Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1052
Esta semana
RSS
M Alto vulnerabilidad
11/09/2026
[CVE-2026-89066] Improper neutralization of special elements used in an OS command in the task synthesis component in…
Improper neutralization of special elements used in an OS command in the task synthesis component in projen before 0.103.0 might allow context-dependent attackers to execute arbitrary commands on a developer workstation or continuous integration runner via shell metacharacters in project configuration values and repository file names that are interpolated into generated task definitions. To rem…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-89013] Dolibarr 23.0.4 before 24.0.1 ontains an authorization bypass vulnerability that allows unauthentica…
Dolibarr 23.0.4 before 24.0.1 ontains an authorization bypass vulnerability that allows unauthenticated attackers to read arbitrary files through the document storage endpoints by supplying a crafted hashp parameter value. Attackers can send a request with hashp=shared to skip token validation while satisfying the authorization condition in htdocs/document.php and htdocs/viewimage.php, gaining acc…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-7863] Improper neutralization of special elements used in an OS command ('OS command injection') vulnerabi…
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Software allows OS Command Injection. This issue affects Pardus Software: before 1.0.5.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-68497] jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGrego…
jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLDeserializers.Std._deserialize. These deserializers are registered by default with no opt-in, so a plain ObjectMapper or JsonMapper with no polymorphic typing and n…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-8301] Improper neutralization of special elements used in an OS command ('OS command injection') vulnerabi…
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Boot Repair allows OS Command Injection. This issue affects Pardus Boot Repair: before 1.0.8.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-8303] Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Instit…
Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-software allows Privilege Escalation. This issue affects Pardus-software: before 1.0.5.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-82578] When XML batch processing is turned on and the XPath option is selected, the raw batch input goes th…
When XML batch processing is turned on and the XPath option is selected, the raw batch input goes through a default XPath/JAXP setup with no entity restrictions, so XXE injection can allow data exfiltration and denial-of-service attacks.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
11/09/2026
[CVE-2026-82583] NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an authenticated user to execute ar…
NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an authenticated user to execute arbitrary SQL through a Database Connector API, which could result in disclosure of stored credentials for connected systems, arbitrary file write, and a denial-of-service condition.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-87020] An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds w…
An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc DICOM Server decodes an attacker-supplied PNG.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-78224] The XSLT Transformer Step builds a bare TransformerFactory without the proper security options set, …
The XSLT Transformer Step builds a bare TransformerFactory without the proper security options set, so XXE injection can allow data exfiltration and denial-of-service attacks.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-38056] A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmwar…
A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0. The iQ200 is a rackmount satellite modem deployed across oil and gas, maritime, defense, and remote infrastructure as the primary, and often sole communications link for offshore rigs, vessels, and remote sites. Important context: the device ships from the factory with a pre-configured l…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-38058] The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, i…
The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for the root SSH and web administration accounts. Any user with valid web credentials can extract these hashes and crack them offline using commodity hardware.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-89212] A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references we…
A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references were improperly restricted during XML-to-JSON processing. The issue affects Akana versions 2026.1, 2025.1.1, and all versions before 2024.1.6 (including older unsupported versions of Akana) and has been fixed as a security patch in the latest release of supported versions.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-71416] Headroom compresses data before the data reaches a large language model. Prior to version 0.35.0, th…
Headroom compresses data before the data reaches a large language model. Prior to version 0.35.0, the Headroom WebSocket server does not validate the `Origin` header of incoming client WebSocket requests before forwarding the request to the upstream server, allowing malicious WebSocket clients to perform arbitrary LLM requests without authentication. This can be exploited by a malicious WebSocket …
M Alto vulnerabilidad
11/09/2026
[CVE-2026-57842] NetBSD contains a use-after-free and double-free vulnerability in msg_recv_copyin() within the COMPA…
NetBSD contains a use-after-free and double-free vulnerability in msg_recv_copyin() within the COMPAT_NETBSD32 compatibility layer due to a missing return statement before the cleanup label on the success path. Any local user able to execute a 32-bit binary on a 64-bit NetBSD system can trigger a kernel panic or memory corruption by calling recvmsg() with msg_iovlen between 9 and IOV_MAX, causing …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad XSS almacenado alta en AVideo plugin Bookmark (CVE-2026-89256)
AVideo contiene una vulnerabilidad de cross-site scripting (XSS) almacenado en el plugin Bookmark que permite a propietarios de videos inyectar código malicioso a través del parámetro de nombre de capítulo. Los nombres de capítulos no se codifican antes de insertarse en el HTML de la página pública, causando que todo visitante ejecute el payload en el origen de AVideo. Con CVSS 8.7, afecta plataformas de streaming y repositorios de video frecuentes en empresas e instituciones educativas de LATAM.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad alta de lectura de archivos sin autenticación en WWBN AVideo (CVE-2026-89250)
WWBN AVideo contiene una vulnerabilidad de lectura de archivos sin autenticación en el endpoint getRecordedFile.php que expone archivos de video grabados en FLV desde el directorio temporal. Atacantes pueden descargar archivos de video en vivo sin validación de autenticación utilizando claves de stream conocidas o adivinadas. Este riesgo afecta principalmente a plataformas de streaming y educación en línea en LATAM que utilizan esta solución para transmisiones en vivo.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad XSS almacenado alta en WWBN AVideo (CVE-2026-89253)
WWBN AVideo contiene una vulnerabilidad de cross-site scripting (XSS) almacenado en el campo de perfil 'donationLink' que permite a usuarios autenticados inyectar código malicioso. La validación insuficiente en la función setDonationLink() acepta URLs malformadas con cargas de script. Afecta principalmente a plataformas de streaming y educación en línea que utilizan este software en servidores locales o en la nube en LATAM.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad alta de XSS almacenado en AVideo (CVE-2026-89254)
AVideo contiene una vulnerabilidad de cross-site scripting (XSS) almacenado en el plugin CustomizeUser que permite a administradores inyectar scripts maliciosos mediante el parámetro field_name sin sanitización en el endpoint add.json.php. Los scripts se ejecutan cuando usuarios visualizan formularios de perfil o páginas de información adicional, afectando la integridad de datos y sesiones de usuarios en plataformas de video bajo demanda. En LATAM, esta vulnerabilidad impacta especialmente a proveedores de contenido, universidades y plataformas educativas que utilizan AVideo en su infraestructura de distribución.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad XSS almacenado alta en AVideo afecta sesiones de administradores
AVideo contiene una vulnerabilidad de cross-site scripting (XSS) almacenado en el plugin LoginControl que no codifica correctamente las claves PGP públicas. Un atacante autenticado puede inyectar código JavaScript malicioso mediante una clave PGP fraudulenta, el cual se ejecuta en la sesión del administrador al visualizar la pestaña de perfil de usuario. Con CVSS 8.7, afecta principalmente plataformas de video on-demand y educación en línea en LATAM que usan AVideo sin actualizar.