Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 15 min
Buscando: "X" — 4173 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-88869] AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scriptin…
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the AD_Server plugin's log.php endpoint that fails to escape the label parameter before storage. An unauthenticated attacker can inject malicious HTML through the label parameter, which is later rendered unsanitized in the admin Ad Types report using jQuery .html(), allowing execu…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88868] AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scriptin…
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LiveLinks plugin where title and description fields are stored without sanitization. A user with canStream permission can inject malicious scripts that execute in the browser of every visitor viewing the live-link page, including administrators, within the site origin.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-88864] Capgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed th…
Capgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed through Supabase PostgREST. A holder of an ordinary Capgo full API key can insert a row with status='active' and enforce_sso=true, bypassing the intended backend SSO provisioning route (supabase/functions/_backend/private/sso/providers.ts) and its controls: the Enterprise plan requirement, SSO provide…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88865] AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate restream ownership …
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate restream ownership in getRestream.json.php, allowing authenticated users with canStream permission to mint tokens for arbitrary restreams. Attackers can exchange the token to retrieve other users' stream keys from getLiveKey.json.php and publish to their YouTube, Twitch, or RTMP destinations.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88866] WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scr…
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to encode the User-Agent header before storing it in login history. Attackers with any valid login account can inject malicious scripts in the User-Agent header that execute in administrator browsers when viewing the Login History page, allo…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88861] Capgo (Cap-go/capgo.app) contains an authentication bypass affecting all versions (no patched versio…
Capgo (Cap-go/capgo.app) contains an authentication bypass affecting all versions (no patched version available at time of publication). The Edge authorization path allows a password-only Supabase aal1 session to exercise privileged RBAC permissions even when the account has a verified MFA factor that has not been used for the session: the Edge JWT middleware (foundJWT() in supabase/functions/_bac…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88862] Capgo (capgo.app) backend through 12.242.4 does not validate parent-child delegation when processing…
Capgo (capgo.app) backend through 12.242.4 does not validate parent-child delegation when processing the x-limited-key-id header. checkKeyByIdPg() in supabase/functions/_backend/utils/hono_middleware.ts resolves the attacker-supplied numeric API key ID using only the key ID, its expiration state, and the authenticating key's user_id, while hasLimitedRbacSubkeyScope() accepts any key with a non-org…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
10/09/2026
[CVE-2026-85217] A maliciously crafted add-in, when installed and executed in Autodesk Fusion Desktop, can modify per…
A maliciously crafted add-in, when installed and executed in Autodesk Fusion Desktop, can modify persistent network proxy settings without user notification or consent. A successful exploit may allow an attacker to redirect authenticated Fusion network traffic through an attacker-controlled proxy, potentially exposing sensitive information with the current user.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-6285] Weak Password Recovery Mechanism for Forgotten Password vulnerability in Ankaref Innovation and Tech…
Weak Password Recovery Mechanism for Forgotten Password vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Password Recovery Exploitation. This issue affects LIBRID/LIBREF: from 2.01.0.2183 through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-64837] ICEcoder through 8.1 passes an unescaped filesystem path into a shell command in lib/properties.php,…
ICEcoder through 8.1 passes an unescaped filesystem path into a shell command in lib/properties.php, allowing authenticated users to inject OS commands through directory names. Attackers can create directories with shell metacharacters in their names and access the Properties function to execute arbitrary commands as the web-server user via popen().
M Alto vulnerabilidad
10/09/2026
Vulnerabilidad alta en ESP32-audioI2S 3.4.4-4.0.0: lectura fuera de límites en procesamiento ID3
ESP32-audioI2S versiones 3.4.4 a 4.0.0 contienen una vulnerabilidad de lectura fuera de límites en la función read_ID3_Header durante procesamiento de etiquetas ID3 sincronizadas. Atacantes pueden crear archivos MP3 maliciosos o flujos de audio HTTP con declaraciones de tamaño de fotograma exageradas, causando caídas del dispositivo o exposición de memoria adyacente. Afecta principalmente a sistemas IoT, dispositivos embebidos y aplicaciones de streaming de audio en infraestructuras empresariales LATAM.
M Alto vulnerabilidad
10/09/2026
Vulnerabilidad de denegación de servicio en t-digest 3.1-3.3 (CVE-2026-87962)
t-digest versiones 3.1 a 3.3 contienen una vulnerabilidad de denegación de servicio en MergingDigest.fromBytes que no valida campos de longitud y capacidad en datos serializados. Atacantes pueden enviar digests serializados manipulados para provocar excepciones ArrayIndexOutOfBoundsException o NegativeArraySizeException, abortando el hilo de procesamiento. Afecta aplicaciones que usan t-digest para compresión de datos o análisis de distribuciones en sistemas altas.
M Alto vulnerabilidad
10/09/2026
Vulnerabilidad de omisión de autorización en Countly Server DBViewer (CVE-2026-87803)
Existe una vulnerabilidad de bypass de autorización en el componente DBViewer de Countly Server que permite a atacantes eludir controles de acceso mediante manipulación de JSON en el endpoint /o/db. El fallo reside en la detección deficiente de sub-pipelines en el sanitizador de etapas de agregación. Empresas en LATAM que usan Countly para analytics están expuestas a acceso no autorizado a bases de datos sensibles (CVSS 7.1).