Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Multiple Vendors" — 5265 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1052
Esta semana
RSS
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106488] Backstage is an open framework for building developer portals. Prior to 0.4.20, the @backstage/plugi…
Backstage is an open framework for building developer portals. Prior to 0.4.20, the @backstage/plugin-auth-backend-module-oidc-provider package is affected by improper authentication in the oidc provider. Deployments using OIDC email-based identity resolution with a provider that permits unverified email addresses may allow an authenticated provider user to assume another catalog identity. This ma…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106459] Backstage is an open framework for building developer portals. From 0.3.0 until 0.3.8, the @backstag…
Backstage is an open framework for building developer portals. From 0.3.0 until 0.3.8, the @backstage/plugin-scaffolder-backend-module-sentry package is affected by improper input validation in sentry scaffolder actions. An authenticated internal user who can execute the affected actions may cause the backend to contact unintended destinations and disclose Sentry integration credentials. Subsequen…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106455] Backstage is an open framework for building developer portals. From 0.11.12 until 1.14.7 and 1.15.5,…
Backstage is an open framework for building developer portals. From 0.11.12 until 1.14.7 and 1.15.5, the @backstage/plugin-techdocs-node package is affected by improper validation of mkdocs plugin configuration in techdocs. An authenticated attacker with control over a TechDocs source repository could cause a documentation build to retrieve and publish data from network locations reachable by the …
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-105812] Improper control of code generation in the agent import functionality of Amazon Bedrock AgentCore St…
Improper control of code generation in the agent import functionality of Amazon Bedrock AgentCore Starter Toolkit before 0.3.14 might allow an authenticated same-account actor to execute arbitrary code when a user imports and runs or deploys a Bedrock Agent, via crafted configuration values incorporated into generated Python source without safe literal encoding. To remediate this issue, users s…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106062] A heap-based buffer overflow was found in GIMP’s DirectDraw Surface (DDS) loader. When loading a cra…
A heap-based buffer overflow was found in GIMP’s DirectDraw Surface (DDS) loader. When loading a crafted DDS image, buffer sizes derived from width, height, and pitch can be computed using 32-bit arithmetic that overflows. The allocated buffer is too small for the amount of pixel data written through GEGL (CWE-787), following integer overflow in size calculations (CWE-190). This may allow heap cor…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-101258] A flaw was found in Ghostscript. When Ghostscript renders a crafted PostScript or EPS document, it c…
A flaw was found in Ghostscript. When Ghostscript renders a crafted PostScript or EPS document, it can bypass the -dSAFER sandbox and execute arbitrary shell commands in the context of the Ghostscript process. The issue chains memory corruption in document parsing with disabling of internal path access controls at runtime. An attacker can deliver the document directly or through formats that deleg…
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-79805] An authenticated path traversal vulnerability exists in ClearPass Policy Manager. Successful exploit…
An authenticated path traversal vulnerability exists in ClearPass Policy Manager. Successful exploitation could allow an attacker to read and modify certain files on the underlying operating system.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-79806] A privilege escalation vulnerability in the ClearPass Policy Manager OnGuard Linux agent could allow…
A privilege escalation vulnerability in the ClearPass Policy Manager OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges. A successful exploit allows a malicious user to escalate to root privileges on the affected Linux client.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-79807] A missing integrity verification vulnerability in the Windows client software for ClearPass Policy M…
A missing integrity verification vulnerability in the Windows client software for ClearPass Policy Manager could allow malicious users on a local instance to elevate their user privileges. A successful exploit could allow these users to execute attacker-supplied code with elevated privileges on the local system.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-79808] A buffer overflow vulnerability exists in the OnGuard agent of ClearPass Policy Manager. Successful …
A buffer overflow vulnerability exists in the OnGuard agent of ClearPass Policy Manager. Successful exploitation could allow an authenticated local user to execute arbitrary code with elevated privileges on the affected host or to disrupt the availability of the affected service.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-79809] An unauthenticated path traversal vulnerability exists in an API endpoint of ClearPass Policy Manage…
An unauthenticated path traversal vulnerability exists in an API endpoint of ClearPass Policy Manager. Successful exploitation of this vulnerability allows an unauthenticated remote attacker to influence authorization decisions and be assigned an unintended role.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-79810] Remote code execution vulnerabilities exist in the affected interface of HPE Networking ClearPass Po…
Remote code execution vulnerabilities exist in the affected interface of HPE Networking ClearPass Policy Manager that could allow an authenticated remote attacker with high privileges to execute arbitrary code. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-79811] A SQL injection vulnerability in the API of ClearPass Policy Manager could allow a remote authentica…
A SQL injection vulnerability in the API of ClearPass Policy Manager could allow a remote authenticated attacker with administrative privileges to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful exploitation could allow an attacker to execute arbitrary database commands.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-79796] Vulnerabilities have been identified in the affected interface of ClearPass Policy Manager that coul…
Vulnerabilities have been identified in the affected interface of ClearPass Policy Manager that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain unauthorized access to the affected system.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-79797] An improper access control vulnerability exists in the Android client application for HPE Networking…
An improper access control vulnerability exists in the Android client application for HPE Networking ClearPass Policy Manager, where application functionality may be invoked by untrusted sources. Successful exploitation could allow an unauthenticated remote attacker, with user interaction, to obtain sensitive information from the affected user.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-79798] SQL injection vulnerabilities in the web-based management interface of ClearPass Policy Manager coul…
SQL injection vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow a low-privileged authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful exploitation could allow an attacker to run arbitrary database commands.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-79799] A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an una…
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-79800] An authenticated path traversal vulnerability exists in the command line interface of ClearPass Poli…
An authenticated path traversal vulnerability exists in the command line interface of ClearPass Policy Manager. Successful exploitation could allow a low-privileged authenticated remote attacker to execute arbitrary code with elevated privileges on the underlying operating system.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-79801] A missing integrity verification vulnerability in the client agent software of HPE Networking ClearP…
A missing integrity verification vulnerability in the client agent software of HPE Networking ClearPass Policy Manager could allow an unauthenticated remote attacker to introduce untrusted code. Successful exploitation could allow an attacker to execute arbitrary code on the affected client system.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-79802] A command injection vulnerability exists in the client software of ClearPass Policy Manager. Success…
A command injection vulnerability exists in the client software of ClearPass Policy Manager. Successful exploitation could allow an attacker who is able to supply crafted input to the affected software to execute arbitrary commands with elevated privileges on the affected host.