Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-101008] A vulnerability was found in aaPanel BaoTa up to 11.8.0. Impacted is the function merge_split_file o…
A vulnerability was found in aaPanel BaoTa up to 11.8.0. Impacted is the function merge_split_file of the file /www/server/panel/class/files.py of the component File Merge Handler. Performing a manipulation of the argument split_file_path results in command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted ear…
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-101002] A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. Affected is the function …
A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. Affected is the function system of the file /usr/bin/network_tools of the component Tools Ping Handler. Performing a manipulation of the argument url results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early …
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-101000] A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.…
A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.apply of the file /usr/share/rpcd/acl.d/unauthenticated.json of the component ACL Handler. This manipulation of the argument section causes missing authorization. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted ear…
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-101001] A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This impacts the function eval…
A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This impacts the function eval of the file /www/cgi-bin/network_tools of the component Web Management Interface. Such manipulation of the argument QUERY_STRING leads to os command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about thi…
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-100896] A weakness has been identified in TOTOLINK N150RT 3.4.0-B20201030. The affected element is the funct…
A weakness has been identified in TOTOLINK N150RT 3.4.0-B20201030. The affected element is the function system of the file /boafrm/formWlSiteSurvey of the component Web Management Interface. This manipulation of the argument wlanif causes os command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
M Crítico vulnerabilidad
27/09/2026
[CVE-2026-100886] A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. …
A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. The affected element is an unknown function of the component Debug Service. Such manipulation leads to improper authentication. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any wa…
M Crítico vulnerabilidad
27/09/2026
[CVE-2026-101090] Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the ne…
Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional dashboard_host setting is empty, /api/v1/oauth2/{provider} (cmd/dashboard/controller/oauth2.go) reflects the attacker-supplied HTTP Host header into the redirect_uri sent to the identity provider instead of falling back to the configured install_host. An attacker who induces a victim to b…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
27/09/2026
[CVE-2026-101065] Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, th…
Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart command documented in the README starts the container listening on 0.0.0.0:8080 with authentication disabled by default. When authentication is disabled, every request is mapped to a synthetic "nobody" user that holds the Owner and Admin roles, so any unauthenticated party who ca…
M Crítico vulnerabilidad
27/09/2026
[CVE-2026-101084] obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allo…
obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID. Attackers can bypass authorization checks to access and manipulate sensitive backend systems through MCP tool calls using stored OAuth credentials.
M Crítico vulnerabilidad
27/09/2026
Inyección Eval crítica en hMailServer 6.0.0-6.3.3 permite ejecución remota de código
Una vulnerabilidad crítica (CVSS 9.8) en el despachador de scripts JScript de hMailServer permite a atacantes no autenticados ejecutar código arbitrario con privilegios de servicio. La falla se activa mediante contraseñas manipuladas con secuencias de escape en autenticación SMTP, POP3 e IMAP. Afecta principalmente a servidores de correo en Windows en organizaciones de México y LATAM que usen versiones 6.0.0 a 6.3.3.
M Crítico vulnerabilidad
27/09/2026
[CVE-2026-100721] vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an e…
vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an embedder configures `require.external` with a custom resolver (and `context: 'host'`), `LegacyResolver.customResolve` in lib/resolver-compat.js records the resolved module directory in `this.externals` as `new RegExp('^' + escapeRegExp(resolvedPath))`, without requiring a path separator or end-of-str…
M Crítico vulnerabilidad
27/09/2026
[CVE-2026-100740] A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_param…
A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_params of the file tunnel.c of the component L2TP Control Channel Parser. Performing a manipulation results in out-of-bounds write. The attack may be initiated remotely. The exploit is now public and may be used.
M Crítico vulnerabilidad
26/09/2026
[CVE-2026-82901] The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due …
The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the 'uacf7_wpcf7_mail_components' function in all versions up to, and including, 3.5.50. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: This is o…
M Crítico vulnerabilidad
26/09/2026
[CVE-2026-85984] The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to A…
The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via the mo_wp_login_intent parameter in all versions up to, and including, 5.5.5. This is due to a missing password-intent guard in the skip_pass_fallback-enabled configuration branch of the mo_by_pass_login() function, which treats administrator role membership alone as suffici…
M Crítico vulnerabilidad
26/09/2026
[CVE-2026-100714] Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlik…
Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlike sibling settings hardened in GHSA-33mp, the field has no string_regexp or required_otp guard, and its value is concatenated unescaped into the acme.sh command line built in lib/Froxlor/Cron/Http/LetsEncrypt/AcmeSh.php and executed by the root cron via FileDir::safe_exec. Because safe_exec only bla…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
26/09/2026
[CVE-2026-100715] Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP dat…
Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP data deletion cron task. Cron task 8 (deleteFtpData), queued when an FTP account is deleted, calls FileDir::makeCorrectDir() without the $fixed_homedir argument, so the symlink component walk is skipped, and then executes 'rm -rf' as root on the resulting path with string-level guards only. Because mak…
M Crítico vulnerabilidad
26/09/2026
[CVE-2026-100716] Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (…
Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fails to validate intermediate path components of the export destination: Froxlor\FileDir::makeCorrectDir() contains an off-by-one in its path-component walk that skips the first segment below the customer home directory, and the guard in ExportCron.php checks only the final component…
M Crítico vulnerabilidad
26/09/2026
[CVE-2026-100717] froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl reje…
froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return and line feed characters only in the path, query and fragment components returned by parse_url, and never inspects the userinfo (user:pass@) components. This is an incomplete fix for GHSA-c3p2. An authenticated low-privilege customer with subdomain-create rights (no admin or chan…
M Crítico vulnerabilidad
26/09/2026
[CVE-2026-100706] kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Policy apiCall urlPath…
kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Policy apiCall urlPath, allowing namespace tenants to bypass the per-namespace clamp and create objects in other namespaces as the admission-controller ServiceAccount. Attackers can exploit this by using percent-encoded directory traversal sequences to create MutatingWebhookConfiguration objects cluster-wide or PolicyExc…
M Crítico vulnerabilidad
26/09/2026
Vulnerabilidad crítica de carga arbitraria de archivos en plugin Request a Quote for WooCommerce
El plugin Request a Quote for WooCommerce para WordPress es vulnerable a carga arbitraria de archivos en versiones hasta la 2.9.2 debido a validación insuficiente de extensiones y tipos MIME en la función afrfq_submit_quote_via_popup(). Un atacante puede cargar archivos maliciosos (como shells PHP) directamente al servidor sin restricción, comprometiendo completamente sitios de comercio electrónico en LATAM. Con CVSS 9.8, afecta principalmente a pequeñas y medianas empresas que usan este plugin para gestionar cotizaciones de productos.