Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 min
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1012
Esta semana
RSS
M Alto vulnerabilidad
10/09/2026
Vulnerabilidad alta en GeoVision GV-LPC2211 V1.13 permite escalada de privilegios
La cámara IP GeoVision GV-LPC2211 versión 1.13 contiene una vulnerabilidad que permite a usuarios invitados sobrescribir la configuración del dispositivo y reemplazar la contraseña del administrador a través del servicio SSVR. Esta falla afecta directamente a sistemas de videovigilancia desplegados en México y Latinoamérica, poniendo en riesgo el acceso no autorizado a infraestructura alta de seguridad física.
M Alto vulnerabilidad
10/09/2026
Vulnerabilidad alta en GeoVision GV-LPC2211 V1.13 permite ejecución de comandos como root
La cámara GeoVision GV-LPC2211 versión 1.13 permite a administradores inyectar metacaracteres de shell en nombres de usuario que se ejecutan con privilegios root al eliminar la cuenta. Esta vulnerabilidad afecta principalmente sistemas de vigilancia en infraestructuras altas, retail y datos centers en LATAM. El impacto es alta: compromiso total del dispositivo y potencial lateral movement en redes corporativas.
M Alto vulnerabilidad
10/09/2026
Vulnerabilidad alta en GeoVision GV-LPC2211 V1.13 permite ejecución de comandos como root
La cámara IP GeoVision GV-LPC2211 versión 1.13 contiene una vulnerabilidad de escape de shell que permite a administradores ejecutar comandos arbitrarios con privilegios root a través del campo de usuario PPPoE. Esta falla afecta principalmente a sistemas de videovigilancia en LATAM, donde estos dispositivos son comúnmente desplegados en infraestructuras altas, puntos de venta y centros de datos.
M Alto vulnerabilidad
10/09/2026
CVE-2026-88274: Ejecución remota de comandos en cámaras GeoVision GV-LPC2211 V1.13
La cámara GeoVision GV-LPC2211 versión 1.13 contiene una vulnerabilidad que permite a administradores ejecutar comandos arbitrarios con privilegios de root mediante configuración maliciosa del SSID inalámbrico. Esta falla afecta sistemas de videovigilancia en infraestructuras altas, hospitales y centros financieros en LATAM. Un atacante con acceso administrativo puede comprometer completamente el dispositivo y la red corporativa.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88275] GeoVision GV-LPC2211 V1.13 allows an administrator-controlled WPA-PSK containing shell syntax to exe…
GeoVision GV-LPC2211 V1.13 allows an administrator-controlled WPA-PSK containing shell syntax to execute arbitrary commands as root when wireless configuration is applied.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88276] GeoVision GV-LPC2211 V1.13 allows administrator-controlled WEP key values containing shell syntax to…
GeoVision GV-LPC2211 V1.13 allows administrator-controlled WEP key values containing shell syntax to execute arbitrary commands as root.
M Alto vulnerabilidad
10/09/2026
Vulnerabilidad alta en cámaras GeoVision GV-LPC2211: inyección de comandos shell
GeoVision GV-LPC2211 versión 1.13 contiene una vulnerabilidad que permite a usuarios ONVIF autenticados inyectar comandos shell a través del parámetro ConsumerReference.Address, resultando en ejecución de código arbitrario con permisos root. Afecta sistemas de vigilancia en infraestructuras altas, acceso remoto corporativo y centros de datos en LATAM.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
10/09/2026
[CVE-2026-84042] A flaw was found in crun. When crun is built with libkrun and a container is started rootful with pa…
A flaw was found in crun. When crun is built with libkrun and a container is started rootful with passt networking (krun.use_passt), crun can execute attacker-controlled payload from the container image with host root privileges. The issue is a regression in crun 1.29. It affects crun >= 1.29
M Alto vulnerabilidad
10/09/2026
[CVE-2026-42805] A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI385 SensorAPI (C librar…
A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI385 SensorAPI (C library) within the debug message parser function bhi385_parse_debug_message (located in bhi385_parse.c). The function parses FIFO events and extracts an 8-bit message length directly from the attacker-controlled event payload (callback_info->data_ptr[0]) without enforcing bounds checks or clamping th…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-42807] A heap-based buffer overflow vulnerability in the PC bridge protocol decoder of BoschSensortec COINE…
A heap-based buffer overflow vulnerability in the PC bridge protocol decoder of BoschSensortec COINES_SDK (versions 2.10 through 2.12.2) allows attackers to cause a denial of service (process crash) or potentially execute arbitrary code. The bridge decoder ({{bridge_decoder.c}}) trusts the packet length field provided by the external device and forwards it to the host response queue ({{mqueue_…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-42804] A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI360 SensorAPI(C-Library…
A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI360 SensorAPI(C-Library) in versions up to and including commit d6b200416a. The vulnerability is located within the FIFO parsing and debug logging subsystem inside the function bhi360_parse_debug_message() in bhi360_parse.c (lines 1852-1875). The parser trusts the first payload byte of a debug frame as the message …
M Alto vulnerabilidad
10/09/2026
[CVE-2026-80354] Authorization bypass through User-Controlled key vulnerability in Apache Camel K. An authorizatio…
Authorization bypass through User-Controlled key vulnerability in Apache Camel K. An authorization vulnerability in custom resource resolution allows a tenant to reference secrets by name in the operator namespace, potentially exposing secrets belonging to other tenants or operator components. This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 2.10.1 before 2.10.2. Users are…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-77771] The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does…
The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not scope its second-factor attempt limit to the account being attacked, keying it instead to an identifier the client supplies and can change at will, allowing an attacker who already knows a victim's password to make unlimited one-time-passcode guesses and defeat the second factor. A second valid…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81431] The Registration Form for WooCommerce WordPress plugin before 1.1.3 does not validate that the form …
The Registration Form for WooCommerce WordPress plugin before 1.1.3 does not validate that the form referenced during registration is a legitimate registration form, reading the permitted-role allow-list from an arbitrary attacker-controlled post instead. A user able to create a post (Contributor and above) can therefore register a new account with an arbitrary role, including Administrator, leadi…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-82925] The Site Reviews WordPress plugin before 8.3.0 does not prevent request data from being deserialized…
The Site Reviews WordPress plugin before 8.3.0 does not prevent request data from being deserialized, and derives the key protecting that data by padding out the site's WordPress nonce key, which makes the key publicly computable on installs where that key is absent, left at its sample value, or too short to be secret. This allows unauthenticated users to inject arbitrary PHP objects on such insta…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
10/09/2026
[CVE-2026-19436] The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not reconcile the value …
The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not reconcile the value of the gift card coupon it issues against the amount actually collected at checkout, allowing unauthenticated users to obtain store credit worth more than they paid.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-19439] The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not have any authorisati…
The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not have any authorisation check when displaying gift card details, allowing unauthenticated users to retrieve the gift cards attached to arbitrary orders and disclose customer personal data, balances, dates and, in 3.2.9, the live redemption code, which anyone holding it can spend. Versions from 3.0.3 to 3.2.8 disclose t…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-82079] A stack-based buffer overflow vulnerability in the Nintendo Switch local wireless networking functio…
A stack-based buffer overflow vulnerability in the Nintendo Switch local wireless networking functionality may allow an attacker within wireless range to execute arbitrary code using return-oriented programming (ROP) through crafted network traffic. This issue affects Nintendo Switch: before 23.0.0.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-49363] An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node detai…
An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node details by sending a SUBSCRIBE_TOPOLOGY request prior to authentication. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-49362] An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leadin…
An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leading to unauthorized broker state manipulation and potential denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.