Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 27 min
Buscando: "Ui" — 865 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-92939] vm2 3.11.3 through 3.11.6 exposes the host Node.js crypto module to a NodeVM sandbox when the crypto…
vm2 3.11.3 through 3.11.6 exposes the host Node.js crypto module to a NodeVM sandbox when the crypto builtin is allowed. The module is presented via a recursive read-only proxy, but its callable exports still execute with host-process authority. Sandboxed JavaScript can therefore call crypto.setEngine() with a filesystem path to an attacker-supplied native library (for example, one bundled in an u…
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-92935] vm2 is a sandbox for running untrusted Node.js code. In versions >= 3.11.4 and <= 3.11.6, the NodeVM…
vm2 is a sandbox for running untrusted Node.js code. In versions >= 3.11.4 and
M Alto vulnerabilidad
17/09/2026
Control de acceso roto en WWBN AVideo permite manipulación de verificación de correo sin autenticación
WWBN AVideo contiene una vulnerabilidad alta de control de acceso en el script objects/userVerifyEmail.php que permite a atacantes invocar funciones de verificación de usuario sin estar autenticados, sin validación de tokens CSRF y sin verificar relación entre usuario y atacante. No existe parche disponible. Plataformas de video, portales educativos y sistemas de streaming en LATAM que usen esta versión están expuestos a ataques de suplantación de identidad y acceso no autorizado a cuentas.
M Crítico vulnerabilidad
17/09/2026
Vulnerabilidad crítica en rcourtman Pulse permite inyección de código remota
Se descubrió una falla de validación de entrada en rcourtman Pulse (versiones hasta 6.0.4 y 6.1.0-rc.4) en el componente Quick Security Setup Handler (/api/security/quick-setup). Un atacante remoto puede manipular el parámetro Username para ejecutar código arbitrario con CVSS 9.1. Afecta principalmente a servidores de autenticación y control de acceso en infraestructuras corporativas de México y LATAM.
M Crítico vulnerabilidad
17/09/2026
Vulnerabilidad crítica de inyección de comandos en appliances FatPipe MPVPN, WARP e IPVPN
Los equipos FatPipe MPVPN, WARP e IPVPN con firmware 10.1.2r60p100 (fin de vida) contienen una vulnerabilidad de inyección de comandos OS en el demonio xtremed. Un atacante remoto no autenticado puede enviar entrada manipulada al endpoint AuthFormServlet para ejecutar comandos arbitrarios en el sistema, afectando la integridad de infraestructuras VPN críticas en empresas latinoamericanas. El CVSS de 9.8 refleja el riesgo extremo sin requerir autenticación previa.
M Crítico vulnerabilidad
17/09/2026
Vulnerabilidad crítica en FatPipe MPVPN, WARP e IPVPN: desbordamiento de búfer remoto (CVE-2026-90823)
Los equipos FatPipe MPVPN, WARP e IPVPN con firmware 10.1.2r60p100 (fin de vida) contienen un desbordamiento de búfer en la interfaz de autenticación que permite ejecución remota de código sin credenciales. Un atacante puede enviar una solicitud manipulada contra la interfaz de gestión para comprometer completamente el dispositivo, poniendo en riesgo la conectividad WAN y acceso a datos corporativos en LATAM.
M Alto vulnerabilidad
17/09/2026
Vulnerabilidad alta de desbordamiento de búfer en Dell OpenManage Server Administrator
Dell OpenManage Server Administrator en versiones anteriores a 11.1.0.3 contiene una vulnerabilidad de desbordamiento de búfer en el montículo (heap-based buffer overflow) con puntuación CVSS 7.8. Un atacante con acceso local y privilegios bajos podría explotarla para elevar sus permisos en sistemas de gestión de servidores. Empresas en México y LATAM que usen esta solución para administración de infraestructura Dell requieren actualizar inmediatamente.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
17/09/2026
[CVE-2026-86320] A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources wit…
A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. An attacker who can provide a malicious source containing a Git post-applypatch hook can cause the hook to execute on the host during the build process, resulting in arbitrary code execution with the privileges of the user running flatpak-builder.
