat…
Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing unauthenticated attackers to access GitHub App credentials. Attackers can observe or intercept the GitHub redirect during setup to obtain the RSA private key and webhook secret, enabling installation token minting and webhook payload forgery.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-82283] VoltAgent through 2.1.20 fails to validate conversation ownership in memory API handlers, allowing a…
VoltAgent through 2.1.20 fails to validate conversation ownership in memory API handlers, allowing authenticated users to access other users' conversations. Attackers can read, modify, and delete arbitrary conversations and messages by supplying caller-controlled identifiers to memory endpoints.