Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ui" — 3500 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-75699] Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injecti…
Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-75703] Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injecti…
Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-43641] Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerabil…
Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in the billing module handler that allows unauthenticated remote attackers to execute arbitrary commands as root by bypassing authentication through specific parameter combinations. Attackers can deserialize a crafted billing_data POST field and inject shell payloads through the uid field, which…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-43643] Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an authorization bypass vulnerabil…
Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an authorization bypass vulnerability in the billing module handler that allows unauthenticated remote attackers to modify any tenant's account balance by supplying crafted act and from_billing_module parameters to the admin panel dispatcher. Attackers can send a POST request with arbitrary uid and balance values in the billing_data…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-83603] Netdata is an open source observability tool. Prior to 2.10.4, the setuid-root ndsudo helper command…
Netdata is an open source observability tool. Prior to 2.10.4, the setuid-root ndsudo helper command fail2ban-client-status-socket in src/collectors/utils/ndsudo.c accepts a caller-controlled --socket_path from the low-privileged netdata service account. The account can direct root fail2ban-client to a malicious UNIX socket, and fail2ban/client/csocket.py CSocket.receive() passes the returned data…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-80148] Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmwa…
Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet listener that allows unauthenticated attackers to cause the affected device to establish SSH connections to attacker-controlled endpoints. The custom shellinaboxd builds its SSH connection target using …
M Alto vulnerabilidad
22/09/2026
[CVE-2026-75608] Frigate is an open source network video recorder. Prior to 0.18.0, the prefix-matched location /api/…
Frigate is an open source network video recorder. Prior to 0.18.0, the prefix-matched location /api/go2rtc/api in docker/main/rootfs/usr/local/nginx/conf/nginx.conf requires authentication but does not require an administrator role for GET requests, exposing the proxied go2rtc API to viewer users. An authenticated viewer can request the streams, config, log, and stack subpaths to obtain internal a…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
22/09/2026
[CVE-2026-89407] NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates "stringified numbers" wit…
NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates "stringified numbers" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2.17.2. PATTERN_FLOAT places adjacent quantifiers over the same character class -- an optional [0-9]* run, an optional dot, then a required [0-9]+ run -…
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-84388] A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Ext…
A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4 all versions may allow attacker to information disclosure via remote unauthenticated attack
M Alto vulnerabilidad
22/09/2026
[CVE-2026-75791] Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to an authenticat…
Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to an authentication bypass vulnerability in the REST API.
M Crítico vulnerabilidad
22/09/2026
Vulnerabilidad crítica de ejecución remota de código en Zohocorp ManageEngine ADSelfService Plus (CVE-2026-74849)
Zohocorp ManageEngine ADSelfService Plus en versiones anteriores a la build 7001 presenta una vulnerabilidad de ejecución remota de código (RCE) con CVSS 9.8 en el cliente GINA. Esta falla permite a atacantes ejecutar comandos arbitrarios sin autenticación previa, afectando principalmente a empresas en LATAM que utilizan esta solución para gestión de identidades y acceso en entornos Active Directory. El impacto es crítico en infraestructuras de TI medianas y grandes.
M Alto vulnerabilidad
22/09/2026
Inyección SQL ciega en HashBar WordPress Notification Bar (CVE-2026-94117)
Se detectó una vulnerabilidad alta de inyección SQL en el plugin HashBar para WordPress (versiones hasta 2.0.3) que permite a atacantes ejecutar consultas SQL no autorizadas contra bases de datos de sitios web. Esta vulnerabilidad afecta especialmente a pequeñas y medianas empresas en LATAM que utilizan WordPress con plugins de barras de notificación para campañas de marketing. Un atacante podría extraer datos sensibles, modificar registros o acceder a credenciales de administrador sin requiere autenticación previa.
M Alto vulnerabilidad
22/09/2026
Escalada de privilegios por configuración débil en manejo de archivos temporales (CVE-2026-25265)
Vulnerabilidad de severidad alta (CVSS 8.8) afecta múltiples productos debido a configuración insegura durante el manejo de archivos temporales, permitiendo a atacantes locales elevar privilegios. En entornos LATAM, esto impacta servidores con acceso multiusuario en empresas, proveedores de cloud y centros de datos. La explotación requiere acceso local pero compromete la integridad de sistemas altas.
M Alto vulnerabilidad
22/09/2026
Escalada de privilegios alta en servidores gRPC mediante función expuesta
Una función peligrosamente expuesta en servidores gRPC permite a atacantes escalar privilegios localmente (CVSS 8.8). Afecta múltiples proveedores y plataformas de microservicios comúnmente desplegadas en infraestructuras cloud de empresas latinoamericanas. Sin parches inmediatos, expone sistemas de APIs, orquestación de contenedores y aplicaciones distribuidas.
M Alto vulnerabilidad
22/09/2026
Desbordamiento de búfer en libslirp afecta hosts con DHCPv6 y TFTP
Se identificó un desbordamiento de búfer basado en heap en los constructores de respuesta DHCPv6 y TFTP de libslirp. Cuando el host está configurado con MTU pequeño, las opciones CLIENTID DHCPv6 o blksize TFTP suministradas por el guest pueden desbordar el búfer de respuesta con contenido controlado por atacante, resultando en negación de servicio y potencial ejecución remota de código en el proceso host. Esta vulnerabilidad afecta infraestructuras de virtualización en data centers y ambientes cloud en LATAM.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
22/09/2026
Vulnerabilidad alta de escalada de privilegios en CUPS y cups-filters
Se identificó una vulnerabilidad de escalada de privilegios (CVSS 8.2) en CUPS cuando se utiliza con el backend serial de cups-filters. Un usuario local miembro del grupo lpadmin puede configurar una impresora con backend serial privilegiado para escribir datos arbitrarios en cualquier archivo del sistema con permisos de root. Esta falla afecta especialmente a infraestructuras de impresión compartida en empresas medianas y grandes en México y Latinoamérica.
M Alto vulnerabilidad
22/09/2026
Vulnerabilidad alta de inclusión de archivos en plugin HUSKY Products Filter para WooCommerce
El plugin HUSKY – Products Filter for WooCommerce Professional para WordPress (versiones hasta 1.4.4) contiene una vulnerabilidad de Local File Inclusion (LFI) que permite a atacantes no autenticados ejecutar código PHP arbitrario en servidores. Esta falla afecta directamente a tiendas en línea de LATAM que usan este plugin, exponiendo bases de datos, credenciales y datos de clientes. Con CVSS 8.1, es considerada alta y requiere acción inmediata.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-87079] Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via quadratic insertion cost …
Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via quadratic insertion cost when decoding a long label in decode_punycode. The XS backend inserts each decoded code point into a UTF-8 buffer and finds the insertion point by scanning that buffer from the start, one character at a time. The scan runs once per code point over the output built so far, so the cost is quadratic i…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-6922] The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to Incorrect Aut…
The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.2.1. This is due to an operator precedence bug in the post-type guard within the trash_table_bulk() and restore_table_bulk() functions that causes the guard to never fire, combined with a permission callback that only verifies plugin role membership…
M Alto vulnerabilidad
22/09/2026
[CVE-2025-1281] The BM Content Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insuffic…
The BM Content Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ux_cb_remove_layout_ajax() and ux_cb_tools_export_ajax() functions in all versions up to, and excluding, 3.17.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can easily lead…