Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
14,812
Total alertas
3354
Críticas
11071
Altas
8
Ransomware
958
Esta semana
RSS
M Alto vulnerabilidad
11/08/2026
[CVE-2026-15560] when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs …
when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to load and instantiate arbitrary classes from a remote URL in the server JVM before EJB security interceptors run.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-15561] A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and cou…
A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the listener, and achieving Denial of Service.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-16053] Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to A…
Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exchange Online backup module.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-4757] A VAPIX API parameter had improper input validation which could allow code execution and potentially…
A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege escalation. This flaw can only be exploited after authenticating with an administrator-privileged service account.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-19516] A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound re…
A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the caller also choose the HTTP method, path, and body. Because the destination is not restricted to the configured Grafana instance, a caller can direct requests at internal, loopback, and link-local network services (including metadata endpoints) and r…
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-13716] Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authent…
Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to the Crafty Controller application and perform remote code execution.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-19425] Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability…
Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
11/08/2026
[CVE-2026-19424] Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability.…
Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated remote attackers can modify a specific parameter to read other users' sensitive data.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-66763] SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated w…
SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic key. An attacker with high privileges and local access to the server could retrieve these objects and decrypt the stored credentials. Successful exploitation could allow the attacker to obtain sensitive authentication data and modify protected inform…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-58243] SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality…
SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to execute unauthorized database operations against SAP NetWeaver AS ABAP. Successful exploitation could allow the attacker to read sensitive data, modify application data, and disrupt access for legitimate users, resulting in high impact on confidentiality…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-44764] Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence…
Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated attacker could send crafted requests to the Cost Servlet using specific parameter values. If processed by the application, these requests enable access to backend operations. Successful exploitation could allow the attacker to read, create, modify, or delete application-managed …
M Alto vulnerabilidad
11/08/2026
[CVE-2026-44765] Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence…
Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated remote attacker could access scheduling-related application functions without proper authorization validation. Successful exploitation could allow the attacker to retrieve, create, modify, or delete application-managed scheduling data, causing a low impact on confidentiality, in…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-58230] SAP Approuter does not sufficiently validate certain token content under specific configurations. An…
SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially crafted token to cause sensitive credential material to be sent to an attacker-controlled destination. The attack complexity is high due to non-default preconditions required in the target environment. This results in a high impact on confidentiality …
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-34265] SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors i…
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could potentially disclose sensitive system information or crash the system, leading to a high impact on the confidentiality, integrity, and availability of the application.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-44758] SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to subm…
SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system, resulting in high impact on confidentiality, integrity, and availability …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
11/08/2026
[CVE-2026-44763] SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient …
SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires a legitimate user to subsequently access the attacker-influenced content and depends on conditions outside the attacker�s control. Successful exploitation could allow files to be written outside the i…
M Alto vulnerabilidad
10/08/2026
[CVE-2026-8718] tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles g…
tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles getsockopt(SOL_TLS, TLS_DTLS_PEER_CID_VALUE), passed the caller-supplied optval directly to mbedtls_ssl_get_peer_cid() without verifying the buffer was at least MBEDTLS_SSL_CID_OUT_LEN_MAX (default 32) bytes. mbedtls_ssl_get_peer_cid() copies the peer-negotiated DTLS Connection ID (length 1..MBEDTLS_…
M Alto vulnerabilidad
10/08/2026
[CVE-2026-72914] Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14,…
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1, the administrative statistics endpoints handled by Api::V1::Admin::MeasuresController and Api::V1::Admin::RetentionController checked authorization only after beginning expensive calculations. Anonymous callers could submit keys, start_at, and end_at parameters that caused …
M Alto vulnerabilidad
10/08/2026
[CVE-2026-72915] Mastodon is a free, open-source social network server based on ActivityPub. From 4.6.0-beta.1 until …
Mastodon is a free, open-source social network server based on ActivityPub. From 4.6.0-beta.1 until 4.6.4 and 4.7.0-beta.1, any logged-in local user could use the show action in app/controllers/admin/collections_controller.rb to access personally identifying information about another local user in a collection because the controller used the general collection policy instead of the admin collectio…
M Alto vulnerabilidad
10/08/2026
[CVE-2026-73030] unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_w…
unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize paths before validation, allowing ../ sequences to bypass directory containment checks. Attackers can supply malicious tar archives with symlink members or traversal sequences to write files to arbitrary filesystem locations accessible to the process.