Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "X" — 4155 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1052
Esta semana
RSS
M Alto vulnerabilidad
11/09/2026
[CVE-2026-54135] AirSane is a SANE frontend, and a scanner server that supports Apple's AirScan protocol. Versions pr…
AirSane is a SANE frontend, and a scanner server that supports Apple's AirScan protocol. Versions prior to 0.4.12 have a vulnerability in the custom HTTP server implementation of AirSane that allows a remote unauthenticated attacker to cause a Denial of Service (DoS) via memory exhaustion (OOM). In httpserver.cpp, the HttpServer::Request::content function reads the Content-Length header and direct…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-79393] A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in th…
A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote unauthenticated attackers to cause a denial of service or potentially execute arbitrary code via a crafted SOAP request containing a wsa5:Action string exceeding 128 bytes.
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-79395] An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routin…
An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote attackers to bypass authentication and execute privileged ONVIF actions (including PTZ control, stream URL retrieval, and system reboot) via a crafted SOAP request supplying the admin…
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-62105] Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.
Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-62089] Missing Authorization vulnerability in Pixar Labs Master Addons for Elementor allows Privilege Abuse…
Missing Authorization vulnerability in Pixar Labs Master Addons for Elementor allows Privilege Abuse. This issue affects Master Addons for Elementor: from n/a through 3.2.2.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-78807] An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper netwo…
An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-72710] SPIP before 4.4.18 contains a remote code execution vulnerability in the editer_objet action where t…
SPIP before 4.4.18 contains a remote code execution vulnerability in the editer_objet action where the arg parameter resolves SQL table names without enforcing an editable columns allowlist, allowing attackers with a valid nonce to inject attacker-controlled rows into the spip_jobs table. Attackers can supply arg=job/0 with crafted fonction and args values, which are later unserialized and execute…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
11/09/2026
[CVE-2026-89260] MoguBlog through 6.2 contains an XML external entity injection vulnerability in the WeChat callback …
MoguBlog through 6.2 contains an XML external entity injection vulnerability in the WeChat callback handler at POST /wechat/wechatCheck. The WechatRestApi.index() method passes the raw request body to SignUtil.xmlToMap(), which uses an unhardened dom4j SAXReader without DTD or external-entity restrictions. Unauthenticated remote attackers can submit DOCTYPE declarations with external parameter ent…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-89065] Relative path traversal in the generated file manifest cleanup component in projen before 0.101.37 m…
Relative path traversal in the generated file manifest cleanup component in projen before 0.101.37 might allow context-dependent attackers to recursively delete files and directories outside the project directory that are writable by the environment running projen, via crafted entries in the version-controlled generated file manifest that is consumed during project synthesis. To remediate this …
M Alto vulnerabilidad
11/09/2026
[CVE-2026-89066] Improper neutralization of special elements used in an OS command in the task synthesis component in…
Improper neutralization of special elements used in an OS command in the task synthesis component in projen before 0.103.0 might allow context-dependent attackers to execute arbitrary commands on a developer workstation or continuous integration runner via shell metacharacters in project configuration values and repository file names that are interpolated into generated task definitions. To rem…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-68497] jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGrego…
jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLDeserializers.Std._deserialize. These deserializers are registered by default with no opt-in, so a plain ObjectMapper or JsonMapper with no polymorphic typing and n…
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-89010] WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticat…
WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted filenames to the sync_server daemon on TCP port 13136. The daemon interpolates attacker-controlled filename input containing shell metacharacters into a shell command string vi…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-82578] When XML batch processing is turned on and the XPath option is selected, the raw batch input goes th…
When XML batch processing is turned on and the XPath option is selected, the raw batch input goes through a default XPath/JAXP setup with no entity restrictions, so XXE injection can allow data exfiltration and denial-of-service attacks.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-82583] NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an authenticated user to execute ar…
NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an authenticated user to execute arbitrary SQL through a Database Connector API, which could result in disclosure of stored credentials for connected systems, arbitrary file write, and a denial-of-service condition.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-78224] The XSLT Transformer Step builds a bare TransformerFactory without the proper security options set, …
The XSLT Transformer Step builds a bare TransformerFactory without the proper security options set, so XXE injection can allow data exfiltration and denial-of-service attacks.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
11/09/2026
[CVE-2026-38056] A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmwar…
A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0. The iQ200 is a rackmount satellite modem deployed across oil and gas, maritime, defense, and remote infrastructure as the primary, and often sole communications link for offshore rigs, vessels, and remote sites. Important context: the device ships from the factory with a pre-configured l…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-38058] The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, i…
The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for the root SSH and web administration accounts. Any user with valid web credentials can extract these hashes and crack them offline using commodity hardware.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-89212] A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references we…
A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references were improperly restricted during XML-to-JSON processing. The issue affects Akana versions 2026.1, 2025.1.1, and all versions before 2024.1.6 (including older unsupported versions of Akana) and has been fixed as a security patch in the latest release of supported versions.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-71416] Headroom compresses data before the data reaches a large language model. Prior to version 0.35.0, th…
Headroom compresses data before the data reaches a large language model. Prior to version 0.35.0, the Headroom WebSocket server does not validate the `Origin` header of incoming client WebSocket requests before forwarding the request to the upstream server, allowing malicious WebSocket clients to perform arbitrary LLM requests without authentication. This can be exploited by a malicious WebSocket …
M Alto vulnerabilidad
11/09/2026
[CVE-2026-57842] NetBSD contains a use-after-free and double-free vulnerability in msg_recv_copyin() within the COMPA…
NetBSD contains a use-after-free and double-free vulnerability in msg_recv_copyin() within the COMPAT_NETBSD32 compatibility layer due to a missing return statement before the cleanup label on the success path. Any local user able to execute a 32-bit binary on a 64-bit NetBSD system can trigger a kernel panic or memory corruption by calling recvmsg() with msg_iovlen between 9 and IOV_MAX, causing …