Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
14,403
Total alertas
3281
Críticas
10814
Altas
8
Ransomware
1046
Esta semana
RSS
M Alto vulnerabilidad
30/07/2026
[CVE-2026-61536] Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3,…
Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3, banks parses Tool JSON objects from the rendered body of {% completion %} blocks and later resolves their import_path field through importlib.import_module(...) + getattr(...) to obtain the callable that handles a tool call. There is no allowlist or sanitization on import_path, so any importable Py…
M Alto vulnerabilidad
30/07/2026
[CVE-2026-18140] Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62…
Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the smithy-rs code generator invokes from every generated struct deserializer, might allow remote unauthenticated users to cause a denial of service (process abort via stack exhaustion) via a single small HTTP request containing deeply nested JSON to a smithy-rs generated server. To rem…
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-18245] Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allo…
Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authenticated user to execute arbitrary code in end-user browsers, developer machines, CI/CD environments, and server-side rendering contexts via crafted Studio component or theme schema values due to insufficient coverage and effectiveness of the input validation introduced for CVE-2025-…
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-15969] SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickle…
SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary command execution through crafted base64-encoded pickle payloads.
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-15971] SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a s…
SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when DUMPER_SERVER_PORT is set, enabling code execution on inference requests.
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-15976] SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace reposit…
SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the /update_weights_from_disk, where torch.load(..., weights_only=False) fallback enables pickle deserialization of .bin files.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-15977] SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return A…
SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SSL keyfile information when only the --admin-api-key is configured.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
30/07/2026
[CVE-2026-15978] SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang…
SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two endpoints that allow a remote attacker to trigger distributed weight broadcasting using NCCL and then triggering data transfer, attackers can exfiltrate all model weights.
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-13435] IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the Pyt…
IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-13444] IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's private vector …
IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's private vector documents by creating their own flow with matching Chroma persist_directory and collection_name values. The attacker receives exact victim content in their workflow output despite having no authorization to read the victim's flow. Additionally, the attacker can pollute the victim's collection by ins…
M Alto vulnerabilidad
30/07/2026
[CVE-2026-12942] IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the s…
IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to view arbitrary files on the system.
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-12943] IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management sys…
IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink) could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-12118] IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to …
IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-12733] IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper res…
IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-10535] IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid …
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
30/07/2026
[CVE-2026-10545] IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an a…
IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an attacker to redirect users to arbitrary external websites via a crafted URL. If used in SSO authentication flows, this could result in exposure of session tokens and allow attackers to hijack user sessions.
M Alto vulnerabilidad
30/07/2026
[CVE-2024-25039] IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6…
IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the web server to become unresponsive.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-9322] IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.…
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-62663] Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4,…
Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4, all four media filters (image, audio, video, document) in banks accept untrusted user input as file paths via Path(value) and pass them directly to open(file_path, "rb") without any path sanitization, canonicalization, or directory restriction. An attacker who controls template variables passed to …
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-12940] IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via e…
IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability exists in src/lfx/src/lfx/base/mcp/util.py where the DANGEROUS_ENV_VARS blocklist fails to include SHELLOPTS , BASHOPTS , and PS4 environment variables.