Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 3 horas
14,928
Total alertas
3375
Críticas
11165
Altas
8
Ransomware
865
Esta semana
RSS
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-18717] ASE2000 2.35 through 2.37 is vulnerable to an improper certificate validation vulnerability, which m…
ASE2000 2.35 through 2.37 is vulnerable to an improper certificate validation vulnerability, which may allow an attacker to impersonate the trusted peer, complete the TLS handshake, and read or modify protected communications.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-18965] PayRange API is missing proper authorization on management endpoints, which allows verbose details o…
PayRange API is missing proper authorization on management endpoints, which allows verbose details of every device on the PayRange network to be publicly accessible, with or without an account.
M Alto vulnerabilidad
Hace 6 días
[CVE-2025-30156] Ceph is an open-source distributed storage platform providing object, block, and file storage. In ve…
Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the CephX authentication protocol encrypts tickets with AES-128-CBC in an unauthenticated mode that uses a hard-coded initialization vector and no message authentication, allowing an attacker to forge credentials and gain cluster-wide access. Because the ciphertext…
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-81838] A relative path traversal issue in the zip extraction functionality in AWS diagram-as-code (awsdac) …
A relative path traversal issue in the zip extraction functionality in AWS diagram-as-code (awsdac) in versions 0.10 through 0.23 can allow a third party to write arbitrary files to the local filesystem via crafted zip entry names containing path traversal sequences. This could allow the third party to perform inappropriate actions in the diagram bundle. To remediate this issue, users should up…
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-81728] Dolibarr before 24.0.0 contains a SQL injection in its CSV and XLSX import wizard. The wizard reads …
Dolibarr before 24.0.0 contains a SQL injection in its CSV and XLSX import wizard. The wizard reads its update keys with GETPOST('updatekeys', 'array') in htdocs/imports/import.php, which applies only the generic alphanohtml filter: that strips HTML but leaves SQL keywords, comment markers, parentheses, spaces and quotes intact. import_insert() in htdocs/core/modules/import/import_csv.modules.php …
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-81730] Dolibarr 9.0.0 through 23.0.4 saves inbound email attachments under the name supplied in the message…
Dolibarr 9.0.0 through 23.0.4 saves inbound email attachments under the name supplied in the message's MIME headers without reducing it to a safe basename. The global saveAttachment() in htdocs/emailcollector/lib/emailcollector.lib.php builds $filepath = $path . $filename . '.' . $ext and hands it to file_put_contents(), and the private saveAttachment() in htdocs/emailcollector/class/emailcollecto…
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-81529] Improper neutralization of delimiters in connection-URL construction allows connection-option inject…
Improper neutralization of delimiters in connection-URL construction allows connection-option injection in the MongoDB C# Driver. When an application passes untrusted text into the driver's connection-URL builder and round-trips the builder back into a client configuration, the untrusted text is serialized without neutralizing the URL/option delimiters and is then re-parsed as authoritative connec…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-81522] A weakness in the MongoDB C++ Driver's handling of caller-supplied namespace identifiers allows spec…
A weakness in the MongoDB C++ Driver's handling of caller-supplied namespace identifiers allows special characters embedded in those identifiers. An application that builds a namespace identifier from untrusted input without validating it may therefore have its operation directed at a different target than intended. This can result in limited unauthorized read and write access to data belonging to…
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-81525] The MongoDB client library for PHP does not sufficiently sanitize special elements in application-su…
The MongoDB client library for PHP does not sufficiently sanitize special elements in application-supplied namespace identifiers before using them to construct the target namespace for database operations. An application that incorporates untrusted text into these identifiers may have operations silently directed at a different storage location than the one the application intended.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-77438] Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.10…
Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the public share-search endpoint does not enforce the per-note shareCredentials and shareHiddenFromTree controls, allowing an unauthenticated visitor to read the titles, tree paths, and content of protected shared notes. The endpoint authorizes only the ancestor note supplied in the request and…
