Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
14,795
Total alertas
3351
Críticas
11057
Altas
8
Ransomware
955
Esta semana
RSS
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-67426] Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the stand…
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verification service in src/core/verification_service.py exposes unauthenticated POST /run on 0.0.0.0:8344 and uses client-supplied callback_url for an outbound POST with X-Internal-Key: $FLYTO_RUNNER_SECRET while bypassing target_allowed, allowing unauthenticated SSRF and runner secret …
M Alto vulnerabilidad
29/07/2026
[CVE-2026-67427] Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, the workf…
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, the workflow engine variable resolver expands ${env.VAR} for any host environment variable without an allowlist or capability policy check, allowing a workflow parameter to bypass the default capability policy denylist for env.get and env.load_dotenv and exfiltrate secrets through allowed modules. This issue…
M Alto vulnerabilidad
29/07/2026
[CVE-2026-16328] In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was…
In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing a connected client to override the server's configured Consul address via a request header. This may allow a malicious client to redirect the server's Consul API traffic to an attacker-controlled endpoint, potentially exfiltrating the Consul token configured on the server. This v…
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-14529] IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.…
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled.
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-16326] In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless…
In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (CVE-2026-16326) is fixed in consul-mcp-server 0.1.4.
M Alto vulnerabilidad
29/07/2026
[CVE-2026-8497] Improper certificate validation in the Devolutions Server connection handling in Devolutions Passwor…
Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS allows an adjacent-network attacker to intercept and modify sensitive information via a forged TLS certificate.
M Alto vulnerabilidad
29/07/2026
[CVE-2026-40272] Improper Input Validation in the decode() function of the traceparser library could allow an attacke…
Improper Input Validation in the decode() function of the traceparser library could allow an attacker with a corrupted kernel trace event log (.kev) file, to execute arbitrary code or cause a crash in processes that use libtraceparser in QNX hosts or targets.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-41939] Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildF…
Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attackers to gain administrative access by using default credentials identical across all installations. Attackers can authenticate to the exposed WildFly management console on port 20990 and deploy a malicious Web Application Ar…
M Alto vulnerabilidad
29/07/2026
[CVE-2026-14266] 7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerab…
7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of XZ chunked data. Crafted …
M Alto vulnerabilidad
29/07/2026
[CVE-2026-54727] proot-distro is a utility for managing proot containers. Prior to version 5.1.6, proot-distro restor…
proot-distro is a utility for managing proot containers. Prior to version 5.1.6, proot-distro restore accepted hardlink entries whose linkname referenced another installed container and did not verify that the hardlink source container matched the destination container being restored, allowing a crafted restore archive to copy files between otherwise isolated containers. This issue is fixed in ver…
M Alto vulnerabilidad
29/07/2026
[CVE-2026-64558] In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Check length in pkey…
In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Check length in pkey_pckmo handler implementation Explicitly check the length of the target buffer in the pkey_pckmo implementation of the key_to_protkey() handler function. The handler function fails, if the generated output data exceeds the length of the provided target buffer.
M Alto vulnerabilidad
29/07/2026
[CVE-2026-64559] In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Check length in PKEY…
In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Check length in PKEY_VERIFYPROTK ioctl Explicitly check the buffer length request structure provided by user-space and fail, if it exceeds the buffer size.
M Alto vulnerabilidad
29/07/2026
[CVE-2026-64560] In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Prevent UAF c…
In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Prevent UAF caused by non-leader exec() race Wongi and Jungwoo decoded and reported a non-leader exec() related race which can result in an UAF: sys_timer_delete() exec() posix_cpu_timer_del() // Observes old leader p = pid_task(pid, pid_type); de_thread() switch_leader(); release…
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-51992] SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8 allows a remote attacker to ex…
SQL Injection vulnerability in ClickHouse Server Versions
M Alto vulnerabilidad
29/07/2026
[CVE-2026-54574] proot-distro is a utility for managing proot containers. Prior to version 5.1.5, proot-distro instal…
proot-distro is a utility for managing proot containers. Prior to version 5.1.5, proot-distro install extracted plain tarball root filesystems through _extract_plain_tar() in proot_distro/commands/install.py and Docker layers through _apply_layer() in proot_distro/helpers/docker.py without validating archive-controlled symlink targets in member.linkname, allowing a malicious archive to plant an ab…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-54680] Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior t…
Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd configuration renderer FluentRender in pkg/sdk/logging/model/render/fluent.go writes CRD strings such as Flow record_transformer.records values directly into fluent.conf without escaping, allowing a user who can create Flow resources to inject a Fluentd block using @t…
M Alto vulnerabilidad
29/07/2026
[CVE-2026-18255] A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot acc…
A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a member of, allowing an attacker with read-only superuser privileges to impersonate any robot account.
M Alto vulnerabilidad
29/07/2026
[CVE-2025-60931] An Insecure Direct Object Reference (IDOR) in the Employee Compensation View function of Infor Globa…
An Insecure Direct Object Reference (IDOR) in the Employee Compensation View function of Infor Global HR v11.24.10.01.33 allows unauthorized attackers to arbitrarily view the compensation information of other employees via a crafted GET request.
M Alto vulnerabilidad
29/07/2026
[CVE-2026-13697] undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up…
undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 and 8.0.0 up to before 8.9.0, a response carrying a degenerate qualified private directive, such as private set to an empty value, can be stored in the default shared cache and later served to a different caller with the same cache key, disclosing private response bodies and header…
M Alto vulnerabilidad
29/07/2026
[CVE-2026-15144] @fastify/rate-limit before 11.2.0 keys rate-limit buckets by the verbatim client IP string returned …
@fastify/rate-limit before 11.2.0 keys rate-limit buckets by the verbatim client IP string returned from request.ip. Because a single IPv6 client can control a large address range (a /64 holds 2^64 distinct addresses) and the same address has multiple valid textual representations, an IPv6 capable client can defeat the rate-limit boundary by rotating addresses or by rewriting the same address in d…