Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
Buscando: "Linux" — 1677 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
25/08/2026
[CVE-2026-65098] NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an at…
NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.
M Alto vulnerabilidad
25/08/2026
Vulnerabilidad alta de inyección de comandos en NVIDIA NemoClaw para Linux (CVE-2026-65099)
NVIDIA NemoClaw para Linux contiene una vulnerabilidad en su interfaz de línea de comandos que permite inyección de comandos del sistema operativo. Un atacante podría explotar esta falla para ejecutar código arbitrario, modificar datos, acceder a información confidencial o provocar denegación de servicio. Afecta principalmente a servidores y estaciones de trabajo con GPU NVIDIA en entornos de desarrollo e IA.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-65105] NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote att…
NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the inference service without authentication. A successful exploit of this vulnerability may lead to information disclosure and denial of service.
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-65083] NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attack…
NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, data tampering, and denial of service.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-65084] NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker coul…
NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, code execution, and escalation of privileges.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-65089] NVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin commands, where an …
NVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin commands, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-65090] NVIDIA NemoClaw for Linux contains a vulnerability in its NIM management component, where an attacke…
NVIDIA NemoClaw for Linux contains a vulnerability in its NIM management component, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
25/08/2026
[CVE-2026-65081] NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker co…
NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution of untrusted code. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, information disclosure, and denial of service.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-65082] NVIDIA NemoClaw for Linux contains a vulnerability in its migration command, where a local attacker …
NVIDIA NemoClaw for Linux contains a vulnerability in its migration command, where a local attacker could cause code injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-66152] A Path traversal vulnerability in OPSWAT tarball in the SonicWall NetExtender Linux client allows an…
A Path traversal vulnerability in OPSWAT tarball in the SonicWall NetExtender Linux client allows an attacker to write arbitrary file as root.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-66153] The NEService auto-upgrade process insecurely handles temporary files in SonicWall NetExtender Linux…
The NEService auto-upgrade process insecurely handles temporary files in SonicWall NetExtender Linux client which allows an attacker to manipulate file paths.
M Alto vulnerabilidad
25/08/2026
Omisión de autenticación en LACT por fallo en validación de PID en Polkit
LACT versiones hasta 0.10.0 presenta una vulnerabilidad de omisión de autenticación en Linux que permite a atacantes locales eludir controles de Polkit mediante manipulación del proceso UnixProcessSubject. Esta falla afecta sistemas que utilizan LACT para gestión de GPU AMD, poniendo en riesgo servidores en centros de datos y estaciones de trabajo en LATAM.
M Alto vulnerabilidad
24/08/2026
[CVE-2026-78414] Cross-site scripting in the Web Administration interface of Network Optix Nx Witness VMS before vers…
Cross-site scripting in the Web Administration interface of Network Optix Nx Witness VMS before version 6.1.3 on Linux, Windows and MacOS allows an adjacent-network attacker to execute arbitrary JavaScript in the browser of an authenticated administrator and steal the administrator's session token, resulting in Administrator Account Takeover. An attacker who controls an Nx server on the same netwo…
M Alto vulnerabilidad
21/08/2026
[CVE-2026-62316] Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior t…
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, ufo/client/mcp/http_servers/linux_mcp_server.py binds a FastMCP streamable HTTP server to localhost:8010 but does not validate the Host, Origin, or Sec-Fetch-Site headers. An attacker-controlled web page can use DNS rebinding to reach the local /mcp endpoint, enumerate tool schemas through …
M Alto vulnerabilidad
21/08/2026
[CVE-2026-63046] Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in …
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache InLong. Agent Installer's ModuleManager executes arbitrary shell commands via ExcuteLinux.exeCmd() with no filtering or whitelist validation. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1]/[2] to solve …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
20/08/2026
Control de acceso roto sin autenticación en Koji versiones <= 2.2.1
Se ha identificado una vulnerabilidad de control de acceso quebrantado en Koji
M Alto vulnerabilidad
19/08/2026
[CVE-2026-44829] Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, filename handling …
Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, filename handling in pkg/modules/api/context.go uses filepath.Base on Linux, which does not treat backslashes as path separators, so a multipart filename containing Windows-style parent directory components survives sanitization. The original filename flows through ctx.diskToOriginal and the multi-output PDF routes i…
M Alto vulnerabilidad
19/08/2026
Vulnerabilidad alta en semctl(2) permite acceso no autorizado a semáforos del sistema
Una falla en los comandos GETALL y SETALL de semctl(2) permite que atacantes locales manipulen semáforos del kernel entre ciclos de creación/destrucción, explotando un desbordamiento de secuencia tras 0x8000 operaciones. Afecta sistemas Unix/Linux en producción que ejecutan aplicaciones multi-proceso con semáforos del sistema operativo, comprometiendo la integridad de sincronización en bases de datos y middleware alta.
M Alto vulnerabilidad
19/08/2026
Vulnerabilidad alta en código de volcado de núcleo ELF permite escritura de memoria fuera de límites
Una vulnerabilidad en el procesamiento de volcados de núcleo ELF (CVE-2026-58088, CVSS 7.4) permite que procesos no privilegiados que compartan espacio de direcciones mediante rfork(2) causen desbordamientos de búfer al mutar mapas de memoria entre dos pasadas de iteración. Afecta principalmente a sistemas Unix/Linux en servidores y estaciones de trabajo en LATAM donde se ejecutan aplicaciones con multiprocessing.
M Alto vulnerabilidad
18/08/2026
[CVE-2026-55426] linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integ…
linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses those modules to run external monitoring commands. From the earliest affected releases until linuxfabrik-lib 5.0.0 and Linuxfabrik Monitoring Plugins 6.0.0, check plugins embedded user-controlled values in command strings passed to lib.shell.shell_exe…