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-76639] Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerabilit…
Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerability that allows network-adjacent attackers to execute arbitrary commands as root by chaining three weaknesses: an unauthenticated WebRTC-to-DDS bridge on TCP port 9991, a static AES-128 key stored with world-readable permissions, and a path traversal flaw in the chat_go knowledge upload API. Attackers…
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-76640] Unitree G1 EDU firmware through 1.5.2 contains multiple chained vulnerabilities in the BLE GATT serv…
Unitree G1 EDU firmware through 1.5.2 contains multiple chained vulnerabilities in the BLE GATT server and WiFi provisioning stack that allow unauthenticated proximate attackers to achieve root code execution without pairing or credentials by exploiting an unquoted heredoc variable in the WiFi provisioning script and a buffer overflow in the SSID chunk accumulator. Attackers can send crafted BLE w…
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-75889] Grafana Alloy’s prometheus.operator.servicemonitors component allows a user who can create or modify…
Grafana Alloy’s prometheus.operator.servicemonitors component allows a user who can create or modify ServiceMonitor resources in a watched namespace to specify an arbitrary local file through bearerTokenFile. Alloy reads the file and sends its contents as a bearer token to an attacker-controlled scrape endpoint. This may disclose files accessible to the Alloy process, including its projected Kuber…
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-59324] When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emit…
When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads, concurrent requests on the same FluxMessageChannel subscription have their reply headers (replyChannel, errorChannel, correlationId, any propagated security/tenant headers) copied from whichever message was most recently consumed upstream. Spring Integration 7.1.0 Spring Integration …
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-59307] An operator who calls JdbcMessageStore.addAllowedPatterns(...) to restrict deserialization receives …
An operator who calls JdbcMessageStore.addAllowedPatterns(...) to restrict deserialization receives no protection at all when the store is a Spring-managed bean. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-59316] Spring Authorization Server's default consent page renders user-controlled values without HTML entit…
Spring Authorization Server's default consent page renders user-controlled values without HTML entity encoding. When using the DefaultConsentPage, an attacker can craft an OAuth2 authorization request containing a malicious value that is stored server-side and later rendered unencoded in the default consent page presented to the end user. Spring Authorization Server 1.5.0 - 1.5.8 Spring Authorizat…
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-59284] There is no allow list for property keys when Spring Cloud Commons writable /actuator/env is enabled…
There is no allow list for property keys when Spring Cloud Commons writable /actuator/env is enabled. Spring Cloud Commons 5.0.0 - 5.0.2 Spring Cloud Commons 4.3.0 - 4.3.3 Spring Cloud Commons 4.0.0 - 4.2.6 Spring Cloud Commons 3.1.10 and earlier
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-53580] Trilium is an open-source hierarchical note-taking application. In versions prior to 0.104.0, the au…
Trilium is an open-source hierarchical note-taking application. In versions prior to 0.104.0, the automatic image-download feature accepts file:// URLs in a note's img tags and reads the referenced local file with no path validation, allowing any authenticated user to disclose arbitrary files readable by the Trilium process. When a text note is saved, Trilium scans its HTML for image sources and d…
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-54718] Silverstripe Advanced Workflow is a highly configurable step-based workflow module. Prior to 6.4.5, …
Silverstripe Advanced Workflow is a highly configurable step-based workflow module. Prior to 6.4.5, 7.1.3, and 7.2.1, an attacker with permission to author the advanced workflow email template can place a specially crafted server-side template payload in NotifyUsersWorkflowAction.EmailTemplate. When NotifyUsersWorkflowAction renders the field through the Silverstripe template engine SSTemplatePars…
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-54721] Silverstripe UserForms provides a visual form builder for the Silverstripe CMS. From 6.0.0 until 6.4…
Silverstripe UserForms provides a visual form builder for the Silverstripe CMS. From 6.0.0 until 6.4.9, 7.0.7, and 7.1.1, the userform email recipient subject field in the CMS accepts a specially crafted payload that can be interpreted as executable server-side code. An authenticated CMS user with permission to configure a UserForms email recipient can use the subject field to run arbitrary code o…