Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad alta en libde265: desbordamiento de enteros en códecs H.265
libde265, biblioteca de código abierto para decodificación de vídeo H.265 (HEVC), contiene un desbordamiento de enteros en versiones anteriores a 1.1.1 que permite a atacantes mediante flujos HEVC manipulados provocar lectura fuera de límites en memoria heap, exponiendo datos sensibles o causando caída del servicio. Afecta servidores multimedia, plataformas de streaming y sistemas de videoconferencia en empresas LATAM que procesan vídeo con esta biblioteca.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad de traversal de directorios en libks anteriores a v2.0.11
libks, biblioteca fundamental para productos SignalWire C, contiene un defecto en la función `clean_uri()` del analizador HTTP que permite eludir la validación de rutas. Versiones anteriores a 2.0.11 no rechazarán URIs con segmentos de ruta excesivos, dejando secuencias ".." intactas y facilitando ataques de traversal de directorios. Esto afecta a cualquier aplicación que integre libks y procese solicitudes HTTP, comprometiendo el acceso a archivos sensibles en servidores de telecomunicaciones y plataformas de comunicaciones unificadas.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad de condición de carrera en Hoverfly anteriores a v1.12.8
Hoverfly, herramienta de código abierto para simulación de APIs, presenta una vulnerabilidad de race condition en modo Diff que afecta escrituras concurrentes sin sincronización. Cuando múltiples solicitudes proxy se procesan simultáneamente, la función AddDiff() accede sin mutex al mapa compartido responsesDiff, causando fallos fatales en sistemas que dependen de esta herramienta para testing y desarrollo. Empresas en LATAM que usan Hoverfly en entornos de CI/CD o ambientes de validación de APIs están expuestas a interrupciones operacionales.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad alta en Shelf permite inyección SSRF en importación de activos
Shelf, plataforma de gestión de inventarios físicos, contiene una vulnerabilidad de Server-Side Request Forgery (SSRF) en versiones anteriores a 1.20.3. Usuarios autenticados con permisos de importación pueden eludir validaciones de URL en la función de importación CSV para ejecutar peticiones HTTP a servidores controlados por atacantes. Afecta principalmente a empresas LATAM que gestionan activos tecnológicos y de infraestructura a través de esta plataforma.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad en Melange y Apko permite instalar paquetes APK maliciosos sin validación
Melange versiones anteriores a 0.50.4 y Apko anteriores a 1.2.9 no verifican la integridad de los archivos de datos en paquetes APK durante la instalación, solo validan metadatos. Un atacante que controle un espejo, envenenene un caché o realice ataques MITM puede distribuir paquetes comprometidos que se instalarán sin detección. Afecta infraestructuras que utilizan estos gestores de compilación en entornos Linux containerizados.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad de control de acceso en NL Portal Backend Libraries permite acceso no autorizado a tareas
El paquete `nl.nl-portal:taak` (versiones 1.5.0 a 3.0.0) no valida correctamente la propiedad de tareas en la mutación GraphQL `submitTaakV2`, permitiendo a usuarios autenticados leer formularios de otros usuarios si conocen o adivinan su ID de tarea. Esta vulnerabilidad afecta sistemas de gobierno digital en portales de atención ciudadana que procesan información sensible de residentes, clientes y proveedores.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-54135] AirSane is a SANE frontend, and a scanner server that supports Apple's AirScan protocol. Versions pr…
AirSane is a SANE frontend, and a scanner server that supports Apple's AirScan protocol. Versions prior to 0.4.12 have a vulnerability in the custom HTTP server implementation of AirSane that allows a remote unauthenticated attacker to cause a Denial of Service (DoS) via memory exhaustion (OOM). In httpserver.cpp, the HttpServer::Request::content function reads the Content-Length header and direct…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
11/09/2026
[CVE-2026-79393] A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in th…
A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote unauthenticated attackers to cause a denial of service or potentially execute arbitrary code via a crafted SOAP request containing a wsa5:Action string exceeding 128 bytes.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-62112] Editor SQL Injection in Amelia <= 2.4.9 versions.
Editor SQL Injection in Amelia
M Alto vulnerabilidad
11/09/2026
[CVE-2026-62102] Subscriber Privilege Escalation in Gato GraphQL <= 19.2.3 versions.
Subscriber Privilege Escalation in Gato GraphQL
M Alto vulnerabilidad
11/09/2026
[CVE-2026-62106] Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.9 versions.
Subscriber Privilege Escalation in SMS Alert Order Notifications
M Alto vulnerabilidad
11/09/2026
[CVE-2026-62107] Unauthenticated PHP Object Injection in Masteriyo - LMS <= 3.4.0 versions.
Unauthenticated PHP Object Injection in Masteriyo - LMS
M Alto vulnerabilidad
11/09/2026
[CVE-2026-62109] Editor SQL Injection in Sky Addons for Elementor <= 3.8.4 versions.
Editor SQL Injection in Sky Addons for Elementor
M Alto vulnerabilidad
11/09/2026
[CVE-2026-62089] Missing Authorization vulnerability in Pixar Labs Master Addons for Elementor allows Privilege Abuse…
Missing Authorization vulnerability in Pixar Labs Master Addons for Elementor allows Privilege Abuse. This issue affects Master Addons for Elementor: from n/a through 3.2.2.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-89099] A race condition in the document value layer of MongoDB Server can allow concurrent server threads t…
A race condition in the document value layer of MongoDB Server can allow concurrent server threads to operate on the same internal memory without synchronization, leading to memory corruption. An authenticated user holding ordinary read-write privileges on a database may be able to trigger this condition over the normal client protocol, resulting in server termination and potential corruption of p…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
11/09/2026
[CVE-2026-78807] An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper netwo…
An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c
M Alto vulnerabilidad
11/09/2026
[CVE-2026-72708] SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the public sitem…
SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the public sitemap endpoint where the MySQL escaper spip_mysql_cite() in ecrire/req/mysql.php returns values unescaped when the target column is a date type and the supplied value matches the pattern of a word character followed by an open parenthesis. Attackers can supply a crafted value such as a time-based paylo…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-89260] MoguBlog through 6.2 contains an XML external entity injection vulnerability in the WeChat callback …
MoguBlog through 6.2 contains an XML external entity injection vulnerability in the WeChat callback handler at POST /wechat/wechatCheck. The WechatRestApi.index() method passes the raw request body to SignUtil.xmlToMap(), which uses an unhardened dom4j SAXReader without DTD or external-entity restrictions. Unauthenticated remote attackers can submit DOCTYPE declarations with external parameter ent…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-89262] MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint…
MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal. Attackers can delete arbitrary comments and their replies by supplying comment UIDs and author UIDs obtained from unauthenticated listing endpoints.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-89065] Relative path traversal in the generated file manifest cleanup component in projen before 0.101.37 m…
Relative path traversal in the generated file manifest cleanup component in projen before 0.101.37 might allow context-dependent attackers to recursively delete files and directories outside the project directory that are writable by the environment running projen, via crafted entries in the version-controlled generated file manifest that is consumed during project synthesis. To remediate this …