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-86709] The Pressengine WordPress plugin through 1.0 does not stop its login handler from issuing a session …
The Pressengine WordPress plugin through 1.0 does not stop its login handler from issuing a session when authentication fails, allowing unauthenticated attackers to log in as any user, including administrators.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-85128] The Choose User Role at Registration WordPress plugin before 1.3.3 does not validate the role reques…
The Choose User Role at Registration WordPress plugin before 1.3.3 does not validate the role requested at registration against the roles an administrator chose to offer, allowing unauthenticated users to request any role, including administrator, and to be granted it once the request is approved. Exploitation requires the Choose User Role at Registration WordPress plugin before 1.3.3's role selec…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92594] Craft CMS 5.0.0-RC1 through versions before 5.11.0 incorrectly authorize the GraphQL draftCreator an…
Craft CMS 5.0.0-RC1 through versions before 5.11.0 incorrectly authorize the GraphQL draftCreator and revisionCreator fields: instead of requiring the user-data scope enforced by Gql::canQueryUsers() (usergroups.*:read), these fields are gated only on the elements.drafts:read / elements.revisions:read scopes, and their resolver returns a raw User element whose email, username, fullName, and addres…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-85469] A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upst…
A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upstream `Noelware/docker-manifest-action` used in the release workflow, which is pinned to a mutable branch. This allows the attacker to inject arbitrary code, leading to the exfiltration of sensitive registry credentials or the publication of malicious images. The workflow also exposes the default Git…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-61594] djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered pe…
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the live (WebSocket) transport authorizes a mount via `check_view_auth`, not Django's `View.dispatch()` chain. As a result, standard Django authorization — `LoginRequiredMixin`, `PermissionRequiredMixin`, `UserPassesTestMixin`, `@method_decorator(login_required, na…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92816] ComfyUI before 0.30.0 fails to sanitize folder_name input in dataset save nodes, allowing attackers …
ComfyUI before 0.30.0 fails to sanitize folder_name input in dataset save nodes, allowing attackers to write files to arbitrary paths outside the output directory. Attackers can load a crafted workflow that writes attacker-controlled content to arbitrary locations, enabling code execution through modified startup files or package initializers.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92782] Chroma through 1.5.9 fails to validate tenant and database segments when resolving collections, allo…
Chroma through 1.5.9 fails to validate tenant and database segments when resolving collections, allowing authenticated attackers to access collections from other tenants by knowing the collection identifier. Attackers can read, modify, and update records in foreign collections by issuing requests under their own tenant path, bypassing authorization checks.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92776] Wiki.js through 2.5.314 fails to require path separators when matching START and END page rules, all…
Wiki.js through 2.5.314 fails to require path separators when matching START and END page rules, allowing attackers to access pages sharing a prefix with authorized folders. Users granted access to a folder can read and modify unrelated pages with matching prefixes, bypassing intended access controls.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92779] Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability…
Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the deep-set helper function that processes content block bindings without validation. Attackers can craft content blocks with binding keys containing __proto__, prototype, or constructor paths to pollute Object.prototype during rendering, affecting all subsequent objects created in the process …
M Alto vulnerabilidad
16/09/2026
[CVE-2026-20323] A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software and…
A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software and Cisco Secure FTD Software could allow an unauthenticated, adjacent attacker to impersonate the peer device and obtain access at the level of the&nbsp;manager role, which is equivalent to root. This vulnerability is due to improper management of the TLS certificate for the sftunnel management con…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-86003] CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-ove…
CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over-gRPC listeners in plugin/pkg/doh/doh.go, core/dnsserver/server_quic.go, and core/dnsserver/server_grpc.go call dns.Msg.Unpack without the dns.DefaultMsgAcceptFunc request policy used by UDP, TCP, and DNS-over-TLS. An unauthenticated client can send an RFC 2136 UPDATE that the pr…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-82399] CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-ove…
CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over-gRPC request paths in plugin/pkg/doh/doh.go, core/dnsserver/server_quic.go, and core/dnsserver/server_grpc.go call dns.Msg.Unpack on attacker-controlled DNS section counts before dns.DefaultMsgAcceptFunc validates the fixed header. An unauthenticated client can use DNS name comp…