Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1055
Esta semana
RSS
M Alto vulnerabilidad
11/09/2026
[CVE-2026-68497] jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGrego…
jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLDeserializers.Std._deserialize. These deserializers are registered by default with no opt-in, so a plain ObjectMapper or JsonMapper with no polymorphic typing and n…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-8301] Improper neutralization of special elements used in an OS command ('OS command injection') vulnerabi…
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Boot Repair allows OS Command Injection. This issue affects Pardus Boot Repair: before 1.0.8.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-8303] Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Instit…
Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-software allows Privilege Escalation. This issue affects Pardus-software: before 1.0.5.
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-89009] WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticat…
WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated arbitrary file write vulnerability that allows remote attackers to overwrite any file on the device by sending a crafted payload to the sync_server daemon on TCP port 13136. The daemon, which runs as root and requires no authentication, accepts a 100-byte filename field in its protocol header wit…
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-89010] WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticat…
WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted filenames to the sync_server daemon on TCP port 13136. The daemon interpolates attacker-controlled filename input containing shell metacharacters into a shell command string vi…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-82578] When XML batch processing is turned on and the XPath option is selected, the raw batch input goes th…
When XML batch processing is turned on and the XPath option is selected, the raw batch input goes through a default XPath/JAXP setup with no entity restrictions, so XXE injection can allow data exfiltration and denial-of-service attacks.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-82583] NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an authenticated user to execute ar…
NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an authenticated user to execute arbitrary SQL through a Database Connector API, which could result in disclosure of stored credentials for connected systems, arbitrary file write, and a denial-of-service condition.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
11/09/2026
[CVE-2026-87020] An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds w…
An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc DICOM Server decodes an attacker-supplied PNG.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-78224] The XSLT Transformer Step builds a bare TransformerFactory without the proper security options set, …
The XSLT Transformer Step builds a bare TransformerFactory without the proper security options set, so XXE injection can allow data exfiltration and denial-of-service attacks.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-38056] A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmwar…
A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0. The iQ200 is a rackmount satellite modem deployed across oil and gas, maritime, defense, and remote infrastructure as the primary, and often sole communications link for offshore rigs, vessels, and remote sites. Important context: the device ships from the factory with a pre-configured l…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-38058] The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, i…
The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for the root SSH and web administration accounts. Any user with valid web credentials can extract these hashes and crack them offline using commodity hardware.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-89212] A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references we…
A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references were improperly restricted during XML-to-JSON processing. The issue affects Akana versions 2026.1, 2025.1.1, and all versions before 2024.1.6 (including older unsupported versions of Akana) and has been fixed as a security patch in the latest release of supported versions.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-71416] Headroom compresses data before the data reaches a large language model. Prior to version 0.35.0, th…
Headroom compresses data before the data reaches a large language model. Prior to version 0.35.0, the Headroom WebSocket server does not validate the `Origin` header of incoming client WebSocket requests before forwarding the request to the upstream server, allowing malicious WebSocket clients to perform arbitrary LLM requests without authentication. This can be exploited by a malicious WebSocket …
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-71644] An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef12345678…
An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause unsafe trajectory planning and potential UAV collisions via a missing default case in the FSM that stops publishing swarm trajectories when the drone enters IDLE
M Alto vulnerabilidad
11/09/2026
[CVE-2026-57842] NetBSD contains a use-after-free and double-free vulnerability in msg_recv_copyin() within the COMPA…
NetBSD contains a use-after-free and double-free vulnerability in msg_recv_copyin() within the COMPAT_NETBSD32 compatibility layer due to a missing return statement before the cleanup label on the success path. Any local user able to execute a 32-bit binary on a 64-bit NetBSD system can trigger a kernel panic or memory corruption by calling recvmsg() with msg_iovlen between 9 and IOV_MAX, causing …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-80462] A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthent…
A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions.
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-84390] A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.…
A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through 7.2.2 may allow attacker to improper access control via
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad XSS almacenado alta en AVideo plugin Bookmark (CVE-2026-89256)
AVideo contiene una vulnerabilidad de cross-site scripting (XSS) almacenado en el plugin Bookmark que permite a propietarios de videos inyectar código malicioso a través del parámetro de nombre de capítulo. Los nombres de capítulos no se codifican antes de insertarse en el HTML de la página pública, causando que todo visitante ejecute el payload en el origen de AVideo. Con CVSS 8.7, afecta plataformas de streaming y repositorios de video frecuentes en empresas e instituciones educativas de LATAM.
M Crítico vulnerabilidad
11/09/2026
Vulnerabilidad crítica en Hugo v0.161.0+ permite ejecución de código mediante TailwindCSS
Hugo, generador de sitios estáticos, ejecuta herramientas Node con permisos insuficientemente restringidos desde la versión 0.161.0. TailwindCSS, incluido en la lista de seguridad por defecto, requiere configuraciones altamente permisivas (--allow-addons, --allow-child-process, --allow-worker) que permiten eludir controles de seguridad previos. Esto afecta a empresas en LATAM que alojan sitios web con Hugo y utilizan TailwindCSS para compilación de estilos.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad alta de lectura de archivos sin autenticación en WWBN AVideo (CVE-2026-89250)
WWBN AVideo contiene una vulnerabilidad de lectura de archivos sin autenticación en el endpoint getRecordedFile.php que expone archivos de video grabados en FLV desde el directorio temporal. Atacantes pueden descargar archivos de video en vivo sin validación de autenticación utilizando claves de stream conocidas o adivinadas. Este riesgo afecta principalmente a plataformas de streaming y educación en línea en LATAM que utilizan esta solución para transmisiones en vivo.